Virtual Client Emulator for Real-Time Threat Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware systems face challenges in accurately and efficiently verifying cyber threats in real-time, leading to potential false alarms and inadequate threat assessment.

Innovation Solution

A real-time cyber threat indicator verification mechanism (TIVM) that instantiates virtual client emulators to interact with suspected threat sources, providing a confidence indicator and generating a confirmation report, thereby enhancing the accuracy and timeliness of threat assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If virtual client emulators are instantiated to verify threat indicators in real-time, then measurement precision of threat assessment is improved, but device complexity increases

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces virtual client emulators as intermediary components that mediate between the threat indicator verification system and the suspected threat sources. These emulators simulate real client behavior to interact with potential threats without exposing actual systems, thereby improving verification accuracy while isolating the complexity of the emulation process to dedicated virtual components rather than the core system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of client systems through virtual client emulators that replicate real client behavior and characteristics. These copies allow the system to safely interact with and verify threat indicators against suspected sources without using actual client systems, improving measurement precision while containing complexity within the virtualization layer.

Inventive Principle:
Principle #26Copying

2Reliability

If virtual client emulators are used to interact with threat sources, then reliability of threat verification is improved, but productivity decreases due to additional verification steps

Engineering Contradiction:
Improvethreat verification reliabilityVSAvoidthreat verification speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary verification actions by instantiating virtual client emulators to proactively test and validate threat indicators before they can impact real systems. The emulators are prepared and configured in advance to quickly interact with suspected threat sources, allowing the system to establish reliable verification results ahead of time while maintaining readiness for rapid response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual client emulators are designed to autonomously perform verification tasks by automatically interacting with suspected threat sources based on received threat indicators. The emulators self-manage the verification process, collecting and reporting results without requiring manual intervention, thereby improving reliability through consistent automated execution while minimizing productivity loss by eliminating human processing bottlenecks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10027705B1Apparatuses, methods and systems for a real-time cyber threat indicator verification mechanism
Publication Date: 2018.07.17 LOOKINGGLASS CYBER SOLUTIONS LLC
  • US10027705B1 patent drawing
  • US10027705B1 patent drawing
  • US10027705B1 patent drawing

AI summary

The real-time cyber threat indicator verification mechanism technology (hereinafter “TIVM”) instantiates one or more virtual client emulators to access a source of a threat, in response to a received threat indicator, so as to evaluate validity and/or severity of the potential threat. In one embodiment, the TIVM may receive a cyber threat indicator having identifying information of a cyber threat source; instantiate, in response to the cyber threat indicator, a virtual client emulator; send a control message to cause the virtual client emulator to interact with the cyber threat source based on the identifying information; obtain a confidence indicator relating to the cyber threat indicator based on interaction between the virtual client emulator and the cyber threat source; and generate a cyber threat indicator confirmation report including the confidence indicator.