IP Library › Granted Patent US 12,652,308
Granted Patent B2
US 12,652,308 · App. 18/226,591 · Granted Jun 9, 2026

Systems and methods of simulating cyberattacks

Inventor: Roni Bachar (Zoran, IL)
Assignee: Rockwell Automation Technologies, Inc.
H04L63/1433H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,308
App. No.
18/226,591
Granted
Jun 9, 2026
Kind
B2
Abstract

A non-transitory computer readable medium stores instructions that, when executed by a processor, cause the processor to receive configuration data representative of one or more operational parameters of the network security system, execute a virtual network including a virtual network security system configured based on the configuration data, deploy simulated cyberattacks on the virtual network, identify one or more of the simulated cyberattacks that were not detected by the virtual network security system, and generate a notification identifying the one or more of the simulated cyberattacks that were not detected by the virtual network security system.

Claims (54)

1 . A non-transitory computer readable medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving one or more sets of configuration data corresponding to one or more network security systems configured to monitor network activity within one or more OT environment networks, wherein the one or more sets of configuration data is representative of one or more operational parameters of the one or more network security systems;

determining, based on the one or more sets of configuration data, one or more sets of detection rules for classifying cyberattacks;

executing a virtual network comprising a virtual network security system configured based on the one or more sets of configuration data and the one or more sets of detection rules;

deploying a plurality of simulated cyberattacks, from a set of predetermined known cyberattacks, on the virtual network;

generating, within a threshold period of time, a respective classification of each of the plurality of simulated cyberattacks;

comparing, based on the threshold period of time, the respective classifications made by the virtual network security system to known classifications of the plurality of simulated cyberattacks to identify one or more of the plurality of simulated cyberattacks that were not detected by the virtual network security system within the threshold period of time;

generating a notification identifying the one or more of the plurality of simulated cyberattacks that were not detected by the virtual network security system; and

providing a recommended adjustment to the one or more sets of detection rules based on the one or more of the plurality of simulated cyberattacks that were not detected by the virtual network security system.

2 . The non-transitory computer readable medium of claim 1 , wherein the virtual network comprises a cyberattack engine configured to generate and execute the plurality of simulated cyberattacks on a target entity within the virtual network.

3 . The non-transitory computer readable medium of claim 1 , wherein the notification comprises a report indicative of whether each simulated cyberattack of the plurality of simulated cyberattacks was detected by the virtual network security system.

4 . The non-transitory computer readable medium of claim 1 , wherein the one or more network security systems comprise an intrusion detection system.

5 . The non-transitory computer readable medium of claim 1 , wherein the operations comprise:

retrieving documentation of known cyberattack techniques from a catalog; and

generating the plurality of simulated cyberattacks based on the documentation of known cyberattack techniques.

6 . The non-transitory computer readable medium of claim 1 , wherein the operations comprise:

receiving the one or more sets of configuration data from a client device; and

sending the notification to the client device.

7 . The non-transitory computer readable medium of claim 1 , wherein each simulated cyberattack of the plurality of simulated cyberattacks comprises one or more packets.

8 . The non-transitory computer readable medium of claim 1 , wherein each simulated cyberattack of the plurality of simulated cyberattacks comprises a signature associated with known cyberattack techniques.

9 . The non-transitory computer readable medium of claim 1 , wherein receiving the one or more sets of configuration data comprises receiving a first set of configuration data corresponding to a first network security system configured to monitor network activity within a first OT environment network, wherein the first configuration data is representative of one or more first operational parameters of the first network security system; and

wherein the operations further comprise:

receiving second configuration data corresponding to a second network security system configured to monitor network activity within a second OT environment network, wherein the configuration data is representative of one or more second operational parameters of the second network security system;

determining, based on the first and second configuration data, one or more shared characteristics between the first OT environment network and the second OT environment network; and

providing, based on the one or more shared characteristics, a recommended adjustment to a second set of detection rules to the second OT environment network.

