Virtual Encapsulated Instances for Cyberattack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity methods are limited in dynamically deploying countermeasures during a cyberattack, leading to potential data loss and prolonged recovery times, as they often rely on proactive methods like honeypots and canaries that do not minimize attack consequences.

Innovation Solution

A system that detects malicious network traffic, identifies compromised software components, performs digital twin simulations to assess risks, and redirects malicious traffic to an encapsulated environment, allowing the production system to continue operating without disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If current cybersecurity methods (honeypots, canaries) are used to detect attacks, then attack detection capability is improved, but the ability to dynamically deploy countermeasures and minimize attack consequences deteriorates

Engineering Contradiction:
Improveattack detection capabilityVSAvoidability to minimize attack consequences
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent creates a copy (clone) of the compromised software component and migrates it to an encapsulated environment. This copy allows the system to continue operating while the original compromised component is isolated and restored, thereby minimizing attack consequences while maintaining detection capability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the software component into an encapsulated environment that can be independently managed. By separating the compromised component into its own encapsulated instance, the system can isolate malicious activity without affecting the production system, thus improving both detection and consequence minimization

Inventive Principle:
Principle #1Segmentation

2Reliability

If software components are restored after compromise, then system reliability is improved, but recovery time and operational disruption increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by creating a clone of the software component before the compromise fully impacts the production system. This pre-prepared clone can be immediately deployed to the encapsulated environment upon detection of malicious activity, significantly reducing recovery time and operational disruption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic restoration by automatically detecting compromised components and triggering the migration of cloned versions to encapsulated environments. This dynamic response eliminates manual intervention and prolonged recovery processes, improving both reliability and reducing time loss

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240348626A1Virtual encapsulated instances for mitigation of cyberattacks
Publication Date: 2024.10.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20240348626A1 patent drawing
  • US20240348626A1 patent drawing
  • US20240348626A1 patent drawing

AI summary

According to one embodiment, a method, computer system, and computer program product for mitigating cyberattacks is provided. The present invention may include responding to a verification of a detected attack on a system, by detecting one or more modifications to one or more software components made by malicious network traffic; identifying the malicious network traffic; determining one or more compromised software components based on the detected one or more modifications and the identified malicious network traffic; performing digital twin simulation to evaluate one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate; creating an encapsulated environment; provisioning the one or more software components to encapsulate to the encapsulated environment; and redirecting the malicious network traffic to the encapsulated environment.