发明名称 Cognitive honeypot
摘要 An electronic communication evaluating device determines a suspicion level for an initial electronic communication. The initial electronic communication is addressed to an addressed entity that is associated with an electronic communication receiver. In response to the suspicion level exceeding a predetermined level, a communication switching device reroutes the initial electronic communication from the addressed entity to a cognitive honeypot. The cognitive honeypot transmits, to the electronic communication transmitting system, emulation electronic communications that emulate the addressed entity until a predefined state of the communication session occurs.
申请公布号 US9560075(B2) 申请公布日期 2017.01.31
申请号 US201414521095 申请日期 2014.10.22
申请人 International Business Machines Corporation 发明人 Goldberg Itzhack;Kozloski James R.;Pickover Clifford A.;Sondhi Neil;Vukovic Maja
分类号 H04L29/06;H04L29/08;G06F17/27;G06F17/28 主分类号 H04L29/06
代理机构 Law Office of Jim Boice 代理人 Law Office of Jim Boice
主权项 1. A method for managing electronic communications, the method comprising: determining, by an electronic communication evaluating device, a suspicion level for an initial electronic communication, wherein the initial electronic communication is addressed to an addressed entity that is associated with an electronic communication receiver; in response to the suspicion level exceeding a predetermined level, rerouting, by a communication switching device, the initial electronic communication from the addressed entity to a cognitive honeypot, wherein the cognitive honeypot is a natural language question and answer honeypot communication device that determines a legitimacy of the initial electronic communication; transmitting, from the cognitive honeypot to an electronic communication transmitting system, emulation electronic communications that emulate the addressed entity until a predefined state of a communication session occurs; receiving, by the electronic communication receiver, responsive electronic communications from the electronic communication transmitting system, wherein the responsive electronic communications are in response to the emulation electronic communications; in response to receiving no additional responsive electronic communications after a predetermined amount of time, terminating the communication session between the electronic communication transmitting system and the electronic communication receiver; determining, by an electronic communication evaluating device, that the suspicion level for the initial electronic communication has dropped below the predetermined level; utilizing the responsive electronic communications from the electronic communication transmitting system to identify a new entity that is better suited to handle the initial electronic communication than the addressed entity; rerouting, by a communication switching device, subsequent electronic communications from the electronic communication transmitting system to the new entity; utilizing the responsive electronic communications from the electronic communication transmitting system to modify the cognitive honeypot from emulating a first type of resource to emulating a second type of resource; utilizing the responsive electronic communications from the electronic communication transmitting system to modify a communication style of the cognitive honeypot, wherein a modified communication style emulates a communication style of the responsive electronic communications; examining the initial electronic communication for a predetermined phrase; determining the suspicion level based on identifying the predetermined phrase in the initial electronic communication; determining a level of data storage device usage by the electronic communication transmitting system during a predefined past period of time; determining, by the electronic communication evaluating device, the suspicion level based on the level of data storage device usage by the electronic communication transmitting system during the predefined past period of time; determining, by the electronic communication evaluating device, a level of cloud resources usage by the electronic communication transmitting system during the predefined past period of time; determining, by the electronic communication evaluating device, the suspicion level based on the level of cloud resources usage by the electronic communication transmitting system during the predefined past period of time; and adjusting, by the electronic communication evaluating device, a time delay for transmitting the emulation electronic communications based on the suspicion level.
地址 Armonk NY US