Honey Network Virtual Clone Manager for Enterprise Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual machine environments for malware detection and security analysis fail to provide a realistic emulation of a target host and network environment, allowing attackers to detect and evade detection by recognizing the absence of expected attributes and devices, leading to inadequate intelligence gathering and risk to production assets.

Innovation Solution

A honey network is deployed to bridge a suspicious device in an enterprise network, using a virtual clone manager to instantiate virtual clones of target devices and route internal communications to a cloud-based honey network, emulating the target network environment and synchronizing attributes to deceive attackers and gather intelligence without risking production assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a virtual machine environment is used for malware detection, then security analysis capability is improved, but the environment is easily detected by attackers who recognize the absence of expected attributes and devices

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidvirtual environment detectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates virtual clones of target devices that replicate the appearance and attributes of real devices in the network. These clones include fake device identifiers, network profiles, and system attributes that mimic legitimate devices, making the virtual environment indistinguishable from a real network to malware and attackers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces an intermediary layer between the malware and the actual network environment. The virtual clone acts as a mediator that presents a realistic network appearance to the malware while isolating it from real production assets, allowing safe observation of malware behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If a honey network is deployed to emulate target devices, then intelligence gathering capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat intelligence gatheringVSAvoidnetwork emulation complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The virtual clone manager provides a universal platform that can create clones of multiple different device types (workstations, servers, mobile devices) using a single system. The clone template mechanism allows the same infrastructure to serve multiple emulation purposes, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs a nested structure where virtual clones are contained within the virtual machine environment, which itself runs on the physical host system. This nested architecture allows layered isolation and management, where each layer provides specific functionality while building upon the previous layer.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Difficulty of detecting and measuring

If virtual clones are used to deceive attackers, then attacker detection capability is improved, but computing resources required increase

Engineering Contradiction:
Improvevirtual environment detectabilityVSAvoidcomputing resource consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The virtual clones replicate only the specific local attributes and characteristics needed to deceive the particular malware or attacker, rather than creating complete duplicate systems. Each clone is configured with just the necessary device profiles, network attributes, and system characteristics required for its specific deception role.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10230689B2Bridging a virtual clone of a target device in a honey network to a suspicious device in an enterprise network
Publication Date: 2019.03.12 PALO ALTO NETWORKS INC
  • US10230689B2 patent drawing
  • US10230689B2 patent drawing
  • US10230689B2 patent drawing

AI summary

Techniques for bridging a honey network to a suspicious device in a network (e.g., an enterprise network) are disclosed. In some embodiments, a system for bridging a honey network to a suspicious device in an enterprise network includes a device profile data store that includes a plurality of attributes of each of a plurality of devices in the target network environment; a virtual clone manager executed on a processor that instantiates a virtual clone of one or more devices in the target network environment based on one or more attributes for a target device in the device profile data store; and a honey network policy that is configured to route an internal network communication from a suspicious device in the target network environment to the virtual clone for the target device in the honey network.