Network Appliance Executable Wrapping for Zero-Day Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional signature-based security solutions are ineffective against Zero-day and Advanced Persistent Threats (APT) attacks, and virtual machine-based appliances face performance bottlenecks, ease of bypass, delayed threat detection, and user inconvenience.

Innovation Solution

A system that delivers executable files securely by wrapping them in a protective manner and running them in a sandbox environment on client systems, where behavior analysis is performed, using a network appliance with an interceptor and packer to analyze and isolate potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all threats are executed and analyzed in the appliance, then threat detection capability is improved, but appliance performance becomes a bottleneck

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidappliance performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the threat analysis process into two parts: initial analysis in the appliance and sandbox execution on client systems. This distributes the computational load and prevents the appliance from becoming a performance bottleneck while maintaining comprehensive threat detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces sandbox wrappers as an intermediary layer between the appliance and client systems. These wrappers enable remote sandbox execution, allowing threats to be analyzed in isolated environments without overloading the appliance's processing capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual machine based analysis is used, then threat analysis capability is improved, but it can be bypassed easily by virtual machine detection

Engineering Contradiction:
Improvethreat analysis capabilityVSAvoidbypass vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses sandbox wrappers as an intermediary that executes threats in isolated environments without exposing virtual machine characteristics. This intermediary layer prevents malware from detecting the virtualized environment, eliminating the bypass vulnerability while maintaining analysis capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If threats are analyzed in a virtual machine appliance, then centralized security management is improved, but users have to wait until analysis completes before using executable files

Engineering Contradiction:
Improvecentralized security managementVSAvoiduser waiting time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary wrapping of executable files with sandbox capabilities before delivery to client systems. This preliminary action enables local sandbox execution, allowing users to immediately use files while security analysis continues in the background, eliminating waiting time while maintaining centralized management.

Inventive Principle:
Principle #10Preliminary action

4Ease of manufacture

If signature-based security solutions are used, then implementation simplicity is improved, but they cannot defend against Zero-day and APT attacks

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddefense capability against Zero-day and APT attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces sandbox wrappers as an intermediary layer that enables behavior-based analysis of unknown threats. This intermediary mechanism allows the system to detect Zero-day and APT attacks through sandbox execution while maintaining implementation simplicity through automated wrapping and analysis processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10735447B2System and method of protecting a network
Publication Date: 2020.08.04 COMODO SECURITY SOLUTIONS INC
  • US10735447B2 patent drawing
  • US10735447B2 patent drawing
  • US10735447B2 patent drawing

AI summary

There is provided a network appliance, methods and systems which intercept web and email traffic, extract executables, compare the executables with a policy and wrap the executables. Then, the wrapped executables are delivered to a client system in a manner to protect the network and end point devices, where the wrapped executables are run in a sandbox with all file system, registry accesses, communication and traffic isolated.