Virtualized Simulator Nodes for Malicious Action Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-malware software is ineffective against sophisticated malware threats, as malicious users continually find ways to circumvent protection, necessitating a new system to simulate malicious actions and analyze vulnerabilities to enhance security.

Innovation Solution

A system comprising simulator nodes that emulate operations in a target system to simulate malicious actions, determine their success, and configure security systems to prevent breaches, utilizing virtual machines, virtual appliances, and physical devices to establish communication connections and update breach scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware software is used to block malicious users, then basic protection is provided, but sophisticated malware can still circumvent the protection

Engineering Contradiction:
Improvemalware protection effectivenessVSAvoidmalware circumvention capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by simulating malicious actions in advance within a virtualized environment before they can affect the actual target system. The simulator nodes execute simulated malicious actions to identify vulnerabilities and test security responses proactively, allowing the system to prepare defenses before real attacks occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the target system in a virtualized environment with simulator nodes that replicate the target's hardware, software, and network configurations. This copy allows safe simulation of malicious actions without risking the actual system, enabling comprehensive security testing and vulnerability identification.

Inventive Principle:
Principle #26Copying

2Difficulty of detecting and measuring

If simulator nodes are allocated to simulate malicious actions, then vulnerability detection capability is enhanced, but system complexity increases

Engineering Contradiction:
Improvebreach scenario detection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The virtualized environment acts as an intermediary layer between the actual target system and the simulation process. Simulator nodes serve as mediators that execute malicious actions in isolation, capturing results without directly accessing or modifying the target system. This intermediary approach enables complex simulation capabilities while maintaining system isolation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtualized simulator nodes are designed with multi-functionality, capable of simulating various types of malicious actions (data theft, system access, network breaches) across different target system configurations. A single virtualized platform can accommodate multiple simulation scenarios and target environments, reducing overall system complexity despite enhanced detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security controllers are configured based on simulation results, then protection effectiveness is improved, but time for security updates increases

Engineering Contradiction:
Improvesecurity controller effectivenessVSAvoidsecurity update cycle time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables continuous security improvement by continuously simulating malicious actions and updating security controllers in an ongoing cycle. Rather than periodic updates, the simulation framework operates continuously to identify new vulnerabilities and refine security responses, ensuring security measures remain effective against evolving threats without significant time delays.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system implements feedback loops where simulation results directly inform security controller configurations. Results from simulated malicious actions are analyzed and used to automatically adjust security rules, policies, and responses. This closed-loop feedback mechanism ensures that security measures are continuously optimized based on actual simulation data, reducing the time between vulnerability identification and defense implementation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9710653B2System and method for verifying malicious actions by utilizing virtualized elements
Publication Date: 2017.07.18 SAFEBREACH LTD
  • US9710653B2 patent drawing
  • US9710653B2 patent drawing
  • US9710653B2 patent drawing

AI summary

A system comprising a memory device having executable instructions stored in the memory device, and a processing device, in response to the executable instructions, configured to prepare breach simulation tasks by reading configurations for types of breach scenarios and preparing a list of tasks to be simulated, send breach simulation tasks to simulator nodes, the simulator nodes simulating parties involved in the types of breach scenarios, execute the breach simulation tasks on the simulator nodes, receive results from the simulator nodes, determine that the parties report on a same result, determine that the parties report on successful results, and identify a successful breach based on the parties report on the same result and the parties report on the successful results.