US2016277444A1PendingUtilityA1
Systems, methods, and media for generating bait information for trap-based defenses
Est. expiryMay 31, 2026(expired)· nominal 20-yr term from priority
H04L 63/1408H04L 51/22H04L 43/0876H04L 63/1491H04L 51/42H04L 63/145
52
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Systems, methods, and media for generating bait information for trap-based defenses are provided. In some embodiments, methods for generating bait information for trap-based defenses include: recording historical information of a network; translating the historical information; and generating bait information by tailoring the translated historical information.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for detecting unauthorized activities, comprising:
recording, using a hardware processor, data sent over a network; generating, using the hardware processor, a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored; sending the bait email message from a first decoy account to a second decoy account; monitoring the bait document to detect whether the bait document has been accessed; and in response to detecting that the bait document has been accessed, indicating that the security of at least one of the first decoy account and the second decoy account have been compromised.
2 . The method of claim 1 , wherein the email message indicates that the bait document contains confidential information.
3 . The method of claim 1 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network.
4 . The method of claim 3 , wherein generating the bait email message comprises replacing a portion of one of the plurality of email messages sent over the network with altered data.
5 . The method of claim 4 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name.
6 . The method of claim 1 , wherein generating the bait email message comprises causing a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message.
7 . A system for detecting unauthorized activities, comprising:
a hardware processor that is programmed to:
record data sent over a network;
generate a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored;
send the bait email message from a first decoy account to a second decoy account;
monitor the bait document to detect whether the bait document has been accessed; and
in response to detecting that the bait document has been accessed, indicate that the security of at least one of the first decoy account and the second decoy account have been compromised.
8 . The system of claim 7 , wherein the email message indicates that the bait document contains confidential information.
9 . The system of claim 7 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network.
10 . The system of claim 9 , wherein the hardware processor is further programmed to replace a portion of one of the plurality of email messages sent over the network with altered data.
11 . The system of claim 10 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name.
12 . The system of claim 7 , wherein the hardware processor is further programmed to cause a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message.
13 . A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, causes the processor to perform a method for detecting unauthorized activities, the method comprising:
recording data sent over a network; generating a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored; sending the bait email message from a first decoy account to a second decoy account; monitoring the bait document to detect whether the bait document has been accessed; and in response to detecting that the bait document has been accessed, indicating that the security of at least one of the first decoy account and the second decoy account have been compromised.
14 . The non-transitory computer-readable medium of claim 13 , wherein the email message indicates that the bait document contains confidential information.
15 . The non-transitory computer-readable medium of claim 13 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network.
16 . The non-transitory computer-readable medium of claim 15 , wherein generating the bait email message comprises replacing a portion of one of the plurality of email messages sent over the network with altered data.
17 . The non-transitory computer-readable medium of claim 16 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name.
18 . The non-transitory computer-readable medium of claim 13 , wherein generating the bait email message comprises causing a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message.Join the waitlist — get patent alerts
Track US2016277444A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.