IP Library › Granted Patent US 10,079,850
Granted Patent B1
US 10,079,850 · App. 14/982,725 · Granted Sep 18, 2018

Systems and methods for provisioning cyber security simulation exercises

Inventors: Dipak Patil (Santa Clara, CA); Prasad Iyer (San Jose, CA)
Assignee: Symantec Corporation
H04L63/1433G06F17/5009H04L41/145H04L41/147H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,079,850
App. No.
14/982,725
Granted
Sep 18, 2018
Kind
B1
Abstract

A computer-implemented method for provisioning cyber security simulation exercises may include (1) maintaining, at a data center level for a data center including a multitude of nodes, a cyber security simulation template that defines a resource configuration for a cyber security simulation exercise in which a participant executes a security attack within a contained network environment to educate the participant about cyber security, (2) detecting an indication to place a user session of the cyber security simulation exercise within the data center to enable the participant to perform the cyber security simulation exercise, and (3) dynamically allocating, by an autonomous and centralized data center allocation agent in response to detecting the indication, a pool of resources at a node within the data center to the user session to enable the participant to perform the cyber security simulation exercise. Various other methods, systems, and computer-readable media are also disclosed.

Claims (79)

1. A computer-implemented method for provisioning cyber security simulation exercises, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

maintaining, at a data center level for a data center comprising a multitude of nodes, a cyber security simulation template that defines a resource configuration for a cyber security simulation exercise in which a participant executes a security attack within a contained network environment;

detecting an indication to place a user session of the cyber security simulation exercise within the data center to enable the participant to perform the cyber security simulation exercise;

dynamically allocating, by an autonomous and centralized data center allocation agent in response to detecting the indication, a pool of resources at a node within the data center to the user session to enable the participant to perform the cyber security simulation exercise at least in part by matching the pool of resources to the cyber security simulation template; and

executing the cyber security simulation exercise, wherein:

the participant comprises a human user;

the cyber security simulation exercise is designed to guide the participant through motions of performing the security attack to educate the participant about how the security attack is performed; and

the resource configuration defined by the cyber security simulation template defines:

target resources for the participant in the cyber security simulation exercise to attack; and

attacking resources for the participant in the cyber security simulation exercise to use to attack the target resources.

2. The method of claim 1 , wherein the indication comprises one of:

a request to create the user session of the cyber security simulation exercise; and

an indication to relocate an existing user session of the cyber security simulation exercise.

3. The method of claim 2 , wherein the indication to relocate the existing user session of the cyber security simulation exercise comprises at least one of:

an indication that a resource has switched an availability state at the node; and

an indication that a resource has switched an availability state at a different node within the data center other than the node.

4. The method of claim 1 ,

wherein the cyber security simulation exercise is performed with authorization of a target of the cyber security simulation exercise.

5. The method of claim 1 , wherein the resource configuration defined by the cyber security simulation template defines at least one of:

a set of virtual machines comprising the target resources; and

a set of virtual machines comprising the attacking resources.

6. The method of claim 5 , wherein the resource configuration defined by the cyber security simulation template defines at least one of:

a router; and

a network topology connecting the target resources, the attacking resources, and the router.

7. The method of claim 1 , wherein dynamically allocating, by the autonomous and centralized data center allocation agent in response to detecting the indication, the pool of resources comprises performing a network status check that checks whether the pool of resources is setup and functioning on the node according to the resource configuration of the cyber security simulation template.

8. The method of claim 7 , wherein performing the network status check comprises at least one of:

verifying that an Internet protocol address is correct;

verifying that a virtual machine is running; and

verifying that members of a defined network topology are connected to each other according to the defined network topology.

9. The method of claim 1 , wherein the autonomous and centralized data center allocation agent abstracts the cyber security simulation exercise from an underlying infrastructure of the data center such that the autonomous and centralized data center allocation agent is programmed in terms that are data center agnostic.

10. The method of claim 1 , wherein dynamically allocating, by the autonomous and centralized data center allocation agent in response to detecting the indication, the pool of resources is performed in a manner that is transparent to at least one of:

the participant in the cyber security simulation exercise; and

an administrator of the cyber security simulation exercise.

