Dynamic Security Assessment via Virtual Attack Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network security strategies are predominantly defensive and fail to effectively counter denial of service attacks, as they do not proactively identify and mitigate vulnerabilities, leading to disruptions and unauthorized access.
Innovation Solution
Implement a system that employs an offensive strategy by using virtual inert simulated attacks to assess vulnerabilities and block malicious IP addresses, while allowing legitimate requests to proceed, utilizing secondary network computers to identify and manage risks dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If defensive security strategies (filtering, monitoring) are used to protect computer networks, then system security is maintained, but the system cannot effectively counter denial of service attacks and remains vulnerable to disruptions
Solution Approach 1:
The patent inverts the traditional defensive security approach by implementing an offensive strategy. Instead of passively defending against attacks, the system actively launches simulated attacks on requesting computers to assess their vulnerability. This inversion allows the defended computer to identify and block malicious requests before they can cause denial of service, while still allowing legitimate requests to proceed.
Solution Approach 2:
The system performs preliminary actions by conducting virtual inert simulated attacks on requesting computers before allowing them to access services. This advance assessment of vulnerability enables the system to proactively identify potentially malicious computers and block them before they can participate in denial of service attacks, rather than reacting after damage occurs.
2Measurement precision
If vulnerability scanning tools are used to identify security loopholes, then potential vulnerabilities can be located, but malicious individuals can also use these same tools to identify vulnerable computers for attacks
Solution Approach 1:
The patent converts the harmful effect of vulnerability identification into a beneficial security measure. By launching simulated attacks using the same tools that attackers would use, the system identifies vulnerable computers and blocks them from accessing services. This transforms the risk of exposure from vulnerability scanning into a protective mechanism that prevents malicious exploitation.
Solution Approach 2:
The system introduces an intermediary layer of simulated attacks between the requesting computer and the defended computer. This intermediary assessment process evaluates the requesting computer's vulnerability without directly exposing the defended computer to real attacks, and blocks malicious requests before they reach the target system.
3Reliability
If all requesting computers are blocked during a denial of service attack to prevent overload, then the defended computer is protected from disruption, but legitimate users cannot access services
Solution Approach 1:
The patent applies local quality by differentiating between legitimate and malicious requesting computers based on their vulnerability assessment results. Instead of uniformly blocking all requests, the system selectively blocks only those computers that fail the simulated attack test (indicating potential malicious intent), while allowing legitimate users to access services normally.
Solution Approach 2:
The system implements feedback by using the results of simulated attacks on requesting computers to dynamically adjust access decisions. Computers that pass the vulnerability assessment receive permission to access services, while those that fail are blocked. This feedback mechanism enables intelligent discrimination between legitimate and malicious traffic during denial of service attacks.
Data Source
AI summary
Systems, program product, and methods related to dynamic Internet security and risk assessment and management, are provided. For example, a system, program product, and method of identifying and servicing actual customer requests to a defended or protected computer or server can include the steps/operations of receiving by the defended computer, a service request from each of a plurality of IP addresses associated with a separate one of a plurality of service requesting computers, sending an inspection code adapted to perform a virtual attack on each existing service requesting computers at each respective associated IP address, and restricting provision of services from the defended computer to a subset of the service requesting computers identified for restriction when a security feature of the respective service requesting computer is determined to have been defeated by the virtual attack.


