Patent · US Active

Large scale high-interactive honeypot farm

US11265346B2 · kind B2 · utility

4Cited by
56References
13Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 19, 2019
Grant dateMar 1, 2022
Priority date
Expiry dateMar 5, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/30
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques for providing a large scale high-interaction honeypot farm are disclosed. In some embodiments, a system/method/computer program product for providing a large scale high-interaction honeypot farm includes sending traffic detected at a sensor to a smart proxy for a honeypot farm that is executed in a honeypot cloud, wherein the traffic is forwarded attack traffic that is sent using a tunneling protocol, and wherein the honeypot farm includes a plurality of container images of distinct types of vulnerable services; selecting a matching type of vulnerable service from the plurality of container images of distinct types of vulnerable services based on a profile of the attack traffic; forwarding the traffic to an instance of the matching type of vulnerable service; and executing a security agent associated with the instance of the matching type of vulnerable service to identify a threat by monitoring behaviors and detecting anomalies or post exploitation activities.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.