Invention Grant
- Patent Title: Large scale high-interactive honeypot farm
-
Application No.: US16721633Application Date: 2019-12-19
-
Publication No.: US11265346B2Publication Date: 2022-03-01
- Inventor: Zihang Xiao , Cong Zheng , Jiangxia Liu
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/26

Abstract:
Techniques for providing a large scale high-interaction honeypot farm are disclosed. In some embodiments, a system/method/computer program product for providing a large scale high-interaction honeypot farm includes sending traffic detected at a sensor to a smart proxy for a honeypot farm that is executed in a honeypot cloud, wherein the traffic is forwarded attack traffic that is sent using a tunneling protocol, and wherein the honeypot farm includes a plurality of container images of distinct types of vulnerable services; selecting a matching type of vulnerable service from the plurality of container images of distinct types of vulnerable services based on a profile of the attack traffic; forwarding the traffic to an instance of the matching type of vulnerable service; and executing a security agent associated with the instance of the matching type of vulnerable service to identify a threat by monitoring behaviors and detecting anomalies or post exploitation activities.
Public/Granted literature
- US20210194925A1 LARGE SCALE HIGH-INTERACTIVE HONEYPOT FARM Public/Granted day:2021-06-24
Information query