MLchartDataset catalogue

Patent · US9462013B1 · B1 · US

Managing security breaches in a networked computing environment

(11) Publication number
US9462013B1
(21) Application number
14/699,279
(22) Filing date
2015-04-29
(30) Priority date
2015-04-29
(43) Publication date
2016-10-04
(45) Date of grant
2016-10-04
(51) IPC
G06F 12/14; H04L 29/06
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 63/1416, 63/1491
  • G06F Electric digital data processing: 21/552, 2221/2127
(73) Assignee
International Business Machines Corp
(72) Inventors
Gregory J. Boss; II Rick A. Hamilton; Jeffrey R. Hoy; Agueda M. H. Magro
(54) Title
Managing security breaches in a networked computing environment
(57) Abstract

Approaches for managing security breaches in a networked computing environment are provided. A method includes detecting, by at least one computer device, a breach of a production system in the networked computing environment, wherein the networked computing environment includes a decoy system interweaved with the production system. The method also includes receiving, by the at least one computer device, a communication after the detecting the breach. The method further includes determining, by the at least one computer device, the communication is associated with one of a valid user and a malicious user. The method additionally includes, based on the determining, routing the valid user to an element of the production system when the communication is associated with the valid user and routing the malicious user to a corresponding element of the decoy system when the communication is associated with the malicious user.

Full text
View on Google Patents

Claims (12)

  1. A method of managing security breaches in a networked computing environment, comprising: detecting, by at least one computer device, a breach of a production system in the networked computing environment, wherein the networked computing environment comprises a decoy system interweaved with the production system; receiving, by the at least one computer device, a communication after the detecting the breach; determining, by the at least one computer device, the communication is associated with one of a valid user and a malicious user; and based on the determining, routing the valid user to an element of the production system when the communication is associated with the valid user and routing the malicious user to a corresponding element of the decoy system when the communication is associated with the malicious user; wherein the networked computing environment comprises layers, and further comprising determining one of the layers at which the breach occurred; and wherein: the communication is determined to be associated with the malicious user; the routing is based on the determined one of the layers; wherein the routing comprises: permitting the malicious user to access at least one element of the production system in one or more first layers up to and including the determined one of the layers; and routing the malicious user to at least one element of the decoy system in one or more second layers downstream of the determined one of the layers.
  2. The method of claim 1, further comprising maintaining the production system intact for servicing valid users after the detecting the breach.
  3. The method of claim 1, further comprising generating automated traffic on elements of the decoy system.
  4. The method of claim 1, wherein a service provider at least one of creates, maintains, deploys and supports the at least one computer device.
  5. The method of claim 1, wherein steps of claim 1 are provided by a service provider on a subscription, advertising, and/or fee basis.
  6. The method of claim 1, further comprising providing software as a service in a cloud environment to perform the steps of claim 1.
  7. A system for managing security breaches, comprising: at least one computer device in a networked computing environment, wherein the at least one computer device is configured to: determine an identification of a malicious user and a detected layer of a breach of a production system of the networked computing environment; route a valid user to an element of the production system; and route the malicious user to a corresponding element of a decoy system of the networked computing environment based on the determined identification of the malicious user and the detected layer of the breach; wherein the networked computing environment comprises: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer; wherein: the malicious user is routed to the decoy application server and the decoy database based on the detected layer of the breach being the first layer; and the malicious user is routed to the production application server and the decoy database based on the detected layer of the breach being one of the second layer and the third layer.
  8. A system for managing security breaches, comprising: a networked computing environment comprising: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer, wherein a malicious user associated with a breach is routed to at least one of the decoy application server and the decoy database, and a valid user is routed to the production application server and the production database; wherein the malicious user and the valid user access the networked computing environment via respective client devices communicating with the external security device; further comprising a breach tool that determines a layer at which the breach occurred; and wherein the malicious user is routed to the production application server and the decoy database based on the breach tool determining the breach occurred at one of the second layer and the third layer.
  9. The system of claim 8, wherein the malicious user is routed to the decoy application server and the decoy database based on the breach tool determining the breach occurred at the first layer.
  10. The system of claim 8, further comprising an activity generation tool that generates automated traffic on the decoy application server and the decoy database.
  11. A computer program product for managing security breaches, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions being executable by a computer device to cause the computer device to: determine, by the computer device, an identification of a malicious user and a detected layer of a breach of a production system of a networked computing environment, wherein the determining comprises receiving or obtaining the identification of the malicious user and the detected layer of the breach from a breach tool; route, by the computer device, a valid user to an element of the production system after the breach; and route, by the computer device, the malicious user to an element of a decoy system of the networked computing environment based on the identification of the malicious user and the detected layer of the breach; wherein the networked computing environment comprises: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer; wherein: the malicious user is routed to the decoy application server and the decoy database based on the detected layer of the breach being the first layer; and the malicious user is routed to the production application server and the decoy database based on the detected layer of the breach being one of the second layer and the third layer.
  12. The computer program product of claim 11, wherein the program instructions cause the computer device to generate automated traffic on the decoy application server and the decoy database.

