Processing system for providing console access to a cyber range virtual environment

US10958670B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10958670-B2
Application numberUS-201816181608-A
CountryUS
Kind codeB2
Filing dateNov 6, 2018
Priority dateNov 6, 2018
Publication dateMar 23, 2021
Grant dateMar 23, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Aspects of the disclosure relate to processing systems that generate a virtual air gap to facilitate improved techniques for establishing console access to a cyber range virtual environment. The computing platform may receive a request to generate a virtual air gap to facilitate brokering of a connection between a secure console host platform and a cyber range host platform. The computing platform may generate the virtual air gap, which may include a built-in kill switch. The computing platform may implement the virtual air gap, which may be configured to receive requests to establish a connection between the secure console host platform and the cyber range host platform and to grant the secure console host platform access to a broker. The broker may establish the connection, and the computing platform may terminate the connection in response to activation of the built-in kill switch.

First claim

Opening claim text (preview).

What is claimed is: 1. A system, comprising: a user device; a secure console host platform; a virtual air gap; and a high-security virtual environment host platform, wherein: the high-security virtual environment host platform is a physical device on a physically separate network than the user device, the secure console host platform, and the virtual air gap; a virtual kill switch is associated with the virtual air gap; networking functionality on a target machine is disabled in response to activation of the virtual kill switch; after disabling the networking functionality on the target machine, one or more snapshots of one or more virtual machines are captured in one or more memory or disk files; and the one or more virtual machines are disabled by the virtual kill switch. 2. The system of claim 1 , wherein the virtual kill switch is an automated kill switch that is activated in response to detection of malware. 3. The system of claim 1 , wherein the virtual kill switch is a manual kill switch that is activated in response to detection of user input. 4. The system of claim 1 , wherein the virtual kill switch operates as an additional enforcement point associated with the virtual air gap to prevent detected malware from spreading. 5. The system of claim 1 , wherein the high-security virtual environment host platform comprises a cyber range. 6. A computing platform comprising: at least one processor; a communication interface communicatively coupled to the at least one processor; and memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to: generate a virtual air gap, wherein the virtual air gap is configured to grant access to a broker, wherein the broker is configured to establish a connection between a secure console host platform and a cyber range host platform, and wherein generating the virtual air gap comprises generating a built-in kill switch corresponding to the virtual air gap; implement the virtual air gap, wherein: the virtual air gap is configured to authenticate and authorize requests to establish a connection between the secure console host platform and the cyber range host platform, and the virtual air gap grants the secure console host platform access to the broker in response to the requests to establish the connection between the secure console host platform and the cyber range host platform, wherein: the broker establishes the connection between a console of the secure console host platform and the cyber range host platform, and the broker is hosted by an additional computing platform that is physically separate from the virtual air gap; and terminate the connection between the secure console host platform and the cyber range host platform in response to activation of the built-in kill switch. 7. The computing platform of claim 6 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to authenticate the secure console host platform prior to establishing, using the broker, the connection between the secure console host platform and the cyber range host platform. 8. The computing platform of claim 7 , wherein establishing the connection between the secure console host platform and the cyber range host platform causes initiation of a virtual data transfer between the secure console host platform and the cyber range host platform. 9. The computing platform of claim 8 , wherein terminating the connection between the secure console host platform and the cyber range host platform using the built-in kill switch is in response to determining that the virtual data being transferred to the secure console host platform corresponds to malware. 10. The computing platform of claim 6 , wherein the virtual air gap is a portion of the computing platform. 11. The computing platform of claim 6 , wherein the secure console host platform and the computing platform are connected to a shared network and wherein the cyber range host platform is not connected to the shared network. 12. The computing platform of claim 6 , wherein the built-in kill switch is activated in response to a user input. 13. The computing platform of claim 6 , wherein the built-in kill switch is automatically activated. 14. A method comprising: at a computing platform comprising at least one processor, a communication interface, and memory: generating a virtual air gap, wherein the virtual air gap is configured to grant access to a broker, wherein the broker is configured to establish a connection between a secure console host platform and a cyber range host platform, and wherein generating the virtual air gap comprises generating a built-in kill switch corresponding to the virtual air gap; implementing the virtual air gap, wherein: the virtual air gap is configured to authenticate and authorize requests to establish a connection between the secure console host platform and the cyber range host platform, and the virtual air gap grants the secure console host platform access to the broker in response to the requests to establish the connection between the secure console host platform and the cyber range host platform, wherein: the broker establishes the connection between a console of the secure console host platform and the cyber range host platform, and the broker is hosted by an additional computing platform that is physically separate from the virtual air gap; and terminating the connection between the secure console host platform and the cyber range host platform in response to activation of the built-in kill switch. 15. The method of claim 14 , further comprising authenticating the secure console host platform prior to establishing, using the broker, the connection between the secure console host platform and the cyber range host platform. 16. The method of claim 15 , wherein establishing the connection between the secure console host platform and the cyber range host platform causes initiation of a virtual data transfer between the secure console host platform and the cyber range host platform. 17. The method of claim 16 , wherein terminating the connection between the secure console host platform and the cyber range host platform using the built-in kill switch is in response to determining that the virtual data being transferred to the secure console host platform corresponds to malware. 18. The method of claim 14 , wherein the virtual air gap is a portion of the computing platform. 19. The method of claim 14 , wherein the secure console host platform and the computing platform are connected to a shared network and wherein the cyber range host platform is not connected to the shared network. 20. The method of claim 14 , wherein the built-in kill switch is activated in response to a user input.

Assignees

Inventors

Classifications

  • Computer malware detection or handling, e.g. anti-virus arrangements · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • using revocation of authorisation · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10958670B2 cover?
Aspects of the disclosure relate to processing systems that generate a virtual air gap to facilitate improved techniques for establishing console access to a cyber range virtual environment. The computing platform may receive a request to generate a virtual air gap to facilitate brokering of a connection between a secure console host platform and a cyber range host platform. The computing platf…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 23 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).