Scarecrow for data security

US2017237771A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2017237771-A1
Application numberUS-201615044479-A
CountryUS
Kind codeA1
Filing dateFeb 16, 2016
Priority dateFeb 16, 2016
Publication dateAug 17, 2017
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, computer program product and/or system receives information pertaining to network data traffic from and/or to a network accessible resource, analyzes the information to determine whether a user is engaged in potential hacking transaction(s) with respect to the resource. On condition that the user is determined to be engaged in potential hacking transaction(s), a “scarecrow” message designed for display to the user, is generated and sent to the user.

First claim

Opening claim text (preview).

What is claimed is: 1 . A computer-implemented method comprising: receiving information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; analyzing the information to determine whether the user is engaged in potential hacking transaction(s) with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking transaction(s): generating a scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and sending the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 2 . The computer-implemented method of claim 1 wherein potential hacking transaction(s) of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transaction(s); the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and the user's computer hostname exists in more than a pre-defined number of sessions with the network accessible resource. 3 . The computer-implemented method of claim 1 further comprising: on condition that the user is engaged in potential hacking transaction(s): receiving data from the network accessible resource, altering the data to generate altered data, and sending the altered data to a computer operated by the user. 4 . The computer-implemented method of claim 1 wherein the scarecrow message is sent to the user in a form and format that is displayable by software running on a computer operated by the user. 5 . The computer-implemented method of claim 1 wherein the scarecrow message includes at least one of the following: (i) the user's internet protocol (IP) address; (ii) indication that the user's activities are being monitored; (iii) indication that a connection profile of the computer operated by the user is being monitored; (iv) a phantom background process; and/or (v) the user's log-in chain. 6 . The computer-implemented method of claim 3 wherein altering the data includes at least one of the following: (i) adding an electronic watermark; (ii) adding a warning message; and/or (iii) preventing transmission to the user's computer of at least a portion of the data. 7 . A computer program product comprising a computer readable storage medium having stored thereon: first program instructions programmed to receive information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; second program instructions programmed to analyze the information to determine whether the user is engaged in potential hacking transaction with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking conduct: third program instructions programmed to generate scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and fourth program instructions programmed to send the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 8 . The computer program product of claim 7 wherein potential hacking activity of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transactions; the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and a computer hostname exists in more than a pre-defined number of sessions. 9 . The computer program product of claim 7 further comprising: on condition that the user is engaged in potential hacking transactions: fifth program instructions programmed to receive data from the network accessible resource, sixth program instructions programmed to alter the data to generate altered data, and seventh program instructions programmed to send the altered data to a computer operated by the user. 10 . The computer program product of claim 7 wherein the scarecrow message is sent to the user in a form and format that is displayable by software running on the computer operated by the user. 11 . The computer program product of claim 7 wherein the scarecrow message includes at least one of the following: (i) the user's internet protocol (IP) address; (ii) indication that the user's activities are being monitored; (iii) indication that a connection profile of the computer operated by the user is being monitored; (iv) a phantom background process; and/or (v) the user's log-in chain. 12 . The computer program product of claim 9 wherein altering the data includes at least one of the following: (i) adding an electronic watermark; (ii) adding a warning message; and/or (iii) preventing transmission to the user's computer of at least a portion of the data. 13 . A computer system comprising: a processor(s) set; and a computer readable storage medium; wherein: the processor(s) set is structured, located, connected and/or programmed to run program instructions stored on the computer readable storage medium; and the program instructions include: first program instructions programmed to receive information pertaining to network data traffic being communicated from and/or to a user's computer which is operated by a user; second program instructions programmed to analyze the information to determine whether the user is engaged in potential hacking transaction with respect to a network accessible resource; and on condition that the user is determined to be engaged in potential hacking conduct: third program instructions programmed to generate scarecrow message designed for display in human understandable form and format to the user on a computer operated by the user, and fourth program instructions programmed to send the scarecrow message to the user's computer; wherein potential hacking transaction(s) are defined as any set of communication(s) to and/or from the user's computer that tend to indicate that the user's computer is engaged in subverting computer security for malicious purposes. 14 . The computer system of claim 13 wherein potential hacking activity of the user includes at least one of the following: a transaction by a user previously known to have engaged in hacking transactions; the user requests information from the network accessible resource at a rate that exceeds a pre-determined threshold; data accessed, by the user, includes information of a predefined format; data access attempts, by the user, generate errors at a rate exceeding a pre-defined threshold; and a computer hostname exists in more than a pre-defined number of sessions. 15 . The computer system of claim 13 further comprising: on condition that the user is engaged in potential hac

Assignees

Inventors

Classifications

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2017237771A1 cover?
A method, computer program product and/or system receives information pertaining to network data traffic from and/or to a network accessible resource, analyzes the information to determine whether a user is engaged in potential hacking transaction(s) with respect to the resource. On condition that the user is determined to be engaged in potential hacking transaction(s), a “scarecrow” message de…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/1466. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Aug 17 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).