Threat Emulation Framework for Network Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network defense systems are reactionary and lack sufficient deception to gain insight into adversary actions, making them ineffective in mitigating and preventing attacks, especially as attacks become more aggressive and widespread.

Innovation Solution

The method involves creating virtual machines in a virtual network computing environment to emulate threat actors with sequences of attack steps, collecting behavioral and performance data, and presenting this data to users via an interface, allowing for the evaluation of security measures and defense strategies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If honeypots are used to detect adversary actions, then information about adversary capabilities can be obtained, but honeypots can be detected and do not provide a sufficiently realistic environment

Engineering Contradiction:
Improveinformation about adversary capabilitiesVSAvoidrealism of environment
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent creates virtual copies of production network environments, systems, and data that mirror the real network architecture and assets. These virtual environments are indistinguishable from real ones to adversaries, providing realistic behavior while maintaining isolation for safe observation and analysis of attack patterns.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the real production network and the adversary. This virtual environment acts as a mediator that captures and analyzes adversary actions without exposing the actual production systems, enabling information gathering while maintaining system integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If current defense tools are used, then network security can be maintained, but the system lacks ability to obtain insight into adversary actions for mitigation

Engineering Contradiction:
Improvenetwork securityVSAvoidinsight into adversary actions
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent performs threat emulation and analysis in advance within virtual environments before adversaries attack the real production network. By pre-configuring virtual copies with known vulnerabilities and deploying them to attract adversaries, the system proactively gathers intelligence about attack methods, tools, and objectives before they threaten actual systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring and analysis of adversary actions within virtual environments, capturing detailed behavioral data and attack patterns. This feedback loop provides actionable intelligence that feeds back into improving real-world defense strategies, detection rules, and security policies based on observed adversary tactics.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11336690B1Threat emulation framework
Publication Date: 2022.05.17 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US11336690B1 patent drawing
  • US11336690B1 patent drawing
  • US11336690B1 patent drawing

AI summary

A method for emulating threats in virtual network computing environment is provided. The method comprises creating a number of virtual machines in the virtual network computing environment. A number of threat actors are emulated, wherein each threat actor comprises a number of threat artifacts that form a sequence of attack steps against the virtual network computing environment. The threat actors are then deployed against the virtual network computing environment. Behavioral data about actions of the threat actors in the virtual network computing environment is collected, as is performance data about the virtual network computing environment in response to the threat actors. The collected behavioral and performance data is then presented to a user via an interface.