Virtual Clone Manager for High-Fidelity Honey Network Emulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual machine environments for malware detection and security analysis fail to provide a realistic emulation of a target host and network environment, allowing attackers to detect the virtual sandbox and evade detection, as they lack synchronization with actual host attributes and network interactions, leading to inadequate threat intelligence and incomplete analysis of advanced threats like APTs.

Innovation Solution

A system for synchronizing a honey network configuration to reflect a target network environment, using a device profile data store and virtual clone manager to instantiate virtual clones of target devices with customized VM images, emulating multiple devices and their interactions to create a high-fidelity VM environment that mimics the actual network, making it difficult for attackers to distinguish from the real environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a virtual machine environment is used for malware detection, then security analysis capability is improved, but realism of target environment emulation deteriorates

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidrealism of target environment emulation
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent creates virtual clones that are precise copies of actual target devices, including their hardware configurations, operating systems, applications, and network settings. These clones are instantiated in a virtual machine environment but maintain high-fidelity replication of the target device attributes, allowing malware to be detonated in an environment that closely mimics the real target while still providing security analysis capabilities.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system dynamically configures virtual machine parameters to match the target device profile, including CPU architecture, memory size, storage configuration, installed software versions, and network interface settings. By adjusting these parameters to reflect the actual target environment, the virtual clone provides both the safety of virtualization and the realism needed for effective malware analysis.

Inventive Principle:
Principle #35Parameter changes

2Manufacturing precision

If virtual clones with customized VM images are instantiated, then fidelity of network environment emulation is improved, but system complexity increases

Engineering Contradiction:
Improvefidelity of network environment emulationVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system pre-configures virtual machine images with common operating systems, applications, and device profiles before they are needed for malware analysis. These customized VM images are stored in a library and can be quickly instantiated when a target device needs to be cloned, reducing the complexity of on-demand configuration while maintaining high fidelity emulation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual clone manager system performs multiple functions including device profile management, virtual machine image customization, clone instantiation, and network configuration. By consolidating these functions into a single management platform, the system reduces overall complexity despite the sophisticated emulation capabilities provided by the virtual clones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If multiple virtual clones are instantiated to emulate network interactions, then threat intelligence gathering is improved, but resource consumption increases

Engineering Contradiction:
Improvethreat intelligence gatheringVSAvoidresource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The system instantiates only the necessary number of virtual clones required for effective malware analysis, rather than creating clones for every possible target device. The virtual clone manager evaluates the malware sample and the target network environment to determine the optimal number of clones needed to gather sufficient threat intelligence without unnecessarily consuming computational resources.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The virtual clone environment is nested within the virtual machine infrastructure, which itself runs on physical hardware resources. This nested architecture allows multiple virtual clones to share underlying hardware resources through virtualization, reducing overall resource consumption while still providing isolated environments for malware detonation and intelligence gathering.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10992704B2Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network
Publication Date: 2021.04.27 PALO ALTO NETWORKS INC
  • US10992704B2 patent drawing
  • US10992704B2 patent drawing
  • US10992704B2 patent drawing

AI summary

Techniques for dynamic selection and generation of detonation location of suspicious content with a honey network are disclosed. In some embodiments, a system for dynamic selection and generation of detonation location of suspicious content with a honey network includes a virtual machine (VM) instance manager that manages a plurality of virtual clones executed in an instrumented VM environment, in which the plurality of virtual clones executed in the instrumented VM environment correspond to the honey network that emulates a plurality of devices in an enterprise network; and an intelligent malware detonator that detonates a malware sample in at least one of the plurality of virtual clones executed in the instrumented VM environment.