Virtual Organization Incubator for Malware Operator Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack effective means to capture and study malware operator behavior without being detected, as they interact with victim systems, making it difficult to develop targeted defense strategies.

Innovation Solution

Creating a virtual organization with simulated users and machines that mimic real corporate networks, allowing malware operators to interact unknowingly, while monitoring and recording their actions to build profiles and gather intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional honeypots and sandboxes are used to study malware, then malware behavior can be observed, but malware operators remain undetected and cannot be fully profiled due to lack of realistic interaction

Engineering Contradiction:
Improvemalware operator behavior trackingVSAvoidrealistic corporate environment simulation
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates virtual copies of corporate networks, users, and systems that replicate realistic organizational structures and behaviors. These synthetic environments mirror real corporate infrastructures, allowing malware operators to interact with simulated entities that behave like genuine targets, thereby enabling comprehensive behavior profiling without compromising actual systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system segments the corporate environment into multiple virtual components including simulated users, machines, networks, and organizational structures. Each segment can be independently configured and monitored, allowing researchers to track malware operator interactions with specific elements while maintaining overall system realism and control.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If malware operators interact with victim systems, then valuable intelligence can be gathered, but the operators detect the monitoring and alter their behavior

Engineering Contradiction:
Improvemalware operator intelligenceVSAvoidoperator awareness of monitoring
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces virtual organizations and simulated users as intermediaries between the malware operators and the research system. These intermediaries conceal the true monitoring nature of the system, allowing operators to interact naturally without detecting the research purpose, thereby preventing behavior alteration while still enabling comprehensive intelligence gathering.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive monitoring of malware operators is implemented, then detailed behavior profiles can be built, but system complexity and resource requirements increase

Engineering Contradiction:
Improveoperator behavior profilingVSAvoidvirtual organization infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses virtualized copies of corporate infrastructure that can be replicated and scaled efficiently. These virtual environments consume fewer resources than physical systems while maintaining full monitoring capabilities, allowing comprehensive behavior profiling without proportionally increasing hardware complexity and resource requirements.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10567432B2Systems and methods for incubating malware in a virtual organization
Publication Date: 2020.02.18 VERISIGN INC
  • US10567432B2 patent drawing
  • US10567432B2 patent drawing
  • US10567432B2 patent drawing

AI summary

Systems and methods for tracking malware operator behavior patterns in a network environment simulated for an extended period of time include a processor that causes the system to receive organizational data that describes a virtual organization, obtain additional data related to the organizational data, and provide a simulated computer network of the virtual organization based on the organizational data. The process can further cause the system to install at least one malware on the simulated computer network, monitor one or more interactions between the simulated computer network and an operator of the malware, and build a malware operator profile that characterizes the operator of the malware based on the one or more interactions, with which the operator of the malware can be identified in subsequent interactions.