Invention Grant
- Patent Title: Deceiving attackers in endpoint systems
-
Application No.: US15383522Application Date: 2016-12-19
-
Publication No.: US10599842B2Publication Date: 2020-03-24
- Inventor: Venu Vissametty , Muthukumar Lakshmanan , Harinath Vishwanath Ramchetty , Vinod Kumar A. Porwal
- Applicant: Attivo Networks Inc.
- Applicant Address: US CA Fremont
- Assignee: ATTIVO NETWORKS INC.
- Current Assignee: ATTIVO NETWORKS INC.
- Current Assignee Address: US CA Fremont
- Agency: Stevens Law Group
- Agent David R. Stevens
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/62

Abstract:
Endpoints in a network execute a sensor module that intercepts commands. The sensor module compares a source of commands to a sanctioned list of applications received from a management server. If the source does not match a sanctioned application and the command is a write or delete command, the command is ignored and a simulated acknowledgment is sent. If the command is a read command, deception data is returned instead. In some embodiments, certain data is protected such that commands will be ignored or modified to refer to deception data where the source is not a sanctioned application. The source may be verified to be a sanctioned application by evaluating a certificate, hash, or path of the source.
Public/Granted literature
- US20180173876A1 DECEIVING ATTACKERS IN ENDPOINT SYSTEMS Public/Granted day:2018-06-21
Information query