发明名称 COMPROMISED INSIDER HONEY POTS USING REVERSE HONEY TOKENS
摘要 According to one embodiment, a method for setting a trap to detect that an intruder has compromised a client end station (CES) in an attempt to gain unauthorized access to enterprise data provided by a server is described. The method includes causing a honey token to be placed on the CES secluded within a configuration repository, wherein the honey token is metadata and/or instructions indicating how applications can seemingly access the enterprise data but that is actually invalid, and the honey token is placed on the CES and not on the server. The method also includes causing attribute values to be installed on a security gateway for a security rule causing the security gateway to monitor network traffic for attempted use of the honey token, and to generate an alert when a set of one or more packets that include the honey token are received.
申请公布号 US2015013006(A1) 申请公布日期 2015.01.08
申请号 US201313934099 申请日期 2013.07.02
申请人 Imperva Inc. 发明人 Shulman Amichai;Cherny Michael;Dulce Sagie
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for setting a trap to detect if an intruder has compromised a client end station in an attempt to gain unauthorized access to enterprise data provided by a server executing on a server end station, wherein the client end station comprises a set of one or more user data files storing user data accessed through a set of one or more applications and further comprises a set of one or more configuration repositories storing application configuration data used by the set of applications to configure the operation of the set of applications, the method comprising: causing a honey token to be placed on the client end station secluded within the application configuration data stored in at least one of the set of configuration repositories, wherein the honey token is one or more of metadata and instructions indicating how one or more of the set of applications can seemingly access the enterprise data provided by the server, wherein the honey token is invalid and does not allow access to any of the enterprise data provided by the server, wherein the server is unaware of the honey token, and wherein the honey token is a reverse honey token in that it is placed on the client end station and not on the server; and causing a set of one or more attribute values to be installed on a security gateway implemented in an electronic device and coupled between the client end station and the server, wherein the set of attribute values are to be utilized for a security rule that causes the security gateway to, monitor network traffic for attempted use of the honey token to gain access to the enterprise data provided by the server, andgenerate an alert when a set of one or more packets that include the honey token are received.
地址 Redwood Shores CA US