Multi-Region Botnet Simulation via Virtualized Network Cards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for simulating bot-net attacks to test web server vulnerabilities are complex, costly, and time-consuming, and malicious users continually develop new attacks, making it difficult for web site developers to implement effective countermeasures.

Innovation Solution

A computer system that simulates a multi-region bot-net from a single geographic region using a scan head computer with multiple network cards, each configured to send requests through different geographic regions, allowing for efficient simulation of bot-net attacks and detection of vulnerabilities using a library of test modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple client computers are deployed in various geographic regions to simulate bot-net attacks, then the simulation accuracy and vulnerability detection capability are improved, but the complexity and cost of the testing infrastructure increase significantly

Engineering Contradiction:
Improvesimulation accuracyVSAvoidtesting infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple virtual client computers into a single physical testing computer. The scan head computer executes multiple virtual machines or containerized environments that simulate distributed bot-net clients across different geographic regions, eliminating the need for physically deploying multiple computers in different locations while maintaining the authenticity of multi-region attack simulation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a proxy server or network address translation (NAT) layer that mediates between the single testing computer and the target web server. This intermediary modifies network packet headers to simulate different geographic origins, IP addresses, and network paths, allowing one physical machine to appear as multiple distributed clients without requiring actual multi-location deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hundreds of servers are set up in data centers around the world to create a real bot-net for testing, then the authenticity of attack simulation is improved, but the cost and time consumption increase dramatically

Engineering Contradiction:
Improveattack simulation authenticityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates virtual copies of client computers through virtualization technology on a single physical machine. These virtual instances replicate the network behavior, request patterns, and geographic distribution characteristics of real bot-net clients without requiring physical hardware deployment. The virtual environments can be rapidly provisioned and configured to simulate various attack scenarios.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent dynamically changes network parameters such as IP addresses, geographic location data, user agent strings, and network latency characteristics to simulate authentic bot-net behavior. By modifying these parameters programmatically, the system recreates the appearance of distributed attacks from multiple geographic regions without the overhead of actual multi-location infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If complex software is written to simulate bot-net attacks using distributed servers, then the versatility of attack simulation is improved, but the difficulty of implementation and maintenance increases

Engineering Contradiction:
Improveattack simulation versatilityVSAvoidsoftware implementation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent develops a universal testing platform that can simulate multiple types of bot-net attacks through a single software architecture. The scan head computer executes a suite of test modules that cover various attack vectors (SQL injection, XSS, DDoS, credential harvesting) across different virtual client environments, eliminating the need to develop separate simulation tools for each attack type or scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the attack simulation functionality into modular test modules that can be independently configured and executed. Each module represents a specific attack vector or simulation scenario, allowing users to selectively enable or disable particular attack types based on testing requirements. This modular approach simplifies implementation and maintenance compared to monolithic simulation software.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9912685B2Simulating a bot-net spanning a plurality of geographic regions
Publication Date: 2018.03.06 SYNACK
  • US9912685B2 patent drawing
  • US9912685B2 patent drawing
  • US9912685B2 patent drawing

AI summary

Computer systems and methods in various embodiments are configured to test the security of a server computer by simulating a wide range of attacks from one or more bot-nets. In an embodiment, a computer system includes a memory; a processor coupled to the memory; a plurality of network cards coupled to the processor and the memory, the computer system being located in a home geographic region; wherein each of the plurality of network cards is configured to send one or more requests to a remote server computer through one of a plurality of geographic regions, that is different than the home geographic region; wherein, for each of the plurality of network cards, the processor is configured to store in the memory one of a plurality of geo-mappings, wherein the geo-mapping indicates the certain geographic region the network card is configured to send the one or more requests to the remote server computer through.