IP Library Granted Patent US 8,356,353
Granted Patent B2
US 8,356,353 · App. 12/147,282 · Granted Jan 15, 2013

System and method for simulating computer network attacks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,356,353
App. No.
12/147,282
Granted
Jan 15, 2013
Kind
B2
Abstract

The present invention provides a system and method for providing computer network attack simulation. The method includes the steps of: receiving a network configuration and setup description; simulating the network configuration based on the received network configuration; receiving at least one confirmed vulnerability of at least one computer, machine, or network device in the simulated network; receiving a method for compromising the confirmed vulnerability of the at least one computer, machine, or network device; and virtually installing a network agent on the at least one computer, machine, or network device, wherein the network agent allows a penetration tester to execute arbitrary operating system calls on the at least one computer, machine, or network device.

Claims (19)

1. A method of providing computer network attack simulation on a computer, comprising the steps of:

receiving a network configuration, a network setup description, and a penetration testing framework with a local agent installed in the penetration testing framework;

simulating the network based on the received network configuration, wherein the simulated network contains at least one of the group consisting of a simulated computer, a simulated machine, and a simulated network device;

receiving a remote agent running in one simulated computer of the simulated network and connected to the penetration testing framework through the local agent;

receiving a simulated exploit for compromising the at least one simulated computer, simulated machine, or simulated network device;

querying an exploit database with a property of said simulated exploit;

receiving an exploit outcome probability from said exploit database in response to said querying;

determining an outcome of the simulated exploit for compromising the at least one simulated computer, simulated machine, or simulated network device based on said exploit outcome probability; and

when the outcome of the simulated exploit is compromising the simulated computer, simulated machine, or simulated network device, virtually installing a remote agent on the at least one simulated computer, simulated machine, or simulated network device, wherein the remote agent allows a user to execute arbitrary operating system calls on the at least one simulated computer, simulated machine, or simulated network device from the local agent.

2. The method of claim 1 , further comprising the step of executing the arbitrary operating system calls on the simulated computer to analyze risk to which the network may be exposed.

3. The method of claim 1 , wherein the network configuration is provided by a configuration file.

4. The method of claim 3 , wherein the configuration file contains a template that is used for at least a portion of the at least one simulated computer, simulated machine, or simulated network device.

5. The method of claim 3 , wherein the configuration file describes which simulated computers are in the simulated network, and at least one of what applications and services are run by the simulated computers, what operating systems are run by the simulated computers, and how the simulated computers are connected through the network.

6. The method of claim 1 , wherein more than one simulator is used to perform the step of simulating the network configuration.

7. The method of claim 6 , wherein a simulator monitor provides management and administrative operations for each simulator.

8. The method of claim 7 , wherein a graphical user interface connected to the simulator allows a user of the present method to view information provided by the simulator monitor.

9. The method of claim 1 , wherein the network configuration includes at least two simulated computers that communicate with each other.

10. The method of claim 1 , further comprising the step of issuing arbitrary operating system calls from the local agent so that the arbitrary operating system calls are executed on the simulated computer and their answer is returned to the local agent to allow the execution of modules within the penetration testing framework.

11. The method of claim 1 , wherein the outcome is selected from the group consisting of compromising the system, crashing the system, and doing nothing.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK. NATIONAL ASSOCIATION
To: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
Reel/Frame 070086/0008 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2019
From: CORE SDI, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048381/0497 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: COURION CORPORATION; CORE SDI, INC.; CORE SECURITY TECHNOLOGIES, INC.
Reel/Frame 044535/0830 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040298/0816 →
SECURITY INTEREST Recorded Dec 29, 2015
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 037374/0301 →
RELEASE OF SECURITY INTEREST Recorded Dec 29, 2015
From: MULTIPLIER CAPITAL, L.P.
To: CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.
Reel/Frame 037372/0488 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 021528 FRAME: 0351. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 22, 2015
From: FUTORANSKY, ARIEL; MIRANDA, FERNANDO CARLOS; ORLICKI, JOSE IGNACIO; SARRAUTE YAMADA, CARLOS EMILIO
To: CORE SDI, INC.
Reel/Frame 037358/0564 →
SECURITY AGREEMENT Recorded Aug 23, 2013
From: CORE SDI, INC.; CORE SECURITY TECHNOLOGIES, INC.
To: MULTIPLIER CAPITAL, LP
Reel/Frame 031077/0477 →