IP Library › Granted Patent US 12,739,260
Granted Patent B2
US 12,739,260 · App. 18/300,802 · Granted Sep 15, 2026

Virtual encapsulated instances for mitigation of cyberattacks

Inventors: Mauro Marzorati (Lutz, FL); Paul Llamas Virgen (Guadalajara, MX); Pedro Mauricio Manjarrez Gutierrez (Guadalajara, MX); Karla Paulina Calderon Vaca (Zapopan, MX)
Assignee: International Business Machines Corporation
H04L63/1416G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,260
App. No.
18/300,802
Granted
Sep 15, 2026
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for mitigating cyberattacks is provided. The present invention may include responding to a verification of a detected attack on a system, by detecting one or more modifications to one or more software components made by malicious network traffic; identifying the malicious network traffic; determining one or more compromised software components based on the detected one or more modifications and the identified malicious network traffic; performing digital twin simulation to evaluate one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate; creating an encapsulated environment; provisioning the one or more software components to encapsulate to the encapsulated environment; and redirecting the malicious network traffic to the encapsulated environment.

Claims (48)

1 . A processor-implemented method for mitigating cyberattacks, the method comprising:

responding to a verification of a detected attack on a system, by detecting one or more modifications to one or more software components made by malicious network traffic;

identifying the malicious network traffic;

determining one or more compromised software components based on the detected one or more modifications and the identified malicious network traffic;

performing digital twin simulation to evaluate one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate;

creating an encapsulated environment;

provisioning the one or more software components to encapsulate to the encapsulated environment; and

redirecting the malicious network traffic to the encapsulated environment.

2 . The method of claim 1 , further comprising:

continuing to process and respond to the detected attack in the encapsulated environment.

3 . The method of claim 1 , wherein the redirecting of the malicious network traffic to the encapsulated environment is performed by creating a virtual proxy magnet.

4 . The method of claim 1 , wherein the detecting of the one or more modifications to the one or more software components made by the malicious network traffic and the identifying the malicious network traffic, occur concurrently.

5 . The method of claim 1 , wherein the performing of the digital twin simulation to evaluate the one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate and the creating of the encapsulated environment, occur concurrently.

6 . The method of claim 1 , wherein the creating of the encapsulated environment comprises an isolated network configuration, and wherein the encapsulated environment maintains same attributes and characteristics required to dynamically operate as it does on the system.

7 . The method of claim 1 , further comprising:

continuing to process the system.

8 . A computer system for mitigating cyberattacks, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

responding to a verification of a detected attack on a system, by detecting one or more modifications to one or more software components made by malicious network traffic;

identifying the malicious network traffic;

determining one or more compromised software components based on the detected one or more modifications and the identified malicious network traffic;

performing digital twin simulation to evaluate one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate;

creating an encapsulated environment;

provisioning the one or more software components to encapsulate to the encapsulated environment; and

redirecting the malicious network traffic to the encapsulated environment.

9 . The computer system of claim 8 , further comprising:

continuing to process and respond to the detected attack in the encapsulated environment.

10 . The computer system of claim 8 , wherein the redirecting of the malicious network traffic to the encapsulated environment is performed by creating a virtual proxy magnet.

11 . The computer system of claim 8 , wherein the detecting of the one or more modifications to the one or more software components made by the malicious network traffic and the identifying the malicious network traffic, occur concurrently.

12 . The computer system of claim 8 , wherein the performing of the digital twin simulation to evaluate the one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate and the creating of the encapsulated environment, occur concurrently.

13 . The computer system of claim 8 , wherein the creating of the encapsulated environment comprises an isolated network configuration, and wherein the encapsulated environment maintains same attributes and characteristics required to dynamically operate as it does on the system.

14 . The computer system of claim 8 , further comprising:

continuing to process the system.

