Network Attack Emulation Using Reconstructed Packets for Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network security systems lack an effective method to emulate attacks accurately, making it difficult to verify the responsiveness of security technologies to real-world threats.

Innovation Solution

A method is developed to emulate a malicious attack on a target network by reconstructing data packets from a previous attack, assigning behavior triggers, and initiating packet transmissions between assets within and outside the network, using a computer system to verify the response of security technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual verification methods are used to test security technologies, then detection accuracy can be maintained, but operational efficiency deteriorates and manual effort increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates copies of actual attack data packets and reconstructs them for use in emulation scenarios. Instead of manually analyzing each attack variant, the system automatically generates and manages multiple copies of attack data, enabling efficient testing of security technologies against replicated threat scenarios while maintaining detection accuracy through faithful reproduction of original attack characteristics

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary actions by pre-processing and organizing attack data packets before emulation scenarios are executed. Attack data is collected, reconstructed, and prepared in advance, allowing security technologies to be tested immediately when scenarios are activated without requiring manual setup or data preparation during the actual testing process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive attack scenarios are emulated to verify security responses, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidemulation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the attack emulation system into distinct functional components: data packet collection modules, reconstruction modules, scenario definition modules, and execution modules. Each component handles a specific aspect of the emulation process, allowing comprehensive attack scenarios to be tested while managing system complexity through modular architecture where each segment can be independently configured and maintained

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal emulation framework that can handle multiple types of attacks and security technologies through a common infrastructure. The system uses standardized data packet formats and scenario definitions that can be applied across different attack vectors and security products, reducing the need for separate specialized systems for each attack type or security technology

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12418559B2Method for emulating an attack on an asset within a target network
Publication Date: 2025.09.16 ATTACKIQ
  • US12418559B2 patent drawing
  • US12418559B2 patent drawing
  • US12418559B2 patent drawing

AI summary

One variation of a method includes: generating data packets by recombining packet fragments transmitted between machines during a prior malicious attack on a reference network; defining triggers for transmission of the data packets between pairs of assets connected to a target network; generating an executable file including the data packets and the triggers; initiating transmission of the data packets between the pairs of assets according to the triggers to emulate the malicious attack on the target network; serving a context file, specifying artifacts representing indicators of the malicious attack responsive to execution of behaviors corresponding to these triggers, to a security technology deployed on the target network; and, in response to absence of an event record related to the emulation in a log of the security technology, generating a prompt to reconfigure the security technology to respond to the malicious attack.