Patents by Inventor Thomas Eugene Sellers
Thomas Eugene Sellers has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12120149Abstract: Disclosed herein are methods, systems, and processes for containing compromised credentials using deception systems. A request to authenticate a credential is received at a honeypot and a determination is made that the request includes context information that correlates the credential with network components that are part of the network. A protected host in the network associated with the credential is identified and the credential is authenticated by validating the credential with the protected host. A determination is made that the credential is compromised and the credential is deactivated.Type: GrantFiled: March 9, 2022Date of Patent: October 15, 2024Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20230171289Abstract: Disclosed herein are methods, systems, and processes for provisioning and deploying deception computing systems with dynamic and flexible personalities. A network connection is received from a source Internet Protocol (IP) address at a honeypot. In response to receiving the network connection, a personality state table is accessed and a determination is made as to whether a personality that corresponds to the source IP address exists in the personality state table. If the personality exists, the personality is designated to the source IP address. If the personality does not exist, an attack characteristic of the network connection is determined and an alternate personality that is substantially similar to the attack characteristic is designated to the source IP address.Type: ApplicationFiled: January 25, 2023Publication date: June 1, 2023Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11595440Abstract: Disclosed herein are methods, systems, and processes for provisioning and deploying deception computing systems with dynamic and flexible personalities. A network connection is received from a source Internet Protocol (IP) address at a honeypot. In response to receiving the network connection, a personality state table is accessed and a determination is made as to whether a personality that corresponds to the source IP address exists in the personality state table. If the personality exists, the personality is designated to the source IP address. If the personality does not exist, an attack characteristic of the network connection is determined and an alternate personality that is substantially similar to the attack characteristic is designated to the source IP address.Type: GrantFiled: April 7, 2021Date of Patent: February 28, 2023Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11522912Abstract: Disclosed herein are methods, systems, and processes for recovering opaque credentials in deception systems. A plaintext credential is received at a honeypot and a plaintext lookup table is accessed. It is determined that the plaintext credential does not exist in the plaintext lookup table and the plaintext credential is added to the plaintext lookup table and a protocol specific plaintext lookup table. An opaque credential is generated for the plaintext credential and the opaque credential is added to a protocol specific opaque lookup table.Type: GrantFiled: March 18, 2021Date of Patent: December 6, 2022Assignee: Rapid7, Inc.Inventors: Thomas Eugene Sellers, Derek Abdine
-
Patent number: 11503073Abstract: Disclosed herein are methods, systems, and processes to perform live deployment of deception computing systems. An imminent or ongoing malicious attack on a protected host in a network is detected. In response to detecting the imminent or ongoing malicious attack, personality characteristics of the protected host are cloned and a honeypot clone based on the personality characteristics is generated. The honeypot clone is then deployed in the network. A determination is made that the malicious attack includes an interactive session between an attacker associated with the malicious attack and the protected host, and a live state transition is performed between the protected host and the honeypot clone using agent data if the interactive session includes an encrypted protocol or using session state data if the interactive session does not include the encrypted protocol.Type: GrantFiled: March 23, 2021Date of Patent: November 15, 2022Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11496515Abstract: Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Lifecycle metadata associated with protected hosts in a network is retrieved. A configurable ratio of honeypots to the protected hosts is accessed. One or more honeypots are deployed based on: the configurable ratio if the lifecycle metadata can be retrieved or determined, or on a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.Type: GrantFiled: March 17, 2021Date of Patent: November 8, 2022Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11489870Abstract: Disclosed herein are methods, systems, and processes for managing and controlling the collective behavior of deception computing system fleets. A malicious attack initiated by a malicious attacker received by a honeypot that is part of a network along with other honeypots is detected. Information associated with the malicious attack is received from the honeypot. Based on the received information, a subset of honeypots other than the honeypot are configured to entice the attacker to engage with the subset of honeypots or avoid the subset of honeypots.Type: GrantFiled: March 24, 2021Date of Patent: November 1, 2022Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11411993Abstract: Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Based on available lifecycle metadata associated with honeypots, a determination is made as to whether honeypot deployment criteria require maintaining a likelihood that a malicious attacker will target a given honeypot and/or preventing the malicious attacker from determining if a target is a protected host or the given honeypot. If a honeypot deployment criteria requires maintaining a likelihood that the malicious attacker will target the given honeypot, a ratio management operation is performed. In addition, if another honeypot deployment criteria requires preventing the malicious attacker from determining if the target is the protected host or the given honeypot, a host replacement operation is performed.Type: GrantFiled: March 17, 2021Date of Patent: August 9, 2022Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20220201038Abstract: Disclosed herein are methods, systems, and processes for containing compromised credentials using deception systems. A request to authenticate a credential is received at a honeypot and a determination is made that the request includes context information that correlates the credential with network components that are part of the network. A protected host in the network associated with the credential is identified and the credential is authenticated by validating the credential with the protected host. A determination is made that the credential is compromised and the credential is deactivated.Type: ApplicationFiled: March 9, 2022Publication date: June 23, 2022Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11303675Abstract: Disclosed herein are methods, systems, and processes for containing compromised credentials using deception systems. A request to authenticate a credential is received at a honeypot and a determination is made that the request includes context information that correlates the credential with network components that are part of the network. A protected host in the network associated with the credential is identified and the credential is authenticated by validating the credential with the protected host. A determination is made that the credential is compromised and the credential is deactivated.Type: GrantFiled: March 28, 2019Date of Patent: April 12, 2022Assignee: Rapid7 , Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20220070218Abstract: Disclosed herein are methods, systems, and processes to perform live deployment of deception computing systems. An