Network Obfuscation via Virtual Host Emulators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face increased difficulty in protection as they grow in size and complexity, with hackers using sophisticated tools to map and exploit networks through a single entry point, necessitating more efficient methods to counter advanced persistent threats and other attacks.

Innovation Solution

The implementation of software-defined host emulators and virtual machines creates a network infrastructure that obfuscates physical computers by generating a 'forest' of low-interaction emulators with pseudo-random IP addresses, which can outnumber real computers, and substitutes resource-intensive virtual machines to present false data to hackers, while intercepting and redirecting connection requests using software-defined networking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network perimeter is protected using traditional firewalls and authentication, then basic security is maintained, but the network becomes vulnerable to advanced persistent threats that can penetrate the perimeter

Engineering Contradiction:
Improvenetwork securityVSAvoidadvanced persistent threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates virtual copies of real network hosts called 'host emulators' that replicate the appearance and behavior of actual computers. These emulators are deployed throughout the network to confuse attackers and make it difficult to distinguish real hosts from fake ones, thereby protecting the real network perimeter from advanced threats

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces virtual machines as intermediary elements between the attacker and real network hosts. When an attacker interacts with a host emulator, a virtual machine substitutes to present false data, acting as a mediator that protects the real network infrastructure while allowing the attacker to continue probing

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If host emulators are deployed to outnumber real computers, then network obfuscation is improved, but resource consumption increases

Engineering Contradiction:
Improvenetwork obfuscationVSAvoidresource consumption
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent uses lightweight host emulators that can be quickly instantiated and terminated compared to deploying actual physical computers. These emulators are resource-efficient virtual constructs that provide sufficient obfuscation without the full resource cost of real hardware, and can be dynamically managed based on attack detection

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent implements dynamic deployment of host emulators that can be activated or deactivated based on network conditions and detected threats. The system adjusts the number and distribution of emulators dynamically, deploying more when attacks are detected and reducing resources when the network is stable

Inventive Principle:
Principle #15Dynamics

3Difficulty of detecting and measuring

If virtual machines are substituted for host emulators to present false data, then attacker confusion is increased, but system complexity increases

Engineering Contradiction:
Improveattacker confusionVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent segments the network defense system into distinct functional layers: host emulators for basic obfuscation, virtual machines for advanced deception, and a management system for coordination. This segmentation allows each component to handle specific tasks independently, managing overall system complexity while maximizing attacker confusion

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9729567B2Network infrastructure obfuscation
Publication Date: 2017.08.08 ACALVIO TECH
  • US9729567B2 patent drawing
  • US9729567B2 patent drawing
  • US9729567B2 patent drawing

AI summary

A shadow network, which can be a virtual reproduction of a real, physical, base computer network, is described. Shadow networks duplicate the topology, services, host, and network traffic of the base network using shadow hosts, which are low interaction, minimal-resource-using host emulators. The shadow networks are connected to the base network through virtual switches, etc. in order to form a large obfuscated network. When a hacker probes into a host emulator, a more resource-intensive virtual machine can be swapped in to take its place. When a connection is attempted from a host emulator to a physical computer, the a host emulator can step in to take the place of the physical computer, and software defined networking (SDN) can prevent collisions between the duplicated IP addresses. Replicating the shadow networks within the network introduces problems for hackers and allows a system administrator easier ways to identify intrusions.