Description

The present invention generally relates to data security, and more particularly, to managing security breaches in a networked computing environment.

Cloud computing has become popular as organizations are discovering that it provides a cost-effective, scalable, and flexible option to deliver business or consume IT (Information Technology) services over a network environment such as the Internet. Cloud computing presents unique issues in terms of data security. A honeypot is a data security tool used to lure attackers and analyze attacker activity in computing environments. Use of honeypots in cloud environments is generally limited to generation of additional environments, some of which are honeypots with falsified data.

The concept of a honeypot for data security was introduced as an information system resource that helps to detect unauthorized use such as malicious attacks. There are two main types of honeypots: a production honeypot to protect an organization, and a research honeypot to predict, monitor, and learn. Honeypots can be automatically provisioned in cloud environments, and provisioned based on attacker activity. However, these solutions have considerable drawbacks of affecting either valid users or attacker system usage, which limits the value of the honeypot. As a result, traditional automated honeypot generation in a cloud environment suffers from several major limitations. For example, in systems that create honeypots up front (e.g., multiple application environments where one environment is the true environment), legitimate users still need to be routed to the valid environment.

Citations (18)

  • US8769687B2
  • US7042852B2
  • US7437766B2
  • US20040111636A1
  • US20050166072A1
  • US7694339B2
  • US7383578B2
  • US8156556B2
  • US7636944B2
  • US8819825B2
  • US8122505B2
  • US20130333037A1
  • US20110179487A1
  • US20130111540A1
  • US8955143B1
  • US20140280887A1
  • US20140359708A1
  • US8943594B1
Record as JSON
{
  "publication_number": "US9462013B1",
  "country": "US",
  "kind": "B1",
  "title": "Managing security breaches in a networked computing environment",
  "abstract": "Approaches for managing security breaches in a networked computing environment are provided. A method includes detecting, by at least one computer device, a breach of a production system in the networked computing environment, wherein the networked computing environment includes a decoy system interweaved with the production system. The method also includes receiving, by the at least one computer device, a communication after the detecting the breach. The method further includes determining, by the at least one computer device, the communication is associated with one of a valid user and a malicious user. The method additionally includes, based on the determining, routing the valid user to an element of the production system when the communication is associated with the valid user and routing the malicious user to a corresponding element of the decoy system when the communication is associated with the malicious user.",
  "claims": [
    "1. A method of managing security breaches in a networked computing environment, comprising: detecting, by at least one computer device, a breach of a production system in the networked computing environment, wherein the networked computing environment comprises a decoy system interweaved with the production system; receiving, by the at least one computer device, a communication after the detecting the breach; determining, by the at least one computer device, the communication is associated with one of a valid user and a malicious user; and based on the determining, routing the valid user to an element of the production system when the communication is associated with the valid user and routing the malicious user to a corresponding element of the decoy system when the communication is associated with the malicious user; wherein the networked computing environment comprises layers, and further comprising determining one of the layers at which the breach occurred; and wherein: the communication is determined to be associated with the malicious user; the routing is based on the determined one of the layers; wherein the routing comprises: permitting the malicious user to access at least one element of the production system in one or more first layers up to and including the determined one of the layers; and routing the malicious user to at least one element of the decoy system in one or more second layers downstream of the determined one of the layers.",
    "2. The method of claim 1, further comprising maintaining the production system intact for servicing valid users after the detecting the breach.",
    "3. The method of claim 1, further comprising generating automated traffic on elements of the decoy system.",
    "4. The method of claim 1, wherein a service provider at least one of creates, maintains, deploys and supports the at least one computer device.",
    "5. The method of claim 1, wherein steps of claim 1 are provided by a service provider on a subscription, advertising, and/or fee basis.",
    "6. The method of claim 1, further comprising providing software as a service in a cloud environment to perform the steps of claim 1.",
    "7. A system for managing security breaches, comprising: at least one computer device in a networked computing environment, wherein the at least one computer device is configured to: determine an identification of a malicious user and a detected layer of a breach of a production system of the networked computing environment; route a valid user to an element of the production system; and route the malicious user to a corresponding element of a decoy system of the networked computing environment based on the determined identification of the malicious user and the detected layer of the breach; wherein the networked computing environment comprises: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer; wherein: the malicious user is routed to the decoy application server and the decoy database based on the detected layer of the breach being the first layer; and the malicious user is routed to the production application server and the decoy database based on the detected layer of the breach being one of the second layer and the third layer.",
