US2009328213A1PendingUtilityA1

Method and system for morphing honeypot

Individually held — no corporate assignee on recordPriority: Dec 31, 2002Filed: Apr 23, 2008Published: Dec 31, 2009
Est. expiryDec 31, 2022(expired)· nominal 20-yr term from priority
H04L 63/1491H04L 63/1441
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, system, apparatus, or computer program product is presented for morphing a honeypot system on a dynamic and configurable basis. The morphing honeypot emulates a variety of services while falsely presenting information about potential vulnerabilities within the system that supports the honeypot. The morphing honeypot has the ability to dynamically change its personality or displayed characteristics using a variety of algorithms and a database of known operating system and service vulnerabilities. The morphing honeypot's personality can be changed on a timed or scheduled basis, on the basis of activity that is generated by the presented honeypot personality, or on some other basis.

Claims

exact text as granted — not AI-modified
1 . A data processing system comprising:
 means for emulating a service on a server;   means for sending a response that comprises information indicating a set of vulnerable characteristics at the server in response to receiving a request at the emulated service; and   means, operative as the service is emulated on the server, for automatically reconfiguring the set of vulnerable characteristics according to a vulnerability alteration rule when an operational condition of the emulated service, as specified in a monitoring rule, is detected.   
     
     
         2 . The data processing system of  claim 1  further comprising:
 means for temporally varying the set of vulnerable characteristics.   
     
     
         3 . The data processing system of  claim 1  further comprising:
 means for configuring a database of vulnerable characteristics.   
     
     
         4 . The data processing system of  claim 3  further comprising:
 means for selecting the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with a type of operating system, a type of emulatable service, or a type of vulnerable characteristic.   
     
     
         5 . The data processing system of  claim 3  further comprising:
 means for allowing a user to specify parameter values; and   means for deriving the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with user-specified parameters.   
     
     
         6 . The data processing system of  claim 5  further comprising:
 means for specifying a time-related parameter for varying the set of vulnerable characteristics.   
     
     
         7 . The data processing system of  claim 5  further comprising:
 means for logging activity by the emulated service; and   means for deriving the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with logged activity by the emulated service.   
     
     
         8 . The data processing system of  claim 7  further comprising:
 means for triggering an automatic alteration of the set of vulnerable characteristics in response to logged activity by the emulated service being below a configurable threshold value.   
     
     
         9 . The data processing system of  claim 1  further comprising:
 means for configuring a database of monitoring rules; and   means for retrieving the monitoring rule from the database of monitoring rules.   
     
     
         10 . The data processing system of  claim 9  further comprising:
 means for retrieving the vulnerability alteration rule that is associated with the monitoring rule; and   means for deriving the reconfigured set of vulnerable characteristics from a database of vulnerable characteristics in accordance with the vulnerability alteration rule.   
     
     
         11 . The data processing system of  claim 10  further comprising:
 means for specifying a parameter for a type of operating system in the vulnerability alteration rule to be used in deriving the reconfigured set of vulnerable characteristics.   
     
     
         12 . The data processing system of  claim 10  further comprising:
 means for specifying a parameter for a type of service in the vulnerability alteration rule to be used in deriving the reconfigured set of vulnerable characteristics.   
     
     
         13 . A computer program product in a computer readable medium for use in operating a data processing system, the computer program product comprising:
 means for emulating a service on a server;   means for sending a response that comprises information indicating a set of vulnerable characteristics at the server in response to receiving a request at the emulated service; and   means, operative as the service is emulated on the server, for automatically reconfiguring the set of vulnerable characteristics according to a vulnerability alteration rule when an operational condition of the emulated service, as specified in a monitoring rule, is detected.   
     
     
         14 . The computer program product of  claim 13  further comprising:
 means for temporally varying the set of vulnerable characteristics.   
     
     
         15 . The computer program product of  claim 13  further comprising:
 means for configuring a database of vulnerable characteristics.   
     
     
         16 . The computer program product of  claim 15  further comprising:
 means for selecting the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with a type of operating system, a type of emulatable service, or a type of vulnerable characteristic.   
     
     
         17 . The computer program product of  claim 15  further comprising:
 means for allowing a user to specify parameter values; and   means for deriving the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with user-specified parameters.   
     
     
         18 . The computer program product of  claim 17  further comprising:
 means for specifying a time-related parameter for varying the set of vulnerable characteristics.   
     
     
         19 . The computer program product of  claim 17  further comprising:
 means for logging activity by the emulated service; and   means for deriving the set of vulnerable characteristics from the database of vulnerable characteristics in accordance with logged activity by the emulated service.   
     
     
         20 . The computer program product of  claim 19  further comprising:
 means for triggering an automatic alteration of the set of vulnerable characteristics in response to logged activity by the emulated service being below a configurable threshold value.   
     
     
         21 . The computer program product of  claim 13  further comprising:
 means for configuring a database of monitoring rules; and   means for retrieving the monitoring rule from the database of monitoring rules.   
     
     
         22 . The computer program product of  claim 21  further comprising:
 means for retrieving the vulnerability alteration rule that is associated with the monitoring rule; and   means for deriving the reconfigured set of vulnerable characteristics from a database of vulnerable characteristics in accordance with the vulnerability alteration rule.   
     
     
         23 . The computer program product of  claim 22  further comprising:
 means for specifying a parameter for a type of operating system in the vulnerability alteration rule to be used in deriving the reconfigured set of vulnerable characteristics.   
     
     
         24 . The computer program product of  claim 22  further comprising:
 means for specifying a parameter for a type of service in the vulnerability alteration rule to be used in deriving the reconfigured set of vulnerable characteristics.

Join the waitlist — get patent alerts

Track US2009328213A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.