Threat Emulation Framework for Network Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network defense systems are reactionary and lack sufficient deception to gain insight into adversary actions, making them ineffective in mitigating and preventing attacks, especially as attacks become more aggressive and widespread.
Innovation Solution
The method involves creating virtual machines in a virtual network computing environment to emulate threat actors with sequences of attack steps, collecting behavioral and performance data, and presenting this data to users via an interface, allowing for the evaluation of security measures and defense strategies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If honeypots are used to detect adversary actions, then information about adversary capabilities can be obtained, but honeypots can be detected and do not provide a sufficiently realistic environment
Solution Approach 1:
The patent creates virtual copies of production network environments, systems, and data that mirror the real network architecture and assets. These virtual environments are indistinguishable from real ones to adversaries, providing realistic behavior while maintaining isolation for safe observation and analysis of attack patterns.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the real production network and the adversary. This virtual environment acts as a mediator that captures and analyzes adversary actions without exposing the actual production systems, enabling information gathering while maintaining system integrity.
2Reliability
If current defense tools are used, then network security can be maintained, but the system lacks ability to obtain insight into adversary actions for mitigation
Solution Approach 1:
The patent performs threat emulation and analysis in advance within virtual environments before adversaries attack the real production network. By pre-configuring virtual copies with known vulnerabilities and deploying them to attract adversaries, the system proactively gathers intelligence about attack methods, tools, and objectives before they threaten actual systems.
Solution Approach 2:
The patent implements continuous monitoring and analysis of adversary actions within virtual environments, capturing detailed behavioral data and attack patterns. This feedback loop provides actionable intelligence that feeds back into improving real-world defense strategies, detection rules, and security policies based on observed adversary tactics.
Data Source
AI summary
A method for emulating threats in virtual network computing environment is provided. The method comprises creating a number of virtual machines in the virtual network computing environment. A number of threat actors are emulated, wherein each threat actor comprises a number of threat artifacts that form a sequence of attack steps against the virtual network computing environment. The threat actors are then deployed against the virtual network computing environment. Behavioral data about actions of the threat actors in the virtual network computing environment is collected, as is performance data about the virtual network computing environment in response to the threat actors. The collected behavioral and performance data is then presented to a user via an interface.