10 . A method, comprising:

receiving configuration data corresponding to network security system configured to monitor network activity within a network, wherein the configuration data comprises a set of detection rules configured to classify the network activity as associated with a cyberattack or not associated with a cyberattack;

determining, based on the configuration data, a set of detection rules for classifying cyberattacks;

configuring a virtual network security system based on the configuration data and the detection rules;

generating a simulated cyberattack selected from a set of predetermined known cyberattacks;

deploying the virtual network security system to classify the simulated cyberattack as a threat or not a threat;

generating, within a threshold period of time, a respective classification of the simulated cyberattack;

comparing, based on the threshold period of time, the respective classification made by the virtual network security system to a known classification of the simulated cyberattack;

generating an alert in response to the virtual network security system not classifying the simulated cyberattack as a threat within the threshold period of time; and

recommending an adjustment to the set of detection rules based on the virtual network security system not classifying the simulated cyberattack as a threat within the threshold period of time.

11 . The method of claim 10 , comprising deploying the simulated cyberattack on a virtual network comprising the virtual network security system, wherein the simulated cyberattack comprises one or more packets transmitted within the virtual network.

12 . The method of claim 11 , wherein the detection rules define characteristics of suspicious activity, and the virtual network security system is configured to classify the simulated cyberattack as a threat or not a threat based on whether the one or more packets exhibit the characteristics of suspicious activity.

13 . The method of claim 10 , wherein the simulated cyberattack is a first simulated cyberattack of a plurality of simulated cyberattacks, and wherein the method comprises deploying the virtual network security system to classify each simulated cyberattack of the plurality of simulated cyberattacks as a threat or not a threat.

14 . The method of claim 10 , comprising exporting the configuration data from a computing device of an operational technology (OT) environment.

15 . The method of claim 10 , wherein generating the simulated cyberattack comprises:

referencing documentation of known cyberattack techniques stored in a catalog; and

generating the simulated cyberattack based on the known cyberattack techniques.

16 . A non-transitory computer readable medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving configuration data from a client device, wherein the configuration data is associated with a configuration of a network security system of an operational technology (OT) environment;

determining, based on the configuration data, a set of detection rules for classifying cyberattacks;

configuring a virtual network security system based on the configuration data and the detection rules;

generating a plurality of simulated cyberattacks selected from a set of predetermined known cyberattacks;

deploying the virtual network security system to classify each simulated cyberattack of the plurality of simulated cyberattacks;

generating, within a threshold period of time, a respective classification of each of the plurality of simulated cyberattacks;

comparing, based on the threshold period of time, the respective classifications made by the virtual network security system to respective known classifications of the set of predetermined known cyberattacks;

generating a report, based on the comparison, comprising a list of simulated cyberattacks from the plurality of simulated cyberattacks that were not correctly classified by the virtual network security system within the threshold period of time; and

providing a recommended adjustment to the set of detection rules based on the simulated cyberattacks from the plurality of simulated cyberattacks that were not correctly classified by the virtual network security system.

17 . The non-transitory computer readable medium of claim 16 , wherein the operations comprise generating new configuration data based on the simulated cyberattacks from the plurality of simulated cyberattacks that were not correctly classified by the virtual network security system.

18 . The non-transitory computer readable medium of claim 16 , wherein each simulated cyberattack of the plurality of simulated cyberattacks comprises one or more packets exhibiting a signature associated with at least one predetermined known cyberattacks from the set of predetermined known cyberattacks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: BACHAR, RONI
To: ROCKWELL AUTOMATION TECHNOLOGIES, INC.
Reel/Frame 064414/0925 →
Continuity (1)
Related Publication 20250039216A1 · Jan 30, 2025
References Cited (11)
US 11470106B1 · Lin · 2022 [cited by examiner]
US 20190207971A1 · Sharfuddin · 2019 [cited by examiner]
US 20210194924A1 · Heinemeyer · 2021 [cited by examiner]
US 20220224723A1 · Crabtree · 2022 [cited by examiner]
US 20220311795A1 · Hutelmyer · 2022 [cited by examiner]
US 20230283629A1 · Boyer · 2023 [cited by examiner]
US 20230319081A1 · Fainberg · 2023 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
US 20240031395A1 · Kiss · 2024 [cited by examiner]
US 20240297896A1 · Watanabe · 2024 [cited by examiner]
US 20240427876A1 · Woodward · 2024 [cited by examiner]