Patent · US Active

Deceiving attackers accessing active directory data

US11616812B2 · kind B2 · utility

0Cited by
169References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 16, 2019
Grant dateMar 28, 2023
Priority date
Expiry dateFeb 9, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/10
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Endpoints in a network execute a sensor module that intercepts commands. The sensor module compares a source of commands to a sanctioned list of applications received from a management server. If the source does not match a sanctioned application and the command is a write or delete command, the command is ignored and a simulated acknowledgment is sent. If the command is a read command, deception data is returned instead. In some embodiments, certain data is protected such that commands will be ignored or modified to refer to deception data where the source is not a sanctioned application. The source may be verified to be a sanctioned application by evaluating a certificate, hash, or path of the source. Responses from an active directory server may be intercepted and modified to reference a decoy server when not addressed to a sanctioned application.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.