Simulator Nodes for Malware Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-malware systems are ineffective against sophisticated malware threats as malicious users continually find ways to circumvent protection, necessitating a new and advanced system for securing computing devices against malware vulnerabilities.

Innovation Solution

A method and system that utilizes simulator nodes to emulate operations in a target system, simulate malicious actions, and determine their success, allowing for the configuration of security systems and identification of vulnerabilities, including virtual machines, virtual appliances, and physical devices, to simulate breach scenarios and analyze results for remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware software is used to block malicious users, then basic malware protection is provided, but sophisticated malware can still circumvent the protection

Engineering Contradiction:
Improvemalware protection effectivenessVSAvoidmalware circumvention capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by simulating malicious actions in a controlled environment before they can affect the actual target system. The simulator nodes execute predetermined malicious scenarios (such as virus infections, Trojan deployments, DDoS attacks) to proactively identify vulnerabilities and test security responses in advance, allowing the real system to be hardened against these threats before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces simulator nodes as intermediary elements that mediate between the actual malicious threats and the target system. These simulator nodes act as safe proxies that can execute malicious code and scenarios without directly compromising the target system, while still providing comprehensive testing and analysis of security mechanisms and vulnerability responses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If simulator nodes are allocated to simulate malicious actions, then vulnerability detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The system segments the simulation function into separate, dedicated simulator nodes that are distinct from the target system architecture. Each simulator node is independently configured to represent specific malicious actors or attack vectors, allowing the complexity of simulation to be isolated and managed separately from the core business systems being protected, thus improving vulnerability detection without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs copying by creating virtual representations of malicious systems, networks, and attack scenarios within the simulator nodes. Instead of directly analyzing complex real-world malware and attack patterns, the system creates simplified copies and models of these threats, making the detection and measurement of vulnerabilities more manageable while reducing the complexity burden on the main system architecture.

Inventive Principle:
Principle #26Copying

3Reliability

If breach scenarios are simulated to identify vulnerabilities, then security improvement is achieved, but time consumption increases

Engineering Contradiction:
Improvesystem security levelVSAvoidsimulation execution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic action by scheduling simulation campaigns to execute at predetermined intervals rather than continuously. The simulator nodes can be configured to run vulnerability assessment simulations periodically (e.g., daily, weekly, or monthly), allowing the system to maintain security through regular updates while avoiding the time consumption of continuous simulation. This enables security improvements to be achieved through scheduled maintenance windows rather than real-time disruption.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies partial action by selecting and simulating only the most critical and relevant breach scenarios rather than exhaustively testing all possible attack vectors. The simulator nodes can be configured to focus on high-impact vulnerabilities and commonly exploited weaknesses, providing sufficient security improvement through targeted simulation while significantly reducing the time required compared to comprehensive exhaustive testing of all possible scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20160308895A1System and method for securing a computer system against malicious actions by utilizing virtualized elements
Publication Date: 2016.10.20 SAFEBREACH LTD
  • US20160308895A1 patent drawing
  • US20160308895A1 patent drawing
  • US20160308895A1 patent drawing

AI summary

A method and system for protecting a computing system, the method comprising allocating simulator nodes, the simulator nodes emulating operations of devices in a target system, simulating malicious action utilizing the simulator nodes, and determining that the malicious action was successfully.