Production Network Security Validation via Destination Address Alteration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for testing the security posture of complex computer networks, such as production networks, are inadequate as they often rely on isolated laboratory testing which fails to validate the network's response to malicious traffic in a real-world scenario, particularly when dealing with stateful connections and known bad destinations.

Innovation Solution

A system and method that includes controllers within the production network to simulate malicious behavior, including attempts to contact known bad destinations, with a network device at the egress point configured to alter packet destinations, ensuring that security controls are validated without risking production network devices, by changing the destination address of packets before they leave the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If isolated laboratory testing is used to test security posture, then individual computing devices can be tested without risking them, but the complex production network response cannot be fully validated

Engineering Contradiction:
Improvesecurity posture validationVSAvoidproduction network scenario coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtualized testbed that copies the production network topology, including zones, devices, and traffic patterns, into a controlled environment. This virtual copy allows comprehensive security testing of the production network's response to malicious traffic without risking actual production systems, resolving the contradiction between safe isolation and realistic validation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements nested virtualization where virtual machines representing production network devices are contained within a virtualized infrastructure. This nested structure allows the complex production network to be embedded within a manageable test environment, enabling full scenario validation while maintaining isolation and control.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If laboratory testing without stateful connections is used, then simple packet streaming can be performed, but active stateful connections necessary for production routing cannot be tested

Engineering Contradiction:
Improvetesting simplicityVSAvoidproduction network accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements continuous stateful connection tracking within the virtualized testbed, maintaining active connections between virtual devices throughout the testing process. This allows complex stateful protocols and routing scenarios to be tested repeatedly and consistently, achieving production-accurate validation while keeping the testing process manageable through automation.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent dynamically adjusts network parameters such as connection states, routing tables, and device configurations within the virtualized environment to match production conditions. This enables precise reproduction of production network behavior for accurate security validation without requiring manual complexity in test execution.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If known bad destinations are tested in production network, then security controls can be validated, but the network may be compromised if security controls fail

Engineering Contradiction:
Improvesecurity control validationVSAvoidnetwork compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtualized intermediary infrastructure that mediates between the test traffic and the production network. This intermediary layer allows malicious traffic to be simulated and directed through the production network's security controls in a controlled manner, enabling validation of security responses while containing any potential harmful effects within the virtualized environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements beforehand cushioning by pre-configuring the virtualized testbed with isolation mechanisms and controlled failure scenarios. This prepares the testing environment to contain potential security control failures before they can affect the actual production network, allowing aggressive security validation without real compromise risk.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11349862B2Systems and methods for testing known bad destinations in a production network
Publication Date: 2022.05.31 GOOGLE LLC
  • US11349862B2 patent drawing
  • US11349862B2 patent drawing
  • US11349862B2 patent drawing

AI summary

The disclosure is directed to a system for testing known bad destinations while in a production network. The system can include a source controller and a destination controller in a production network. The source controller and the destination controller can have a configuration of a predetermined set of one or more known bad external destinations to test a security control device of the production network intermediary to the source controller and the destination controller. The source controller can be configured to communicate test traffic generated to a known bad external destination. The test traffic can pass through the security control device with a network identifier of the known bad external destination. The destination controller can be configured to receive the test traffic forwarded by a network device of the production network. The security control device can be validated whether or not the security control device applied security controls on the test traffic using the network identifier of the known bad external destination.