Dynamic Honeypot Personality Assignment via Attack Characteristic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Honeypots with narrowly defined personalities fail to entice specific attackers, while those with broadly defined personalities stand out as decoys, and existing systems cannot dynamically present different personalities to multiple attackers effectively.

Innovation Solution

A method for provisioning and deploying deception systems with dynamic and flexible personalities, using a personality state table to determine and generate alternate personalities based on attack characteristics, allowing a single honeypot to present unique personalities to multiple attackers simultaneously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a honeypot uses a narrowly defined personality, then it can maintain a realistic decoy profile, but it fails to entice attackers looking for specific target types

Engineering Contradiction:
Improvedecoy realismVSAvoidattacker attraction
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The honeypot dynamically changes its personality based on the attacker's behavior and attack characteristics. The system monitors attack patterns and automatically adjusts the presented personality to match what the attacker is seeking, transforming from a static decoy to an adaptive target that evolves during the interaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters of the honeypot's personality including operating system type, service configurations, and vulnerability profiles based on the detected attack characteristics. This allows the honeypot to present different system configurations (e.g., Windows vs. Linux, different service versions) to match the attacker's exploit targets.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If a honeypot uses a broadly defined personality, then it can entice a wide range of attackers, but it stands out as an obvious honeypot

Engineering Contradiction:
Improveattacker attractionVSAvoiddecoy realism
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Instead of making the entire honeypot broadly defined, the system applies local quality by presenting different personality aspects selectively. The honeypot maintains a realistic, narrow personality for most interactions but can locally expand its defined characteristics when specific attack patterns are detected, allowing it to match the attacker's target without appearing obviously broad.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The honeypot's personality definition dynamically expands or contracts based on the interaction context. It starts with a realistic narrow profile and only broadens its defined characteristics when attack patterns indicate the attacker is seeking specific target types, thereby maintaining realism while adapting to attract the right attackers.

Inventive Principle:
Principle #15Dynamics

3Stability of the object's composition

If a single honeypot presents one personality, then it maintains consistency, but it cannot effectively present different personalities to multiple attackers simultaneously

Engineering Contradiction:
Improvepersonality consistencyVSAvoidmulti-attacker personalization
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The system segments the attacker population by monitoring and analyzing attack characteristics from different source IP addresses. Each attacker or attacker group is assigned a specific personality profile based on their attack patterns, allowing the single honeypot to present different consistent personalities to different attackers simultaneously while maintaining overall system stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The honeypot achieves multi-functionality by implementing a personality state table that stores multiple personality profiles and a selection mechanism that assigns the appropriate personality to each attacker based on their characteristics. This allows one honeypot instance to serve multiple functions by presenting different personalities to different attackers concurrently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11595440B2Maintaining interactive session continuity in honeypot deployments
Publication Date: 2023.02.28 RAPID7 INC
  • US11595440B2 patent drawing
  • US11595440B2 patent drawing
  • US11595440B2 patent drawing

AI summary

Disclosed herein are methods, systems, and processes for provisioning and deploying deception computing systems with dynamic and flexible personalities. A network connection is received from a source Internet Protocol (IP) address at a honeypot. In response to receiving the network connection, a personality state table is accessed and a determination is made as to whether a personality that corresponds to the source IP address exists in the personality state table. If the personality exists, the personality is designated to the source IP address. If the personality does not exist, an attack characteristic of the network connection is determined and an alternate personality that is substantially similar to the attack characteristic is designated to the source IP address.