Network Appliance Executable Wrapping for Zero-Day Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional signature-based security solutions are ineffective against Zero-day and Advanced Persistent Threat (APT) attacks, and virtual machine-based appliances face performance bottlenecks, ease of bypass, delayed threat detection, and user inconvenience.

Innovation Solution

A network appliance that intercepts and analyzes network traffic, wraps executable applications in a protective manner, and runs them in a sandbox environment on client systems for behavior analysis, ensuring secure delivery and preventing threats from compromising local systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all threats are executed and analyzed in the appliance, then threat detection capability is improved, but appliance performance becomes a bottleneck

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidappliance performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the threat analysis process into two parts: the appliance performs initial interception and wrapping of executable files, while the actual behavior analysis is distributed to client systems through sandbox environments. This segmentation removes the performance bottleneck from the appliance while maintaining comprehensive threat detection capability across multiple endpoints.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual machine based analysis is used, then threat analysis capability is improved, but it can be bypassed easily by virtual machine detection

Engineering Contradiction:
Improvethreat analysis capabilityVSAvoidbypass resistance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system introduces a wrapper as an intermediary layer between the executable file and the sandbox environment. This wrapper prevents malware from detecting that it is running in a virtualized or sandboxed environment, thereby eliminating the bypass vulnerability while maintaining the analytical capabilities of controlled environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If threats are analyzed in a virtual machine appliance, then security analysis is improved, but users have to wait until analysis completes

Engineering Contradiction:
Improvesecurity analysisVSAvoiduser waiting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary wrapping of executable files at the appliance level before delivery to client systems. This preliminary action prepares the files for safe execution in sandbox environments, enabling users to receive and potentially use wrapped executables immediately while security analysis occurs concurrently in the background, eliminating the waiting period.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If signature-based security solutions are used, then known threat detection is improved, but Zero-day and APT attacks cannot be defended against

Engineering Contradiction:
Improveknown threat detectionVSAvoidZero-day and APT defense
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system transitions from static signature-based detection to dynamic behavior analysis through sandbox execution. Wrapped executables are allowed to run in controlled sandbox environments where their actual behavior is monitored and analyzed in real-time, enabling detection of Zero-day and APT attacks that lack known signatures while maintaining the ability to detect known threats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12155624B2System and method of protecting a network
Publication Date: 2024.11.26 COMODO SECURITY SOLUTIONS INC
  • US12155624B2 patent drawing
  • US12155624B2 patent drawing
  • US12155624B2 patent drawing

AI summary

There is provided a network appliance, methods and systems which intercept web and email traffic, extract executables, compare the executables with a policy and wrap the executables. Then, the wrapped executables are delivered to a client system in a manner to protect the network and end point devices, where the wrapped executables are run in a sandbox with all file system, registry accesses, communication and traffic isolated. Systems, networks, and methods for the prevention of phishing are also provided.