Simulated Environment Layer for Active Cyber Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security measures, such as honeypots and sandboxes, are passive and lack the ability to actively engage attackers, failing to capture valuable forensic information like tactics, techniques, and procedures (TTPs) and Indicators of Compromise (IoCs) effectively.

Innovation Solution

A method that utilizes a simulated environment layer configured using generative adversarial network (GAN) machine learning to mirror a production environment, routing suspect users' interactions to this simulated layer, where the environment is dynamically modified to capture TTPs and IoCs, creating a continually changing attack surface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional honeypots and sandboxes are used to detect attackers, then security monitoring capability is improved, but the ability to actively engage attackers and capture forensic information deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidforensic information capture
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The simulated environment dynamically adapts its behavior based on attacker actions, transitioning from static honeypot configurations to a living, evolving system that responds to threats in real-time, thereby maintaining engagement while capturing comprehensive forensic data

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The simulated environment acts as an intermediary layer between the attacker and the production system, allowing forensic information to be captured in the simulated layer while preventing actual harm to production assets

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If production environment is exposed to attackers for detection, then attack data collection is improved, but production system security deteriorates

Engineering Contradiction:
Improveattack data collectionVSAvoidproduction system security
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system segments the attack surface by creating a separate simulated environment that mirrors production capabilities while isolating actual production systems, allowing attack data collection without exposing production assets to harm

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A simulated environment is created as a copy of the production environment, allowing attackers to interact with the replica while the original production system remains protected, thereby collecting forensic information without compromising production security

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If static honeypot configurations are used, then deployment simplicity is improved, but ability to maintain attacker engagement deteriorates

Engineering Contradiction:
Improvedeployment simplicityVSAvoidattacker engagement duration
Core Design Contradiction:
Ease of manufactureVSDuration of action of moving object

Solution Approach 1:

The system transitions from static honeypot configurations to a dynamic simulated environment that evolves in response to attacker behavior, maintaining long-term engagement while managing complexity through automated adaptation mechanisms

Inventive Principle:
Principle #15Dynamics

4Loss of information

If simulated environment is dynamically modified to engage attackers, then forensic information capture is improved, but system complexity deteriorates

Engineering Contradiction:
Improveforensic information captureVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The simulated environment employs self-service mechanisms where automated systems manage the complexity of dynamic modifications, allowing the environment to adapt and evolve without requiring proportional increases in human operational complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11483318B2Providing network security through autonomous simulated environments
Publication Date: 2022.10.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11483318B2 patent drawing
  • US11483318B2 patent drawing
  • US11483318B2 patent drawing

AI summary

A method to secure a production environment in a network begins by associating a set of resources into a simulated environment layer configured to simulate at least a portion of the production environment. A preferred approach to building the simulated environment layer utilizes generative adversarial network (GAN) machine learning modeling. Upon detecting a suspect user attempting to interact with the production environment, one or more requests received from the suspect user are routed to the simulated environment layer as opposed to the production environment. At least one behavior of the simulated environment layer is then modified as the suspect user interacts within the simulated environment layer. The modified behavior facilitates that an attack initiated by the suspect user can proceed. Information (such as the user's tactics, techniques and procedures (TPPs), or other Indicators of Compromise (IoCs) associated with the attack is captured for analysis and subsequent action.