IP Library Patent Application 17859854
Patent Application
App. No. 17/859,854

CYBER SECURITY SANDBOX ENVIRONMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/859,854
Abstract

A virtual computing environment cloning method is used to allow rapid repeatable testing of unsupervised machine learning (ML) architectures and algorithms. A virtual reference environment contains a set of virtual devices, user accounts and IP traffic as well as scripted activity and a cyber security appliance including unsupervised ML trained on the scripted activity. A clone creator makes a replica of the environment. Clones can be taken from the reference at any time and more than one can exist simultaneously. Testing that takes place within a clone environment has no effect on the reference environment, including having no effect on the unsupervised ML architectures and algorithms. Clones can be interacted with, and outcomes from testing a clone can be recorded. Clones can be discarded after tests are completed and tests are independent and repeatable.

Claims (40)

1 . An apparatus, comprising:

a clone creator configured to

1) create a clone of one or more machine learning architectures and their corresponding one or more machine learning algorithms from a reference cyber security appliance, wherein the reference cyber security appliance includes one or more architectures using the one or more machine learning algorithms that continue to update weights applied to its machine learning during a deployment of that machine learning architecture;

2) create a clone network from the reference network in operation, wherein the reference network includes a set of devices, a set of user accounts, and a set of IP packet traffic, and the clone network includes a set of devices corresponding to the set of devices in the reference network, and copies of the set of user accounts and the set of IP packet traffic;

3) create a clone cyber security appliance from the reference cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms and machine learning architectures from the reference cyber security appliance, and

4) test out one or more cyber-attacks on the clone network, which is being protected by the clone cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms by injecting one or more cyber-attacks into the clone network, wherein the reference network including its devices, user accounts, and IP packet traffic will not be affected by the one or more cyber-attacks that will be unleashed on the clone network, wherein the clone network is created in a virtual machine environment; and

a user interface configured to cooperate with the clone creator to convey results of the one or more cyber-attacks on the clone network and analysis by the clone cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms recorded during the one or more cyber-attacks.

2 . The apparatus of claim 1 , wherein the clone creator is configured to make the clone from the reference network including the set of devices, the set of user accounts, and the set of IP packet traffic, by taking a first snapshot of a disk image including a memory and settings of the set of devices and the set of user accounts being cloned and then store the clone of the reference network in a data store.

3 . The apparatus of claim 1 , wherein the clone creator is further configured to make the clone from the reference cyber security appliance, that has the one or more machine learning architectures using the one or more machine learning algorithms, by taking a second snapshot of a disk image including a memory and settings including its machine learning weights of the one or more machine learning architectures and then store the clone of the reference security appliance in a data store.

4 . The apparatus of claim 1 , wherein the clone creator is further configured to set up one or more sandbox environments, wherein each sandbox environment is populated with one or more virtual machines to implement the clone network, including the set of devices, the set of user accounts, the set of IP packet traffic, and a virtual machine configured to implement a reference copy of the cyber security appliance and the one or more machine learning architectures.

5 . The apparatus of claim 4 , further comprising:

a cyber threat creator, wherein the cyber threat creator is configured to unleash an actual cyber threat attack on the clone network, including the set of devices, the set of user accounts and the set of IP packet traffic.

6 . The apparatus of claim 5 , wherein the actual cyber threat is implemented by the one or more virtual machines, which is being protected by the copy of the cyber security appliance and the one or more machine learning architectures.

7 . The apparatus of claim 1 , further comprising:

a user interface and a data management module in the clone creator, wherein the clone creator, the cyber threat creator and the data management module cooperate with a data store and the user interface to record events in the clone cyber security appliance and the clone network.

8 . The apparatus of claim 7 , wherein the recorded events include lateral movement indicative of possible activity and the set of devices and the set of user accounts compromised during the actual cyber threat attack in the clone network and actions taken by the clone cyber security appliance to detect the actual cyber threat attack on the clone network, and actions taken by the reference cyber security appliance to mitigate the actual cyber threat attack.

9 . The apparatus of claim 8 , the user interface is further configured to display, on a display screen, the recorded events to a user and allow a user to watch and observe what is happening in the clone cyber security appliance and the clone network.

