IP Library Granted Patent US 9,742,804
Granted Patent B2
US 9,742,804 · App. 14/925,645 · Granted Aug 22, 2017

Computer network defense system

Inventors: Vincent Urias (Albuquerque, NM); William M. S. Stout (Alburquerque, NM); Caleb Loverro (Albuquerque, NM)
Assignee: National Technology & Engineering Solutions of Sandia, LLC
H04L63/1491G06F9/45558H04L63/1425G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,742,804
App. No.
14/925,645
Granted
Aug 22, 2017
Kind
B2
Abstract

A method and apparatus for protecting virtual machines. A computer system creates a copy of a group of the virtual machines in an operating network in a deception network to form a group of cloned virtual machines in the deception network when the group of the virtual machines is accessed by an adversary. The computer system creates an emulation of components from the operating network in the deception network. The components are accessible by the group of the cloned virtual machines as if the group of the cloned virtual machines was in the operating network. The computer system moves network connections for the group of the virtual machines in the operating network used by the adversary from the group of the virtual machines in the operating network to the group of the cloned virtual machines, enabling protecting the group of the virtual machines from actions performed by the adversary.

Claims (40)

1. A computer-implemented method for protecting virtual machines, the computer-implemented method comprising:

creating a copy of a group of the virtual machines in an operating network in a deception network to form a group of cloned virtual machines in the deception network in response to determining that the group of the virtual machines in the operating network is accessed by an adversary;

determining, in response to determining that the group of the virtual machines in the operating network is accessed by an adversary, at least one component from the operating network that the adversary has accessed;

creating, in response to determining that the adversary has accessed at least one component from the operating network, an emulation of the at least one component in the deception network; and

moving a group of network connections for the group of the virtual machines in the operating network used by the adversary from the group of the virtual machines in the operating network to the group of the cloned virtual machines in the deception network, thereby enabling protection of the group of the virtual machines from actions performed by the adversary, wherein the cloned virtual machine is shown to the adversary to have been running for the same period of time as that of a corresponding virtual machine in the operating network from which the cloned virtual machine was cloned.

2. The computer-implemented method of claim 1 further comprising:

identifying information about the actions taken by the adversary with respect to the group of the cloned virtual machines in the deception network.

3. The computer-implemented method of claim 1 further comprising:

monitoring the operating network with the virtual machines for unauthorized access by the adversary.

4. The computer-implemented method of claim 3 , wherein the actions of the adversary in the deception network are selected from at least one of a file transfer, a file deletion, a movement of a file, or a modification of the file.

5. The computer-implemented method of claim 1 , wherein the virtual machines are managed by a hypervisor running in a kernel of an operating system.

6. The computer-implemented method of claim 1 , wherein the emulation of the at least one component is created by a threat manager, and wherein the threat manager modifies at least one of information exchanged between a hypervisor and the group of the cloned virtual machines, or a flow of the information between the hypervisor and the group of the cloned virtual machines.

7. The computer-implemented method of claim 6 , wherein the flow of the information between the hypervisor and the group of the cloned virtual machines includes an exception generated by the group of the cloned virtual machines, and wherein the threat manager handles the exception to simulate the flow of the information between the hypervisor and the group of the cloned virtual machines in the deception network as if the adversary was performing activities in the group of the virtual machines in the operating network.

8. The computer-implemented method of claim 1 , wherein the emulation of the at least one component identifies a request for a state of a cloned virtual machine in the group of the cloned virtual machines in the deception network and changes the state of the cloned virtual machine for a response to the request such that the state is selected from at least one of the cloned virtual machine being shown to the adversary to be located in the operating network, or the cloned virtual machine being shown to the adversary to be using memory used by the corresponding virtual machine.

9. The computer-implemented method of claim 1 , wherein the group of network connections is moved without an interruption to the group of network connections used by the adversary.

10. An apparatus comprising:

a threat manager in a computer system that:

creates a copy of a group of virtual machines in an operating network in a deception network to form a group of cloned virtual machines in the deception network in response to determining that the group of the virtual machines in the operating network is accessed by an adversary;

determines at least one component from the operating network that the adversary has accessed;

creates an emulation of the at least one component in the deception network; and

moves a group of network connections for the group of the virtual machines in the operating network used by the adversary from the group of the virtual machines in the operating network to the group of the cloned virtual machines in the deception network, thereby enabling protection of the group of the virtual machines from actions performed by the adversary, wherein the cloned virtual machine is shown to the adversary to have been running for the same period of time as that of a corresponding virtual machine in the operating network from which the cloned virtual machine was cloned.