11. A system for provisioning cyber security simulation exercises, the system comprising:

a maintenance module, stored in memory, that maintains, at a data center level for a data center comprising a multitude of nodes, a cyber security simulation template that defines a resource configuration for a cyber security simulation exercise in which a participant executes a security attack within a contained network environment;

a detection module, stored in memory, that detects an indication to place a user session of the cyber security simulation exercise within the data center to enable the participant to perform the cyber security simulation exercise;

an allocation module, stored in memory, that:

dynamically allocates, as part of an autonomous and centralized data center allocation agent in response to detecting the indication, a pool of resources at a node within the data center to the user session to enable the participant to perform the cyber security simulation exercise at least in part by matching the pool of resources to the cyber security simulation template; and

executes the cyber security simulation exercise; and

at least one physical processor configured to execute the maintenance module, the detection module, and the allocation module, wherein:

the participant comprises a human user;

the cyber security simulation exercise is designed to guide the participant through motions of performing the security attack to educate the participant about how the security attack is performed; and

the resource configuration defined by the cyber security simulation template defines:

target resources for the participant in the cyber security simulation exercise to attack; and

attacking resources for the participant in the cyber security simulation exercise to use to attack the target resources.

12. The system of claim 11 , wherein the indication comprises one of:

a request to create the user session of the cyber security simulation exercise; and

an indication to relocate an existing user session of the cyber security simulation exercise.

13. The system of claim 12 , wherein the indication to relocate the existing user session of the cyber security simulation exercise comprises at least one of:

an indication that a resource has switched an availability state at the node; and

an indication that a resource has switched an availability state at a different node within the data center other than the node.

14. The system of claim 11 , wherein

the cyber security simulation exercise is performed with authorization of a target of the cyber security simulation exercise.

15. The system of claim 11 , wherein the resource configuration defined by the cyber security simulation template defines at least one of:

a set of virtual machines comprising the target resources; and

a set of virtual machines comprising the attacking resources.

16. The system of claim 15 , wherein the resource configuration defined by the cyber security simulation template defines at least one of:

a router; and

a network topology connecting the target resources, the attacking resources, and the router.

17. The system of claim 11 , wherein the allocation module is further programmed to dynamically allocate the pool of resources at least in part by performing a network status check that checks whether the pool of resources is setup and functioning on the node according to the resource configuration of the cyber security simulation template.

18. The system of claim 17 , wherein the allocation module is programmed to perform the network status check by performing at least one of:

verifying that an Internet protocol address is correct;

verifying that a virtual machine is running; and

verifying that members of a defined network topology are connected to each other according to the defined network topology.

19. The system of claim 11 , wherein the autonomous and centralized data center allocation agent abstracts the cyber security simulation exercise from an underlying infrastructure of the data center such that the autonomous and centralized data center allocation agent is programmed in terms that are data center agnostic.

20. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

maintain, at a data center level for a data center comprising a multitude of nodes, a cyber security simulation template that defines a resource configuration for a cyber security simulation exercise in which a participant executes a security attack within a contained network environment;

detect an indication to place a user session of the cyber security simulation exercise within the data center to enable the participant to perform the cyber security simulation exercise;

perform a network status check that checks whether a pool of resources is setup and functioning on a node according to the resource configuration of the cyber security simulation template by performing at least one of:

verifying that an Internet protocol address is correct;

verifying that a virtual machine is running; and

verifying that members of a defined network topology are connected to each other according to the defined network topology;

dynamically allocate, by an autonomous and centralized data center allocation agent in response to detecting the indication, the pool of resources at the node within the data center to the user session to enable the participant to perform the cyber security simulation exercise at least in part by matching the pool of resources to the cyber security simulation template; and

execute the cyber security simulation exercise, wherein:

the participant comprises a human user;

the cyber security simulation exercise is designed to guide the participant through motions of performing the security attack to educate the participant about how the security attack is performed; and

the resource configuration defined by the cyber security simulation template defines:

target resources for the participant in the cyber security simulation exercise to attack; and

attacking resources for the participant in the cyber security simulation exercise to use to attack the target resources.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2015
From: PATIL, DIPAK; IYER, PRASAD
To: SYMANTEC CORPORATION
Reel/Frame 037377/0011 →
Cited By (3)
US 12,526,319 US 12,621,331 US 12,750,404