Honeypots for infrastructure-as-a-service security

US2021067553A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2021067553-A1
Application numberUS-202017009634-A
CountryUS
Kind codeA1
Filing dateSep 1, 2020
Priority dateSep 4, 2019
Publication dateMar 4, 2021
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for using honeypots to lure attackers and gather data about attackers and attack patterns on Infrastructure-as-a-Service (IaaS) instances. The gathered data may then be analyzed and used to proactively prevent such attacks.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method, comprising: providing, by a compute instance, a plurality of honeypot servers, each honeypot server of the plurality of honeypot servers comprising a honeypot type; luring, by the compute instance, an attacker to establish a session with at least one honeypot server of the plurality of honeypot servers; receiving, by the compute instance, a first request from the attacker, the first request related to the instance and including a request characteristic; identifying, by the compute instance, a particular honeypot server of the plurality of honeypot servers based at least in part on the request characteristic and the honeypot type; establishing, by the compute instance, a session with the attacker for connection with the particular honeypot server; generating, by the particular honeypot server of the compute instance, a response to a second request from the attacker; causing, by the particular honeypot server of the compute instance, the response to be communicated to the attacker responsive to the second request; and recording, by the compute instance, data related to the attacker or data related to one or more interactions by the attacker with the particular honeypot server. 2 . The method of claim 1 , wherein the compute instance comprises an Infrastructure-as-a-Service (IaaS) compute instance. 3 . The method of claim 2 , wherein the IaaS compute instance is executed by a controller of an IaaS service provider corresponding to an IaaS service provider environment. 4 . The method of claim 3 , wherein the IaaS compute instance is executed by a third-party service provider outside of the IaaS servicer provider environment. 5 . The method of claim 4 , wherein the response to the second request is configured to appear to be from the IaaS service provider. 6 . The method of claim 1 , wherein the plurality of honeypot servers are implemented in respective containers of the compute instance. 7 . The method of claim 1 , wherein each container of the respective containers is configured to emulate a respective honeypot server of the plurality of honeypot servers. 8 . The method of claim 1 , wherein generating the response comprises using rules information to generate the response. 9 . The method of claim 1 , wherein the luring comprises exposing one or more ports over a public network. 10 . The method of claim 9 , wherein the one or more ports comprise at least one of a Secure Shell (SSH) port 21, a File Transfer Protocol (FTP) port 22, or an simple mail transfer protocol (SMTP) port 25. 11 . The method of claim 9 , wherein the one or more ports require one or more credentials that include at least one of a username-password pair, a certificate, a key, or a tenant identifier. 12 . The method of claim 1 , wherein the attacker is an automated bot. 13 . The method of claim 1 , wherein the attacker is a user using an application to generate at least one of the first request or the second request. 14 . The method of claim 1 , wherein receiving the first request or the second request comprises receiving the first request or the second request from a graphical user interface (GUI) based application. 15 . One or more computer-readable storage medium, comprising computer-executable instructions that, when executed by one or more processors of a compute instance, cause the one or more processors to perform operations comprising: providing a plurality of honeypot servers, each honeypot server of the plurality of honeypot servers comprising a honeypot type; luring an attacker to establish a session with at least one honeypot server of the plurality of honeypot servers; receiving a first request from the attacker, the first request related to the instance and including a request characteristic; identifying a particular honeypot server of the plurality of honeypot servers based at least in part on the first request characteristic and the honeypot type; establishing a session with the attacker for connection with the particular honeypot server; generating, by the particular honeypot server of the compute instance, a response to a second request from the attacker; causing, by the particular honeypot server of the compute instance, the response to be communicated to the attacker responsive to the second request; and recording data related to the attacker or data related to one or more interactions by the attacker with the particular honeypot server. 16 . The one or more computer-readable storage medium of claim 15 , wherein the operations further comprise: determining, by the particular honeypot server, an action corresponding to the second request, the action requesting instantiation of a virtual compute instance; and instantiating, by the particular honeypot sever, the virtual compute instance using at least one of computer resources, storage resources, or networking resources, wherein the response indicates successful instantiation of the virtual compute instance. 17 . The one or more computer-readable storage medium of claim 15 , wherein the operations further comprise determining, by the particular honeypot server, that the second request requests an action to be performed using a virtual compute instance, wherein the virtual compute instance is instantiated prior to receiving the second request, and wherein generating the response comprises generating the response by applying the action to the virtual compute instance. 18 . A computing system, comprising: a memory; and one or more processors configured to: provide, by a compute instance, a plurality of honeypot servers, each honeypot server of the plurality of honeypot servers comprising a honeypot type; lure, by the compute instance, an attacker to establish a session with at least one honeypot server of the plurality of honeypot servers; receive, by the compute instance, a first request from the attacker, the first request related to the instance and including a request characteristic; identify, by the compute instance, a particular honeypot server of the plurality of honeypot servers based at least in part on the request characteristic and the honeypot type; establish, by the compute instance, a session with the attacker for connection with the particular honeypot server; generate, by the particular honeypot server of the compute instance, a response to a second request from the attacker; cause, by the particular honeypot server of the compute instance, the response to be communicated to the attacker responsive to the second request; and record, by the compute instance, data related to the attacker or data related to one or more interactions by the attacker with the particular honeypot server. 19 . The computing system of claim 18 , wherein the rules information comprises a plurality of actions and, for each action in the plurality of actions, at least one response corresponding to an action identified in the second request; and further comprising identifying the response using the rules information. 20 . The computing system of claim 18 , wherein identifying the response using the rules information comprises: searching the rules information to find an entry in the rules information where an action corresponding to the entry matches the action; and using the entry to determine the response.

Assignees

Inventors

Classifications

  • Setup of application sessions (admission control or resource allocation in data switching networks H04L47/70) · CPC title

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • Filtering policies (mail message filtering H04L51/212) · CPC title

  • Rule management · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2021067553A1 cover?
Techniques for using honeypots to lure attackers and gather data about attackers and attack patterns on Infrastructure-as-a-Service (IaaS) instances. The gathered data may then be analyzed and used to proactively prevent such attacks.
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/1491. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Mar 04 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).