Browser-Based Security Agents for Continuous Network Threat Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing network security, such as tabletop exercises and penetration tests, are limited in effectiveness and often costly, infrequently conducted, and may not detect pervasive security holes or patterns, while vulnerability scanning can impact operations and require significant resources and human involvement.

Innovation Solution

A security assessment system that uses executable program code to simulate security threat techniques, tactics, and practices on end devices, allowing for continuous, automated, and on-demand network security testing, with agents executing simulations within browser applications and automatically deleting after completion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional penetration tests and tabletop exercises are used to assess network security, then security vulnerabilities can be detected, but the assessment process is costly, time-consuming, and conducted infrequently

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidassessment frequency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates virtual copies of threat actors (bots) that simulate real attack patterns. These digital twins can continuously replicate sophisticated threat behaviors without requiring actual human penetration testers, enabling frequent reassessment while maintaining detection accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system enables networks to self-assess their own security posture through automated bot simulations. The bots independently execute threat techniques, collect vulnerability data, and generate assessments without continuous human intervention, allowing ongoing security evaluation at minimal cost.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If vulnerability scanning is performed to detect security holes, then security weaknesses can be identified, but operations are impacted and significant resources and human involvement are required

Engineering Contradiction:
Improvesecurity weakness identificationVSAvoidresource requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent employs disposable bot instances that are created, execute their simulation tasks, and then terminate. These short-lived virtual threat actors require minimal resources compared to traditional vulnerability scanning infrastructure, reducing complexity while maintaining identification accuracy.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system replaces complex mechanical vulnerability scanning systems with software-based bot simulations. By substituting physical scanning infrastructure with virtual threat actor software, the patent reduces device complexity and resource requirements while achieving the same security assessment goals.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If comprehensive security assessments are conducted to detect pervasive security holes and patterns, then a complete view of network security can be obtained, but the assessment process becomes more costly and resource-intensive

Engineering Contradiction:
Improvecomprehensive security viewVSAvoidassessment cost
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments comprehensive security assessments into multiple independent bot simulations, each specializing in specific threat techniques or attack patterns. This modular approach allows the system to achieve complete security coverage by coordinating multiple focused assessments rather than one expensive comprehensive scan.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts simulation parameters such as bot behavior patterns, target selection criteria, and assessment depth based on network conditions and security priorities. This flexibility allows comprehensive assessment when needed while enabling cost-effective targeted assessments during other periods.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11709945B2System and method for identifying network security threats and assessing network security
Publication Date: 2023.07.25 RELIAQUEST HOLDINGS LLC
  • US11709945B2 patent drawing
  • US11709945B2 patent drawing
  • US11709945B2 patent drawing

AI summary

A system and method of security assessment of a network is described. The system may include one or more security assessment computers controlled by a security assessor, and connected to a network, and first executable program code for acting as an agent on a first end device on the network. The first executable program code is configured to be executed by a browser application of the first end device, and is configured to collect software information, hardware information, and/or vulnerability information of the first end device and transmit the same to a first security assessment computer of the one or more security assessment computers. The information may be transmitted as part of a domain name server (DNS) request. The DNS request may include information identifying the first end device to thus allow modification of the first end device in response to analysis of the collected information.