Detecting and Thwarting Browser-Based Network Intrusion Attacks For Intellectual Property Misappropriation System and Method
Detecting and thwarting browser-based network intrusion attacks for intellectual property misappropriation is provided by enabling a local machine to direct retrieval of resources using uniform resource identifiers to a browser operating within a virtual machine whose internet protocol address is within a range external to a trusted network sub-circuit. Such a virtual machine is constrained by not having access to the Active Director Server of the trusted network. Such a virtual machine is constrained by not having access to other resources of the trusted network. Such a virtual machine is constrained by a monitor application which terminates the virtual machine if characteristics of intrusion or network attack are observed within the virtual machine.
1 . A system comprising a layered network of trusted and untrusted subnets isolated by a firewall from the Internet wherein the trusted subnet comprises at least one DHCP Server and a plurality of local machines whose IP addresses are registered with DHCP as participating in the Active Directory and on the trusted network, the local machines configured to operate virtual machine processes communicatively coupled to the Internet by a second IP address without access to the Active Director or to the trusted network.
2 . An apparatus communicatively coupled to a network comprising a trusted subnet and coupled to an untrusted subnet managed by at least one Dynamic Host Configuration Protocol (DHCP) server, comprises
a local machine configured with a first operating system and a first internet protocol address obtained from the DHCP server which is within the range of trusted sub-network IP addresses;
the local machine further configured with a virtual machine process which presents a virtual processor configured with a second operating system and a second internet protocol (IP) address assigned by the DHCP server which said IP address is within the range of un-trusted sub-network IP addresses;
the local machine further configured with a browser operating within the virtual machine process under the second operating system and communicatively coupled to the public Internet via a firewall; and
the local machine further configured with a monitoring application under the first operating system adapted to observe network activity within the virtual machine process, and terminate the virtual machine process under conditions consistent with malicious intrusion.
3 . The local machine of claim 2 further configured to provide a user with access to applications and objects on the trusted sub-network, also comprises a processor configured to operate a virtual machine process configured to have no privileges within the trusted network.
4 . A method for operating a processor configured with a virtual machine process comprising requesting assignment of an IP address from the DHCP server and receiving an IP address which does not have access to the Active Director Server but does have access to the external public Internet.
5 . A method for operating a processor configured to operate on a trusted subnet of a network by
transferring every request for a resource on the Internet to a virtual machine configured to run an operating system and a browser, said virtual machine configured with an Internet Protocol address that is external to the trusted subnet of the network.
6 . The method of claim 5 further comprising operating a monitor program to adapt the processor of the local machine to terminate the virtual machine process on detection of an attempted intrusion.
7 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of matching the fingerprints of non-web related network calls within a file.
8 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting to exploit a vulnerability in a browser.
9 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting to exploit a vulnerability in an operating system.
10 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting to access an Active Directory service.
11 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting a network services command.
12 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting to change its IP address.
13 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of attempting to access an IP address known to carry malicious software.
14 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to terminate the virtual machine process on the condition of sending a domain name service query for a uniform resource locator known for malicious software.
15 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to restore a version of the virtual machine process archived at a previous checkpoint.
16 . The method of claim 6 wherein said monitor program adapts the processor of the local machine to archive the present virtual machine image and compute a signature for comparison with archived virtual machines known to be infected with malicious software.