×

System and method for creation, deployment and management of augmented attacker map

  • US 9,553,885 B2
  • Filed: 01/23/2016
  • Issued: 01/24/2017
  • Est. Priority Date: 06/08/2015
  • Status: Active Grant
First Claim
Patent Images

1. A system for network surveillance to detect attackers, comprising:

  • a deception management server within a network of resources, comprising;

    a deployment processor managing and planting one or more decoy attack vectors in one or more of the resources in the network, wherein an attack vector is an object in memory or storage of a first resource that may be used to access a second resource; and

    a notification processor; and

    one or more decoy servers accessible from resources in the network, each decoy server comprising a forensic alert processor that issues an alert when a specific resource in the network accesses that decoy server via one or more of the decoy attack vectors planted in that specific resource by said deployment processor, the alert causing said deception management server to transmit a real-time forensic application to the specific resource, wherein the forensic application, when launched in the specific resource, identifies a process running within the specific resource that is accessing that decoy server, logs the activities performed by the thus-identified process in a forensic report, and transmits the forensic report to said deception management server, wherein said notification processor transmits to a notification server a notification that a resource in the network accessed a decoy server, and information in the forensic report provided by the forensic application, in response to said deception management server receiving the forensic report.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×