Dissolvable Software Agents for Operational Network Cyber-Attack Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber-attack training methods, whether on operational networks or virtual environments, face limitations such as lack of realism in virtual environments and restrictions on disrupting operational networks, hindering effective training for cyber-warriors.

Innovation Solution

The deployment of dissolvable software agents configured to emulate cyber-attacks on operational networks, saving and restoring system states, allowing for realistic training without harming the network infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If training is conducted on operational networks, then training realism and fidelity are improved, but network security and stability deteriorate due to potential disruptions and damage

Engineering Contradiction:
Improvetraining fidelityVSAvoidnetwork stability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent creates virtual copies of operational network systems that replicate real-world environments and attack scenarios. These virtual systems allow trainees to practice cyber-attack detection and response against simulated threats that mirror actual operational networks, achieving high training fidelity without exposing real networks to risk.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between trainees and operational networks. This intermediary environment provides realistic training scenarios while isolating the operational network from potential harm, allowing realistic attack simulations without direct exposure of critical infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual environments are used for training, then network security is improved by preventing disruptions, but training realism deteriorates due to oversimplified mock-ups

Engineering Contradiction:
Improvenetwork securityVSAvoidtraining realism
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent creates highly detailed virtual copies of operational systems that preserve complex network architectures, diverse workloads, and realistic attack vectors. These virtual environments replicate the intricacies of production systems including multiple server types, network configurations, and authentic threat scenarios, providing both security and realism.

Inventive Principle:
Principle #26Copying

3Measurement precision

If live red teams are used for training, then training realism is improved, but resource availability and operational complexity worsen due to limited availability and restoration challenges

Engineering Contradiction:
Improvetraining realismVSAvoidcommand and control complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements automated training scenario management where virtual systems self-provision training environments, automatically configure attack scenarios, and manage exercise execution. This automation eliminates the need for manual coordination of live red teams while maintaining realistic training conditions through programmable attack simulations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10909244B1Computer network defense training on operational networks using software agents
Publication Date: 2021.02.02 ARCHITECTURE TECH CORP
  • US10909244B1 patent drawing
  • US10909244B1 patent drawing
  • US10909244B1 patent drawing

AI summary

An example method includes storing a scenario event list that defines one or more events associated with a training exercise, and configuring, based on the events defined in the scenario event list, one or more software agents to emulate one or more cyber-attacks against a host computing system during the training exercise, which includes configuring the software agents to save a state of one or more resources of the host computing system prior to emulating the cyber-attacks and to restore the state of the resources upon conclusion of the cyber-attacks. The example method further includes deploying the software agents for execution on the host computing system during the training exercise to emulate the cyber-attacks against the host computing system using one or more operational networks.