11. The apparatus of claim 10 , wherein the threat manager identifies information about the actions taken by the adversary with respect to the group of the cloned virtual machines in the deception network.

12. The apparatus of claim 10 , wherein the threat manager further comprises: monitoring the operating network with the virtual machines for unauthorized access by the adversary.

13. The apparatus of claim 12 , wherein the actions of the adversary in the deception network are selected from at least one of a file transfer, a file deletion, a movement of a file, or a modification of the file.

14. The apparatus of claim 10 , wherein the virtual machines are managed by a hypervisor running in a kernel of an operating system.

15. The apparatus of claim 10 , wherein the threat manager modifies at least one of information exchanged between a hypervisor and the group of the cloned virtual machines, or a flow of the information between the hypervisor and the group of the cloned virtual machines.

16. The apparatus of claim 15 , wherein the flow of the information between the hypervisor and the group of the cloned virtual machines includes an exception generated by the group of the cloned virtual machines, and wherein the threat manager handles the exceptions to simulate the flow of the information between the hypervisor and the group of the cloned virtual machines in the deception network as if the adversary was performing activities in the group of the virtual machines in the operating network.

17. The apparatus of claim 10 , wherein the threat manager identifies a request for a state of a cloned virtual machine in the group of the cloned virtual machines in the deception network and changes the state of the cloned virtual machine for a response to the request such that the state is selected from at least one of the cloned virtual machine being shown to the adversary to be located in the operating network, or the cloned virtual machine being shown to the adversary to be using memory used by the corresponding virtual machine.

18. The apparatus of claim 10 , wherein the group of network connections is moved without an interruption to the group of network connections used by the adversary.

19. A computer program product for protecting virtual machines, the computer program product being on a non-transitory computer readable storage media comprising program code, which when processed by a processor:

creates a copy of a group of the virtual machines in an operating network in a deception network to form a group of cloned virtual machines in the deception network in response to determining that the group of the virtual machines in the operating network is accessed by an adversary;

determines at least one component from the operating network that the adversary has accessed;

creates, in response to determining that the adversary has accessed at least one component from the operating network, an emulation of the at least one component in the deception network; and

moves a group of network connections for the group of the virtual machines in the operating network used by the adversary from the group of the virtual machines in the operating network to the group of the cloned virtual machines in the deception network, thereby enabling protection of the group of the virtual machines from actions performed by the adversary, wherein the cloned virtual machine is shown to the adversary to have been running for the same period of time as that of a corresponding virtual machine in the operating network from which the cloned virtual machine was cloned.

20. The computer program product of claim 19 , wherein the program code is further processed by the processor to identify information about the actions taken by the adversary with respect to the group of the cloned virtual machines in the deception network.

21. The computer program product of claim 19 , wherein the program code is further processed by the processor to monitor the operating network with the virtual machines for unauthorized access by the adversary.

22. The computer program product of claim 19 , wherein the emulation of the at least one component is created by a threat manager that modifies at least one of information exchanged between a hypervisor and the group of the cloned virtual machines, or a flow of the information between the hypervisor and the group of the cloned virtual machines.

23. The computer program product of claim 19 , wherein the virtual machines are managed by a hypervisor running in a kernel of an operating system and a flow of information between the hypervisor and the virtual machines includes exceptions generated by the virtual machines, and wherein a threat manager handles the exceptions to simulate the flow of the information between the hypervisor and the group of the cloned virtual machines in the deception network as if the adversary was performing activities in the group of the virtual machines in the operating network.

24. The computer program product of claim 19 , wherein the emulation of the at least one component identifies a request for a state of a cloned virtual machine in the group of the cloned virtual machines in the deception network and changes the state of the cloned virtual machine for a response to the request such that the state is selected from at least one of the cloned virtual machine being shown to the adversary to be located in the operating network, or the cloned virtual machine being shown to the adversary to be using memory used by the corresponding virtual machine.

25. The computer program product of claim 19 , wherein the group of network connections is moved without an interruption to the group of network connections used by the adversary.

Assignments (3)
CHANGE OF NAME Recorded Jun 27, 2017
From: SANDIA CORPORATION
To: NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA, LLC
Reel/Frame 043038/0572 →
CONFIRMATORY LICENSE Recorded Feb 1, 2016
From: SANDIA CORPORATION
To: U.S. DEPARTMENT OF ENERGY
Reel/Frame 037629/0140 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2016
From: URIAS, VINCENT; STOUT, WILLIAM M.S.; LOVERRO, CALEB
To: SANDIA CORPORATION
Reel/Frame 037524/0363 →
Continuity (1)
Related Publication 20170126736A1 · May 4, 2017