Benign Malware Variant for Proactive Network Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions are reactive and unable to assess the impact of security breaches effectively, as they rely on signature-based detection and cannot evaluate user behavior or potential damage from security threats, leading to vulnerabilities in network security.

Innovation Solution

A proactive assessment method is introduced, where a benign variant of a network security threat is deployed within a private network to simulate a penetration attempt, capturing user interactions and network reactions, allowing for logging and reporting of security missteps and facilitating user training to enhance security habits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection and reactive security solutions are used, then network security threats can be detected and blocked, but the network cannot proactively assess potential damage or evaluate user behavior responses to security threats

Engineering Contradiction:
Improvenetwork security assessment capabilityVSAvoidability to evaluate user behavior and potential damage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent deploys a benign variant of malware (vaccine program) into the network before a real attack occurs. This preliminary action allows the system to proactively assess how the network and users respond to security threats, evaluating propagation depth, user behaviors, and potential damage without causing actual harm. The assessment is performed in advance to identify vulnerabilities and train users before real attacks happen.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If network vulnerability scanners are used to assess security holes, then identified vulnerabilities can be reported, but the scanners cannot access how much the network might be affected in case of an infection

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidassessing impact on network security
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a benign copy (vaccine program) that replicates the propagation mechanisms and symptoms of the actual malware but without its harmful effects. This copy allows comprehensive measurement of propagation depth, affected systems, and potential damage scope by tracking the benign variant's movement through the network while maintaining safety through monitoring and control mechanisms.

Inventive Principle:
Principle #26Copying

3Reliability

If existing antivirus solutions with signatures are used, then known malware can be protected against, but new viruses without signatures are likely to escape detection

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection of new malware variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent converts the potentially harmful malware propagation mechanism into a beneficial assessment tool. By deploying a benign variant that mimics real malware behavior, the system transforms what would be a harmful infection process into a useful security assessment and user training opportunity, enabling detection and evaluation of new threat scenarios without actual damage.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10839703B2Proactive network security assessment based on benign variants of known threats
Publication Date: 2020.11.17 FORTINET INC
  • US10839703B2 patent drawing
  • US10839703B2 patent drawing
  • US10839703B2 patent drawing

AI summary

Systems and methods for performing a proactive assessment of the network security of a private network are provided. According to one embodiment, computer systems and users of the private network are caused to react to a benign variant of a network security threat (“benign threat”) by deploying the benign threat within the private network. The benign threat is created by leaving in tact symptoms and propagation mechanisms associated with the network security threat and replacing malicious behaviors of the network security threat with tracking, monitoring and/or reporting behaviors implemented within the benign threat. Responsive to activation of the benign threat on a particular computer system by a particular user information is captured by the benign threat regarding an identity of the particular user. Training of the particular user regarding proper security habits is facilitated by reporting, by the benign threat, the captured information to a management server.