imminent or ongoing malicious attack on a protected host in a network is detected. In response to detecting the imminent or ongoing malicious attack, personality characteristics of the protected host are cloned and a honeypot clone based on the personality characteristics is generated. The honeypot clone is then deployed in the network. A determination is made that the malicious attack includes an interactive session between an attacker associated with the malicious attack and the protected host, and a live state transition is performed between the protected host and the honeypot clone using agent data if the interactive session includes an encrypted protocol or using session state data if the interactive session does not include the encrypted protocol.Type: ApplicationFiled: March 23, 2021Publication date: March 3, 2022Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20210226993Abstract: Disclosed herein are methods, systems, and processes for provisioning and deploying deception computing systems with dynamic and flexible personalities. A network connection is received from a source Internet Protocol (IP) address at a honeypot. In response to receiving the network connection, a personality state table is accessed and a determination is made as to whether a personality that corresponds to the source IP address exists in the personality state table. If the personality exists, the personality is designated to the source IP address. If the personality does not exist, an attack characteristic of the network connection is determined and an alternate personality that is substantially similar to the attack characteristic is designated to the source IP address.Type: ApplicationFiled: April 7, 2021Publication date: July 22, 2021Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20210226992Abstract: Disclosed herein are methods, systems, and processes for recovering opaque credentials in deception systems. A plaintext credential is received at a honeypot and a plaintext lookup table is accessed. It is determined that the plaintext credential does not exist in the plaintext lookup table and the plaintext credential is added to the plaintext lookup table and a protocol specific plaintext lookup table. An opaque credential is generated for the plaintext credential and the opaque credential is added to a protocol specific opaque lookup table.Type: ApplicationFiled: March 18, 2021Publication date: July 22, 2021Applicant: Rapid7, Inc.Inventors: Thomas Eugene Sellers, Derek Abdine
-
Publication number: 20210211465Abstract: Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Lifecycle metadata associated with protected hosts in a network is retrieved. A configurable ratio of honeypots to the protected hosts is accessed. One or more honeypots are deployed based on: the configurable ratio if the lifecycle metadata can be retrieved or determined, or on a schedule if the lifecycle metadata cannot be retrieved or determined, but can be estimated.Type: ApplicationFiled: March 17, 2021Publication date: July 8, 2021Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20210211466Abstract: Disclosed herein are methods, systems, and processes for managing and controlling the collective behavior of deception computing system fleets. A malicious attack initiated by a malicious attacker received by a honeypot that is part of a network along with other honeypots is detected. Information associated with the malicious attack is received from the honeypot. Based on the received information, a subset of honeypots other than the honeypot are configured to entice the attacker to engage with the subset of honeypots or avoid the subset of honeypots.Type: ApplicationFiled: March 24, 2021Publication date: July 8, 2021Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11057429Abstract: Disclosed herein are methods, systems, and processes for tracking honeytokens. A malicious attack from an attacker is received at a honeypot and a determination is made that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot. A unique credential pair that corresponds to the deceptive credential information sought by the attack event is generated and a honeytoken tracker state table is modified to include the unique credential pair and attack event metadata in association with the attack event. The unique credential pair is then transmitted to the attacker and the honeytoken tracker state table is synchronized with a honeypot management system. Another malicious attack is detected, the honeytoken tracker state table is accessed, and the malicious attacker is correlated to the attacker.Type: GrantFiled: December 17, 2019Date of Patent: July 6, 2021Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11057428Abstract: Disclosed herein are methods, systems, and processes for tracking honeytokens. A malicious attack from an attacker is received at a honeypot and a determination is made that an attack event associated with the malicious attack has compromised deceptive credential information maintained by the honeypot. A unique credential pair that corresponds to the deceptive credential information sought by the attack event is generated and a honeytoken tracker state table is modified to include the unique credential pair and attack event metadata in association with the attack event. The unique credential pair is then transmitted to the attacker.Type: GrantFiled: March 29, 2019Date of Patent: July 6, 2021Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Publication number: 20210203696Abstract: Disclosed herein are methods, systems, and processes for dynamically deploying deception computing systems based on network environment lifecycle. Based on available lifecycle metadata associated with honeypots, a determination is made as to whether honeypot deployment criteria require maintaining a likelihood that a malicious attacker will target a given honeypot and/or preventing the malicious attacker from determining if a target is a protected host or the given honeypot. If a honeypot deployment criteria requires maintaining a likelihood that the malicious attacker will target the given honeypot, a ratio management operation is performed. In addition, if another honeypot deployment criteria requires preventing the malicious attacker from determining if the target is the protected host or the given honeypot, a host replacement operation is performed.Type: ApplicationFiled: March 17, 2021Publication date: July 1, 2021Applicant: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11038920Abstract: Disclosed herein are methods, systems, and processes for managing and controlling the collective behavior of deception computing system fleets. A malicious attack initiated by a malicious attacker received by a honeypot that is part of a network along with other honeypots is detected. Information associated with the malicious attack is received from the honeypot. Based on the received information, a subset of honeypots other than the honeypot are configured to entice the attacker to engage with the subset of honeypots or avoid the subset of honeypots.Type: GrantFiled: March 28, 2019Date of Patent: June 15, 2021Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers
-
Patent number: 11038919Abstract: Disclosed herein are methods, systems, and processes for provisioning and deploying deception computing systems with dynamic and flexible personalities. A network connection is received from a source Internet Protocol (IP) address at a honeypot. In response to receiving the network connection, a personality state table is accessed and a determination is made as to whether a personality that corresponds to the source IP address exists in the personality state table. If the personality exists, the personality is designated to the source IP address. If the personality does not exist, an attack characteristic of the network connection is determined and an alternate personality that is substantially similar to the attack characteristic is designated to the source IP address.Type: GrantFiled: March 28, 2019Date of Patent: June 15, 2021Assignee: Rapid7, Inc.Inventor: Thomas Eugene Sellers