    "8. A system for managing security breaches, comprising: a networked computing environment comprising: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer, wherein a malicious user associated with a breach is routed to at least one of the decoy application server and the decoy database, and a valid user is routed to the production application server and the production database; wherein the malicious user and the valid user access the networked computing environment via respective client devices communicating with the external security device; further comprising a breach tool that determines a layer at which the breach occurred; and wherein the malicious user is routed to the production application server and the decoy database based on the breach tool determining the breach occurred at one of the second layer and the third layer.",
    "9. The system of claim 8, wherein the malicious user is routed to the decoy application server and the decoy database based on the breach tool determining the breach occurred at the first layer.",
    "10. The system of claim 8, further comprising an activity generation tool that generates automated traffic on the decoy application server and the decoy database.",
    "11. A computer program product for managing security breaches, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions being executable by a computer device to cause the computer device to: determine, by the computer device, an identification of a malicious user and a detected layer of a breach of a production system of a networked computing environment, wherein the determining comprises receiving or obtaining the identification of the malicious user and the detected layer of the breach from a breach tool; route, by the computer device, a valid user to an element of the production system after the breach; and route, by the computer device, the malicious user to an element of a decoy system of the networked computing environment based on the identification of the malicious user and the detected layer of the breach; wherein the networked computing environment comprises: an external security device in a first layer; a production application server and a decoy application server in a second layer; an internal security device in a third layer; and a production database and a decoy database in a fourth layer; wherein: the malicious user is routed to the decoy application server and the decoy database based on the detected layer of the breach being the first layer; and the malicious user is routed to the production application server and the decoy database based on the detected layer of the breach being one of the second layer and the third layer.",
    "12. The computer program product of claim 11, wherein the program instructions cause the computer device to generate automated traffic on the decoy application server and the decoy database."
  ],
  "description_excerpt": "The present invention generally relates to data security, and more particularly, to managing security breaches in a networked computing environment.\n\nCloud computing has become popular as organizations are discovering that it provides a cost-effective, scalable, and flexible option to deliver business or consume IT (Information Technology) services over a network environment such as the Internet. Cloud computing presents unique issues in terms of data security. A honeypot is a data security tool used to lure attackers and analyze attacker activity in computing environments. Use of honeypots in cloud environments is generally limited to generation of additional environments, some of which are honeypots with falsified data.\n\nThe concept of a honeypot for data security was introduced as an information system resource that helps to detect unauthorized use such as malicious attacks. There are two main types of honeypots: a production honeypot to protect an organization, and a research honeypot to predict, monitor, and learn. Honeypots can be automatically provisioned in cloud environments, and provisioned based on attacker activity. However, these solutions have considerable drawbacks of affecting either valid users or attacker system usage, which limits the value of the honeypot. As a result, traditional automated honeypot generation in a cloud environment suffers from several major limitations. For example, in systems that create honeypots up front (e.g., multiple application environments where one environment is the true environment), legitimate users still need to be routed to the valid environment.",
  "cpc": [
    "H04L 63/1416",
    "G06F 21/552",
    "G06F 2221/2127",
    "H04L 63/1491"
  ],
  "ipc": [
    "G06F 12/14",
    "H04L 29/06"
  ],
  "assignees": [
    "International Business Machines Corp"
  ],
  "inventors": [
    "Gregory J. Boss",
    "II Rick A. Hamilton",
    "Jeffrey R. Hoy",
    "Agueda M. H. Magro"
  ],
  "filing_date": "2015-04-29",
  "publication_date": "2016-10-04",
  "grant_date": "2016-10-04",
  "priority_date": "2015-04-29",
  "application_number": "US-201514699279-A",
  "family_id": "56995392",
  "cited_by_count": 176,
  "citations": [
    "US8769687B2",
    "US7042852B2",
    "US7437766B2",
    "US20040111636A1",
    "US20050166072A1",
    "US7694339B2",
    "US7383578B2",
    "US8156556B2",
    "US7636944B2",
    "US8819825B2",
    "US8122505B2",
    "US20130333037A1",
    "US20110179487A1",
    "US20130111540A1",
    "US8955143B1",
    "US20140280887A1",
    "US20140359708A1",
    "US8943594B1"
  ]
}

Record 4,543 of 8,000 in Patents full text (MLC-0201). Request the full dataset.