Network Obfuscation via Virtual Host Emulators
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer networks face increased difficulty in protection as they grow in size and complexity, with hackers using sophisticated tools to map and exploit networks through a single entry point, necessitating more efficient methods to counter advanced persistent threats and other attacks.
Innovation Solution
The implementation of software-defined host emulators and virtual machines creates a network infrastructure that obfuscates physical computers by generating a 'forest' of low-interaction emulators with pseudo-random IP addresses, which can outnumber real computers, and substitutes resource-intensive virtual machines to present false data to hackers, while intercepting and redirecting connection requests using software-defined networking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network perimeter is protected using traditional firewalls and authentication, then basic security is maintained, but the network becomes vulnerable to advanced persistent threats that can penetrate the perimeter
Solution Approach 1:
The patent creates virtual copies of real network hosts called 'host emulators' that replicate the appearance and behavior of actual computers. These emulators are deployed throughout the network to confuse attackers and make it difficult to distinguish real hosts from fake ones, thereby protecting the real network perimeter from advanced threats
Solution Approach 2:
The patent introduces virtual machines as intermediary elements between the attacker and real network hosts. When an attacker interacts with a host emulator, a virtual machine substitutes to present false data, acting as a mediator that protects the real network infrastructure while allowing the attacker to continue probing
2Difficulty of detecting and measuring
If host emulators are deployed to outnumber real computers, then network obfuscation is improved, but resource consumption increases
Solution Approach 1:
The patent uses lightweight host emulators that can be quickly instantiated and terminated compared to deploying actual physical computers. These emulators are resource-efficient virtual constructs that provide sufficient obfuscation without the full resource cost of real hardware, and can be dynamically managed based on attack detection
Solution Approach 2:
The patent implements dynamic deployment of host emulators that can be activated or deactivated based on network conditions and detected threats. The system adjusts the number and distribution of emulators dynamically, deploying more when attacks are detected and reducing resources when the network is stable
3Difficulty of detecting and measuring
If virtual machines are substituted for host emulators to present false data, then attacker confusion is increased, but system complexity increases
Solution Approach 1:
The patent segments the network defense system into distinct functional layers: host emulators for basic obfuscation, virtual machines for advanced deception, and a management system for coordination. This segmentation allows each component to handle specific tasks independently, managing overall system complexity while maximizing attacker confusion
Data Source
AI summary
A shadow network, which can be a virtual reproduction of a real, physical, base computer network, is described. Shadow networks duplicate the topology, services, host, and network traffic of the base network using shadow hosts, which are low interaction, minimal-resource-using host emulators. The shadow networks are connected to the base network through virtual switches, etc. in order to form a large obfuscated network. When a hacker probes into a host emulator, a more resource-intensive virtual machine can be swapped in to take its place. When a connection is attempted from a host emulator to a physical computer, the a host emulator can step in to take the place of the physical computer, and software defined networking (SDN) can prevent collisions between the duplicated IP addresses. Replicating the shadow networks within the network introduces problems for hackers and allows a system administrator easier ways to identify intrusions.