10 . The apparatus of claim 1 , wherein the actual cyber threat is not applied to the reference network, so the reference network and the reference cyber security appliance remain clean and untainted by the actual cyber threat attack.

11 . A method for automated cloning, comprising:

configuring a clone creator to

1) create a clone of one or more machine learning architectures and their corresponding one or more machine learning algorithms from a reference cyber security appliance, wherein the reference cyber security appliance includes one or more architectures using the one or more machine learning algorithms that continue to update weights applied to its machine learning during a deployment of that machine learning architecture;

2) create a clone network from the reference network in operation, wherein the reference network includes a set of devices, a set of user accounts, and a set of IP packet traffic, and the clone network includes a set of devices corresponding to the set of devices in the reference network, and copies of the set of user accounts and the set of IP packet traffic;

3) create a clone cyber security appliance from the reference cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms and machine learning architectures from the reference cyber security appliance, and

4) test out one or more cyber-attacks on the clone network, which is being protected by the clone cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms by injecting one or more cyber-attacks into the clone network, wherein the reference network including its devices, user accounts, and IP packet traffic will not be affected by the one or more cyber-attacks that will be unleashed on the clone network, wherein the clone network is created in a virtual machine environment; and

configuring aa user interface to cooperate with the clone creator to convey results of the one or more cyber-attacks on the clone network and analysis by the clone cyber security appliance including the one or more machine learning architectures using the one or more machine learning algorithms recorded during the one or more cyber-attacks.

12 . The method of claim 11 , further comprising:

configuring the clone creator to make the clone from the reference network including the set of devices, the set of user accounts, and the set of IP packet traffic, by taking a first snapshot of a disk image including a memory and settings of the set of devices and the set of user accounts being cloned and then store the clone of the reference network in a data store.

13 . The method of claim 11 , further comprising:

configuring the clone creator to make the clone from the reference cyber security appliance, that has the one or more machine learning architectures using the one or more machine learning algorithms, by taking a second snapshot of a disk image including a memory and settings including its machine learning weights of the one or more machine learning architectures and then store the clone of the reference security appliance in a data store.

14 . The method of claim 11 , further comprising:

configuring the clone creator to set up one or more sandbox environments, wherein each sandbox environment is populated with one or more virtual machines to implement the clone network, including the set of devices, the set of user accounts, the et of IP packet traffic, and a virtual machine configured to implement a reference copy of the cyber security appliance and the one or more machine learning architectures.

15 . The method of claim 14 , further comprising:

configuring a cyber threat creator to unleash an actual cyber threat attack on the clone network, including the set of devices, the set of user accounts and the set of IP packet traffic, wherein the actual cyber threat is implemented by the one or more virtual machines, which is being protected by the copy of the cyber security appliance and the one or more machine learning architectures.

16 . The method of claim 11 , further comprising:

configuring a user interface and a data management module in the clone creator, wherein the clone creator, the cyber threat creator and the data management module cooperate with a data store and the user interface to record events in the clone cyber security appliance and the clone network.

17 . The method of claim 16 , wherein the recorded events include lateral movement indicative of possible activity and the set of devices and the set of user accounts compromised during the actual cyber threat attack in the clone network and actions taken by the clone cyber security appliance to detect the actual cyber threat attack on the clone network, and actions taken by the reference cyber security appliance to mitigate the actual cyber threat attack.

18 . The method of claim 17 , further comprising:

configuring the user interface to display, on a display screen, the recorded events to a user and allow a user to watch and observe what is happening in the clone cyber security appliance and the clone network.

19 . The method of claim 11 , wherein the reference network and the reference cyber security appliance use the one or more machine learning architectures to protect the reference network remain clean and untainted by the actual cyber threat attack on the clone network.

20 . A non-transitory computer readable medium in an apparatus, comprising: one or more computer readable codes operable, when executed by one or more processors, to instruct a clone creator configured to perform the method of claim 11 .

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: FELLOWS, SIMON DAVID LINCOLN; JASIK, FRANK
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 061259/0720 →