15 . A computer program product for mitigating cyberattacks, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor to cause the processor to perform a method comprising:

responding to a verification of a detected attack on a system, by detecting one or more modifications to one or more software components made by malicious network traffic;

identifying the malicious network traffic;

determining one or more compromised software components based on the detected one or more modifications and the identified malicious network traffic;

performing digital twin simulation to evaluate one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate;

creating an encapsulated environment;

provisioning the one or more software components to encapsulate to the encapsulated environment; and

redirecting the malicious network traffic to the encapsulated environment.

16 . The computer program product of claim 15 , further comprising:

continuing to process and respond to the detected attack in the encapsulated environment.

17 . The computer program product of claim 15 , wherein the redirecting of the malicious network traffic to the encapsulated environment is performed by creating a virtual proxy magnet.

18 . The computer program product of claim 15 , wherein the detecting of the one or more modifications to the one or more software components made by the malicious network traffic and the identifying the malicious network traffic, occur concurrently.

19 . The computer program product of claim 15 , wherein the performing of the digital twin simulation to evaluate the one or more risks associated with the one or more compromised software components in order to identify the one or more software components to encapsulate and the creating of the encapsulated environment, occur concurrently.

20 . The computer program product of claim 15 , wherein the creating of the encapsulated environment comprises an isolated network configuration, and wherein the encapsulated environment maintains same attributes and characteristics required to dynamically operate as it does on the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2023
From: MARZORATI, MAURO; LLAMAS VIRGEN, PAUL; MANJARREZ GUTIERREZ, PEDRO MAURICIO; CALDERON VACA, KARLA PAULINA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063327/0143 →
Continuity (1)
Related Publication 20240348626A1 · Oct 17, 2024
References Cited (24)
US 7594270B2 · Church · 2009 [cited by applicant]
US 9253206B1 · Fleischman · 2016 [cited by applicant]
US 9398043B1 · Yang · 2016 [cited by examiner]
US 10095866B2 · Gong · 2018 [cited by applicant]
US 10277612B2 · Marzorati · 2019 [cited by applicant]
US 10567441B2 · Nainar · 2020 [cited by applicant]
US 10579403B2 · Antony · 2020 [cited by applicant]
US 10674719B2 · Baughman · 2020 [cited by applicant]
US 10791132B1 · Power · 2020 [cited by examiner]
US 20100138920A1 · Kim · 2010 [cited by examiner]
US 20170093888A1 · Marzorati · 2017 [cited by applicant]
US 20180260574A1 · Morello · 2018 [cited by applicant]
US 20190222612A1 · Nainar · 2019 [cited by examiner]
US 20190246626A1 · Baughman · 2019 [cited by applicant]
US 20200389469A1 · Litichever · 2020 [cited by applicant]
US 20210328977A1 · Luo · 2021 [cited by examiner]
US 20220141194A1 · Xiao · 2022 [cited by applicant]
CN 106031118B · 2020 [cited by applicant]
JP 5250594B2 · 2013 [cited by applicant]
JP 5853327B2 · 2016 [cited by applicant]
Hirono et al, Development of a Secure Traffic Analysis System to Trace Malicious Activities on Internal Networks, Jul. 25, 2014, IEEE, pp. 305-310. (Year: 2014). [cited by examiner]
Bhayo et al, A Time-Efficient Approach Toward DDOS Attack Detection in IoT Network Using SDN, Jul. 19, 2021, IEEE, pp. 3612-3630. (Year: 2021). [cited by examiner]
Vrable, et al., “Scalability, fidelity, and containment in the potemkin virtual honeyfarm,” ACM SIGOPS Operating Systems Review [article], Dec. 2005, pp. 148-162, vol. 39, Issue 5, Retrieved from the Internet: <URL: htt… [cited by applicant]
Wang, “A cyber-security defense method using Docker containers,” Vanderbilt University Intuitional Repository [thesis], May 2015, 25 pages, Retrieved from the Internet: <URL: https://ir.vanderbilt.edu/handle/1803/11128>. [cited by applicant]