US2016277444A1PendingUtilityA1

Systems, methods, and media for generating bait information for trap-based defenses

Assignee: UNIV COLUMBIAPriority: May 31, 2006Filed: May 16, 2016Published: Sep 22, 2016
Est. expiryMay 31, 2026(expired)· nominal 20-yr term from priority
H04L 63/1408H04L 51/22H04L 43/0876H04L 63/1491H04L 51/42H04L 63/145
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and media for generating bait information for trap-based defenses are provided. In some embodiments, methods for generating bait information for trap-based defenses include: recording historical information of a network; translating the historical information; and generating bait information by tailoring the translated historical information.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting unauthorized activities, comprising:
 recording, using a hardware processor, data sent over a network;   generating, using the hardware processor, a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored;   sending the bait email message from a first decoy account to a second decoy account;   monitoring the bait document to detect whether the bait document has been accessed; and   in response to detecting that the bait document has been accessed, indicating that the security of at least one of the first decoy account and the second decoy account have been compromised.   
     
     
         2 . The method of  claim 1 , wherein the email message indicates that the bait document contains confidential information. 
     
     
         3 . The method of  claim 1 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network. 
     
     
         4 . The method of  claim 3 , wherein generating the bait email message comprises replacing a portion of one of the plurality of email messages sent over the network with altered data. 
     
     
         5 . The method of  claim 4 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name. 
     
     
         6 . The method of  claim 1 , wherein generating the bait email message comprises causing a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message. 
     
     
         7 . A system for detecting unauthorized activities, comprising:
 a hardware processor that is programmed to:
 record data sent over a network; 
 generate a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored; 
 send the bait email message from a first decoy account to a second decoy account; 
 monitor the bait document to detect whether the bait document has been accessed; and 
 in response to detecting that the bait document has been accessed, indicate that the security of at least one of the first decoy account and the second decoy account have been compromised. 
   
     
     
         8 . The system of  claim 7 , wherein the email message indicates that the bait document contains confidential information. 
     
     
         9 . The system of  claim 7 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network. 
     
     
         10 . The system of  claim 9 , wherein the hardware processor is further programmed to replace a portion of one of the plurality of email messages sent over the network with altered data. 
     
     
         11 . The system of  claim 10 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name. 
     
     
         12 . The system of  claim 7 , wherein the hardware processor is further programmed to cause a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message. 
     
     
         13 . A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, causes the processor to perform a method for detecting unauthorized activities, the method comprising:
 recording data sent over a network;   generating a bait email message based on the data sent over the network that references a name of a bait document and a location where the bait document is stored;   sending the bait email message from a first decoy account to a second decoy account;   monitoring the bait document to detect whether the bait document has been accessed; and   in response to detecting that the bait document has been accessed, indicating that the security of at least one of the first decoy account and the second decoy account have been compromised.   
     
     
         14 . The non-transitory computer-readable medium of  claim 13 , wherein the email message indicates that the bait document contains confidential information. 
     
     
         15 . The non-transitory computer-readable medium of  claim 13 , wherein the data sent over the network comprises the content of a plurality of email messages sent over the network. 
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein generating the bait email message comprises replacing a portion of one of the plurality of email messages sent over the network with altered data. 
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein the altered data includes at least one of: a date; a username; a password; a keyword; a geographical location; and a name. 
     
     
         18 . The non-transitory computer-readable medium of  claim 13 , wherein generating the bait email message comprises causing a surrogate user bot (SUB) that uses virtualized keyboard and mouse drivers to provide inputs to write the bait email message.

Join the waitlist — get patent alerts

Track US2016277444A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.