Sandboxed Computing Environment for Malware Command and Control Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions to prevent malware from contacting command and control servers are often costly and difficult to maintain, and still allow malicious activities to occur despite defensive measures.

Innovation Solution

Implementing a sandboxed computing environment with internal and host-based firewalls, along with border and proxy devices, to isolate and block unauthorized communications, ensuring that only authenticated and authorized interactions with untrusted networks occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based firewalls and elaborate defensive protections are implemented, then security protection is improved, but system complexity and maintenance difficulty increase

Engineering Contradiction:
Improvesecurity protectionVSAvoiddefensive system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a sandboxed computing environment as an intermediary layer between the untrusted network and the host system. This sandbox acts as a mediator that isolates malware execution from the main system, allowing security monitoring without direct exposure. The sandbox container process enforces an internal isolation firewall that mediates all communication between isolated and non-isolated environments, simplifying the overall security architecture while maintaining strong protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the computing environment into distinct isolated and non-isolated memory spaces. The sandboxed environment is divided into separate containment zones with controlled access points. This segmentation allows the system to maintain multiple security zones with different trust levels, reducing the complexity of protecting the entire system uniformly while still providing comprehensive security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If sandboxed computing environment with internal isolation firewall is implemented, then malware communication blocking is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvemalware communication blockingVSAvoiduser access to untrusted devices
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The sandboxed computing environment is designed to serve multiple functions: it acts as both a secure execution zone for untrusted content and a controlled communication gateway. The same sandbox infrastructure that blocks malware also enables authorized user access to untrusted devices through controlled interfaces. This multi-functionality maintains ease of operation while ensuring security, as users interact with a unified interface that handles both legitimate and malicious content appropriately.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements monitoring and control mechanisms that provide feedback between the sandboxed environment and the host system. Authorized user actions are tracked and validated, allowing legitimate access to untrusted devices while blocking malicious activities. The feedback loop enables dynamic adjustment of access controls based on detected threats, maintaining both security and operational ease without requiring users to manually configure complex security settings.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11552987B2Systems and methods for command and control protection
Publication Date: 2023.01.10 CROGA INNOVATIONS LTD
  • US11552987B2 patent drawing
  • US11552987B2 patent drawing
  • US11552987B2 patent drawing

AI summary

A host computer system may be configured to connect to a network. The host computer system may be configured to implement a workspace and an isolated computing environment. The host computer system may be configured to isolate the isolated computing environment from the workspace using an internal isolation firewall. The internal isolation firewall may be configured to prevent data from being communicated between the isolated computing environment and the workspace, for example, without an explicit user input. The host computer system may be configured to implement one or more mechanisms that prevent malware received by the host computer system from receiving external communications from an external source. The one or more mechanisms may be configured to prevent control of the malware by the external source. The one or more mechanisms may be configured to prevent the malware from establishing a command channel with the external source.