Invention Grant
- Patent Title: Database deception in directory services
-
Application No.: US14965574Application Date: 2015-12-10
-
Publication No.: US09942270B2Publication Date: 2018-04-10
- Inventor: Venu Vissamsetty , Satya Das , Srikant Vissamsetti
- Applicant: Attivo Networks Inc.
- Applicant Address: US CA Fremont
- Assignee: ATTIVO NETWORKS INC.
- Current Assignee: ATTIVO NETWORKS INC.
- Current Assignee Address: US CA Fremont
- Agency: Stevens Law Group
- Agent David R. Stevens
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06

Abstract:
A system includes one or more “BotMagnet” modules that are exposed to infection by malicious code. The BotMagnets may include one or more virtual machines hosing operating systems in which malicious code may be installed and executed without exposing sensitive data or other parts of a network. In particular, outbound traffic may be transmitted to a Sinkhole module that implements a service requested by the outbound traffic and transmits responses to the malicious code executing within the BotMagnet. Credentials for services implemented by a BotSink may be planted in an active directory (AD) server. The BotSink periodically uses the credentials thereby creating log entries indicating use thereof. In response to an attacker accessing the services using the credentials, the BotSink engages and monitors an attacker system and may generate an alert.
Public/Granted literature
- US20170171244A1 DATABASE DECEPTION IN DIRECTORY SERVICES Public/Granted day:2017-06-15
Information query