Sandbox Analysis via Victim Machine Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current sandbox systems fail to effectively capture and analyze the behavior of illicit programs, allowing attackers to detect and suspend cyber attacks by recognizing the presence of a sandbox or security apparatus, thereby preventing the execution and operation of malicious programs.

Innovation Solution

An attack content analysis program that executes read-based instructions on a victim machine while executing write-based instructions within a sandbox system, making it difficult for attackers to detect the presence of the sandbox and allowing the program to emulate and analyze illicit operations without affecting the attack target machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the illicit program is executed in a sandbox environment, then the attack target machine is protected from damage, but the attacker can detect the sandbox presence and suspend the attack

Engineering Contradiction:
Improveprotection of attack target machineVSAvoiddetection of sandbox presence by attacker
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a victim machine as an intermediary between the sandbox and the attacker. The illicit program executes in the sandbox but interacts with the victim machine through a simulated session, making the attacker believe they are communicating with the actual attack target. This mediator hides the sandbox environment from the attacker while maintaining protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the attack target machine's environment by setting up a victim machine that mimics the target's characteristics. The illicit program interacts with this copy rather than the real target, allowing analysis while preventing detection of the sandbox. The victim machine replicates the target's profile information, screen shots, and machine environment.

Inventive Principle:
Principle #26Copying

2Loss of information

If the illicit program is executed on the attack target machine, then the attacker's behavior can be captured, but the attack target machine suffers damage

Engineering Contradiction:
Improvecapture of attacker behaviorVSAvoiddamage to attack target machine
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the system into three distinct components: the sandbox (for safe execution), the victim machine (for interaction), and the attack target machine (for protection). This segmentation allows the illicit program to execute and interact without damaging the actual target, while still capturing attacker behavior through the victim machine's responses.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The victim machine serves as an intermediary that absorbs the harmful interactions. The illicit program sends requests to the victim machine instead of the attack target machine, and the victim machine generates appropriate responses without being damaged. This mediator captures the attacker's behavior while protecting the real target.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the sandbox executes all instructions locally, then the analysis is simple, but the attacker can easily detect the sandbox environment

Engineering Contradiction:
Improvesimplicity of sandbox operationVSAvoiddetection of sandbox by attacker
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a victim machine as an intermediary that the sandbox communicates with through a simulated network session. This adds complexity to the sandbox operation but effectively hides the sandbox environment from the attacker, as the illicit program believes it is interacting with the real target machine through the victim machine.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10601867B2Attack content analysis program, attack content analysis method, and attack content analysis apparatus
Publication Date: 2020.03.24 FUJITSU LTD
  • US10601867B2 patent drawing
  • US10601867B2 patent drawing
  • US10601867B2 patent drawing

AI summary

An attack content analysis program causing a computer to execute a process including, receiving transmit data including a first program and transmitted, through a second network, to a first machine connected to a first network, transmitting, after initiation of the first program, a read-based instruction for the first machine via a first session established between the computer and a second machine, which is different from the first machine; and executing, after initiation of the first program, a write-based instruction for the first machine on behalf of the first machine.