Generating a honey network configuration to emulate a target network environment

US9716727B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9716727-B1
Application numberUS-201514805406-A
CountryUS
Kind codeB1
Filing dateJul 21, 2015
Priority dateSep 30, 2014
Publication dateJul 25, 2017
Grant dateJul 25, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for generating a honey network configuration to emulate a target network environment are disclosed. In some embodiments, techniques for generating a honey network configuration to emulate a target network include receiving a network scan survey of the target network; generating the honey network configuration to emulate the target network using the network scan survey of the target network; and executing a honey network using the honey network configuration.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a processor configured to: receive a network scan survey of a target network; generate a honey network configuration to emulate the target network using the network scan survey of the target network, wherein generating the honey network configuration includes generating a trigger table; and execute a honey network using the honey network configuration, wherein executing the honey network using the honey network configuration includes determining a set of responses for each of a plurality of devices on the target network and each service in response to probes received from a scanning tool using the trigger table, wherein the trigger table includes a set of data that indicates responses used by the scanning tool to identify a device type, an operating system (OS) type and OS version, and/or a service provided by a device; and a memory coupled to the processor and configured to provide the processor with instructions. 2. The system recited in claim 1 , wherein the processor is further configured to: translate the network scan survey into a representation of a plurality of devices and a plurality of services. 3. The system recited in claim 1 , wherein the processor is further configured to: translate the network scan survey into a representation of a plurality of devices and a plurality of services; and determine a set of attributes associated with each of the devices and each of the services. 4. The system recited in claim 1 , wherein the processor is further configured to: initiates initiate a virtual machine (VM) instance for implementing the honey network based on the honey network configuration. 5. The system recited in claim 1 , wherein the processor is further configured to: receive a probe sent to an IP address that is in the honey network. 6. The system recited in claim 1 , wherein the processor is further configured to: receive a probe from the scanning tool sent to an IP address that is in the honey network; and generate a response to the probe using the trigger table of the honey network configuration. 7. The system recited in claim 1 , wherein the processor is further configured to: receive a probe from the scanning tool sent to an IP address that is in the honey network; generate a response to the probe using the trigger table of the honey network configuration; and send the response, wherein the scanning tool is unable to detect that the response is associated with an emulated device and/or an emulated service in the honey network. 8. A method, comprising: receiving a network scan survey of a target network; generating a honey network configuration to emulate the target network using the network scan survey of the target network, wherein generating the honey network configuration includes generating a trigger table; and executing a honey network using the honey network configuration, wherein executing the honey network using the honey network configuration includes determining a set of responses for each of a plurality of devices on the target network and each service in response to probes received from a scanning tool using the trigger table, wherein the trigger table includes a set of data that indicates responses used by the scanning tool to identify a device type, an operating system (OS) type and OS version, and/or a service provided by a device. 9. The method of claim 8 , further comprising: translating the network scan survey into a representation of a plurality of devices and a plurality of services. 10. The method of claim 8 , further comprising: translating the network scan survey into a representation of a plurality of devices and a plurality of services; and determining a set of attributes associated with each of the devices and each of the services. 11. A computer program product, the computer program product being embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for: receiving a network scan survey of a target network; generating a honey network configuration to emulate the target network using the network scan survey of the target network, wherein generating the honey network configuration includes generating a trigger table; and executing a honey network using the honey network configuration, wherein executing the honey network using the honey network configuration includes determining a set of responses for each of a plurality of devices on the target network and each service in response to probes received from a scanning tool using the trigger table, wherein the trigger table includes a set of data that indicates responses used by the scanning tool to identify a device type, an operating system (OS) type and OS version, and/or a service provided by a device. 12. The computer program product recited in claim 11 , further comprising computer instructions for: translating the network scan survey into a representation of a plurality of devices and a plurality of services. 13. The computer program product recited in claim 11 , further comprising computer instructions for: translating the network scan survey into a representation of a plurality of devices and a plurality of services; and determining a set of attributes associated with each of the devices and each of the services. 14. The system recited in claim 1 , wherein the trigger table is provided for the scanning tool, and another trigger table is provided for another scanning tool. 15. The system recited in claim 1 , wherein the trigger table includes a plurality of systems tables and a plurality of services tables. 16. The method of claim 8 , wherein the trigger table is provided for the scanning tool, and another trigger table is provided for another scanning tool. 17. The method of claim 8 , wherein the trigger table includes a plurality of systems tables and a plurality of services tables. 18. The computer program product recited in claim 11 , wherein the trigger table is provided for the scanning tool, and another trigger table is provided for another scanning tool. 19. The computer program product recited in claim 11 , wherein the trigger table includes a plurality of systems tables and a plurality of services tables.

Assignees

Inventors

Classifications

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9716727B1 cover?
Techniques for generating a honey network configuration to emulate a target network environment are disclosed. In some embodiments, techniques for generating a honey network configuration to emulate a target network include receiving a network scan survey of the target network; generating the honey network configuration to emulate the target network using the network scan survey of the target n…
Who is the assignee on this patent?
Palo Alto Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1491. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 25 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).