Dynamic Security Assessment via Virtual Attack Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network security strategies are predominantly defensive and fail to effectively counter denial of service attacks, as they do not proactively identify and mitigate vulnerabilities, leading to disruptions and unauthorized access.

Innovation Solution

Implement a system that employs an offensive strategy by using virtual inert simulated attacks to assess vulnerabilities and block malicious IP addresses, while allowing legitimate requests to proceed, utilizing secondary network computers to identify and manage risks dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If defensive security strategies (filtering, monitoring) are used to protect computer networks, then system security is maintained, but the system cannot effectively counter denial of service attacks and remains vulnerable to disruptions

Engineering Contradiction:
Improvesystem securityVSAvoidvulnerability to denial of service attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional defensive security approach by implementing an offensive strategy. Instead of passively defending against attacks, the system actively launches simulated attacks on requesting computers to assess their vulnerability. This inversion allows the defended computer to identify and block malicious requests before they can cause denial of service, while still allowing legitimate requests to proceed.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary actions by conducting virtual inert simulated attacks on requesting computers before allowing them to access services. This advance assessment of vulnerability enables the system to proactively identify potentially malicious computers and block them before they can participate in denial of service attacks, rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If vulnerability scanning tools are used to identify security loopholes, then potential vulnerabilities can be located, but malicious individuals can also use these same tools to identify vulnerable computers for attacks

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidexposure to targeted attacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful effect of vulnerability identification into a beneficial security measure. By launching simulated attacks using the same tools that attackers would use, the system identifies vulnerable computers and blocks them from accessing services. This transforms the risk of exposure from vulnerability scanning into a protective mechanism that prevents malicious exploitation.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The system introduces an intermediary layer of simulated attacks between the requesting computer and the defended computer. This intermediary assessment process evaluates the requesting computer's vulnerability without directly exposing the defended computer to real attacks, and blocks malicious requests before they reach the target system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all requesting computers are blocked during a denial of service attack to prevent overload, then the defended computer is protected from disruption, but legitimate users cannot access services

Engineering Contradiction:
Improveprotection from disruptionVSAvoidaccessibility to legitimate users
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating between legitimate and malicious requesting computers based on their vulnerability assessment results. Instead of uniformly blocking all requests, the system selectively blocks only those computers that fail the simulated attack test (indicating potential malicious intent), while allowing legitimate users to access services normally.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback by using the results of simulated attacks on requesting computers to dynamically adjust access decisions. Computers that pass the vulnerability assessment receive permission to access services, while those that fail are blocked. This feedback mechanism enables intelligent discrimination between legitimate and malicious traffic during denial of service attacks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8069471B2Internet security dynamics assessment system, program product, and related methods
Publication Date: 2011.11.29 LOCKHEED MARTIN CORP
  • US8069471B2 patent drawing
  • US8069471B2 patent drawing
  • US8069471B2 patent drawing

AI summary

Systems, program product, and methods related to dynamic Internet security and risk assessment and management, are provided. For example, a system, program product, and method of identifying and servicing actual customer requests to a defended or protected computer or server can include the steps/operations of receiving by the defended computer, a service request from each of a plurality of IP addresses associated with a separate one of a plurality of service requesting computers, sending an inspection code adapted to perform a virtual attack on each existing service requesting computers at each respective associated IP address, and restricting provision of services from the defended computer to a subset of the service requesting computers identified for restriction when a security feature of the respective service requesting computer is determined to have been defeated by the virtual attack.