IP Library › Granted Patent US 11,507,673
Granted Patent B1
US 11,507,673 · App. 17/715,075 · Granted Nov 22, 2022

Adaptive cyber-attack emulation

Inventors: Freddy Ouzan (Sunnyvale, CA); Mauricio Sandt (Aachen, DE)
Assignee: APOLYTA INC.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,507,673
App. No.
17/715,075
Granted
Nov 22, 2022
Kind
B1
Abstract

A system for cyber-attack emulation includes a memory and one or more processors. The memory is configured to store a library of attack-code templates, each attack-code template including configurable program code that carries out a respective type of cyber-attack. The one or more processors are configured to specify an attack-emulation campaign based on one or more of the attack-code templates, and, for at least a given attack-code template included in the attack-emulation campaign, to perform an iterative process including (i) generating an emulated attack from the given attack-code template, (ii) applying the emulated attack to a component of a target computer system, (iii) evaluating an interim outcome of the emulated attack, and (iv) adapting the emulated attack depending on the interim outcome.

Claims (31)

1. A system for cyber-attack emulation, comprising:

a memory, configured to store a library of attack-code templates, each attack-code template comprising configurable program code that carries out a respective type of cyber-attack; and

one or more processors, configured to:

specify an attack-emulation campaign based on one or more of the attack-code templates; and

for at least a given attack-code template included in the attack-emulation campaign, perform an iterative process comprising (i) generating an emulated attack from the given attack-code template, (ii) applying the emulated attack to a component of a target computer system in a given iteration of the iterative process, (iii) monitoring the target computer system so as to evaluate an interim outcome of the emulated attack, (iv) adapting the emulated attack depending on the interim outcome, and (v) in a subsequent iteration of the iterative process, applying the adapted emulated attack, which was adapted depending on the interim outcome of the given iteration, to the component of the target computer system,

wherein the one or more processors are configured to adapt the emulated attack by:

identifying that the emulated attack was detected;

upon identifying that the emulated attack was detected by static detection, adding a code obfuscation scheme to the emulated attack; and

upon identifying that the emulated attack was detected by dynamic detection, adding an evasion scheme to the emulated attack.

2. The system according to claim 1 , wherein the one or more processors are configured to adapt the emulated attack by modifying one or more parameters of the emulated attack.

3. The system according to claim 1 , wherein the one or more processors are configured to adapt the emulated attack by modifying a code obfuscation scheme used by the emulated attack.

4. The system according to claim 1 , wherein the one or more processors are configured to adapt the emulated attack by modifying an evasion scheme used by the emulated attack.

5. The system according to claim 1 , wherein the one or more processors are configured to adapt the emulated attack by modifying source code of the emulated attack and re-compiling the modified source code.

6. The system according to claim 1 , wherein the one or more processors are configured to adapt the emulated attack by modifying machine code of the emulated attack.

7. The system according to claim 1 , wherein, in performing the iterative process, the one or more processors are configured to switch from the given attack-code template to another attack-code template.

8. The system according to claim 1 , wherein the one or more processors are further configured to apply benign software code to one or more components of the target computer system, and to evaluate a response of the target computer system to the benign software code.

9. A method for cyber-attack emulation, comprising:

storing a library of attack-code templates, each attack-code template comprising configurable program code that carries out a respective type of cyber-attack;

specifying an attack-emulation campaign based on one or more of the attack-code templates; and

for at least a given attack-code template included in the attack-emulation campaign, perform an iterative process comprising (i) generating an emulated attack from the given attack-code template, (ii) applying the emulated attack to a component of a target computer system in a given iteration of the iterative process, (iii) monitoring the target computer system so as to evaluate an interim outcome of the emulated attack, (iv) adapting the emulated attack depending on the interim outcome, and (v) in a subsequent iteration of the iterative process, applying the adapted emulated attack, which was adapted depending on the interim outcome of the given iteration, to the component of the target computer system,

wherein adapting the emulated attack comprises:

identifying that the emulated attack was detected;

upon identifying that the emulated attack was detected by static detection, adding a code obfuscation scheme to the emulated attack; and

upon identifying that the emulated attack was detected by dynamic detection, adding an evasion scheme to the emulated attack.

10. The method according to claim 9 , wherein adapting the emulated attack comprises modifying one or more parameters of the emulated attack.

11. The method according to claim 9 , wherein adapting the emulated attack comprises modifying a code obfuscation scheme used by the emulated attack.

12. The method according to claim 9 , wherein adapting the emulated attack comprises modifying an evasion scheme used by the emulated attack.

13. The method according to claim 9 , wherein adapting the emulated attack comprises modifying source code of the emulated attack and re-compiling the modified source code.

14. The method according to claim 9 , wherein adapting the emulated attack comprises modifying machine code of the emulated attack.

15. The method according to claim 9 , wherein performing the iterative process comprises switching from the given attack-code template to another attack-code template.

16. The method according to claim 9 , further comprising applying benign software code to one or more components of the target computer system, and evaluating a response of the target computer system to the benign software code.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2022
From: OUZAN, FREDDY; SANDT, MAURICIO
To: APOLYTA INC.
Reel/Frame 059617/0238 →
Cited By (2)
US 12,386,980 US 12,450,042