A system and method for distributed attack process forensics

By constructing a distributed proactive deception environment and agentless forensics technology, the problems of real-time monitoring and resource consumption in traditional forensics technologies are solved, enabling real-time monitoring and recording of unknown threats and improving user experience.

CN115378706BActive Publication Date: 2026-02-03BEIJING YUAN FULCRUM INFORMATION SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211007483.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-22
Publication Date
2026-02-03
Estimated Expiration
2042-08-22

AI Technical Summary

Technical Problem

Existing technologies cannot effectively monitor and record the attack process of unknown threats in real time. Traditional forensic techniques consume a lot of resources, have a poor user experience, and are easily identified by attackers.

Method used

A distributed, proactive deception environment is constructed, user behavior is monitored through a decoy system, dynamic evidence collection is performed using an agentless approach, and non-intrusive evidence collection is achieved by combining system kernel event tracing.

Benefits of technology

It enables real-time monitoring and recording of unknown threats, reduces resource consumption, improves user experience, and avoids being identified by attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378706B_ABST
    Figure CN115378706B_ABST
Patent Text Reader

Abstract

The application discloses a system and method for distributed attack process forensics, introduces a user-unaware, distributed active defense model into attack forensics, automatically constructs a high-fidelity and high-density camouflage environment in a network, constructs decoys and luring traps along the way in the network and terminal, actively spreads false messages and polluted data to an attacker, and when the attacker intrudes, issues a forensics strategy and a forensics component in an Agentless mode, realizes distributed and non-invasive dynamic forensics through system kernel event tracking, and makes up for the shortcomings of existing attack forensics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically to a system and method for forensic investigation of distributed attack processes. Background Technology

[0002] When networks and terminal systems are compromised, the main tasks of attack forensics are to promptly detect the attack, extract intrusion evidence to identify the intruder, and fully record the intrusion process. Traditional security defense technologies, such as intrusion detection systems, intrusion prevention systems, and web intrusion detection, mostly focus on protecting against known attacks. These security defense technologies cannot prevent or detect intrusion attacks from unknown threats.

[0003] Currently, most traditional forensic techniques in this field involve static analysis and dynamic forensics of the target system after an incident occurs. Static forensics lacks complete real-time monitoring and recording of attack actions, resulting in low effectiveness. Dynamic forensics mostly employs kernel or application-level hooking methods, which are constantly resident on the terminal, consuming significant resources, leading to issues such as lag, poor user experience, and easy detection by attackers. Summary of the Invention

[0004] In view of this, the present invention provides a system and method for forensic investigation of distributed attack processes that can solve the above problems.

[0005] To achieve the above objectives, the present invention provides the following technical solution, comprising the following steps:

[0006] S1: Construct a distributed active deception environment and a decoy system simultaneously;

[0007] S2: Obtain user action commands through the data center and detect attack commands;

[0008] S3: After receiving the attack command, the evidence collection and classification master node collects, classifies, and uploads the evidence. It analyzes the evidence collection service command and, based on the analysis results, distributes the evidence collection service request to the appropriate evidence collection slave node of the evidence collection master node so that the evidence collection slave node can execute the evidence collection process.

[0009] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the decoy system constructed in S1 consists of a real host terminal, a network decoy sensing master node, and security devices such as linked boundary devices, IDS / IPS, and WAF. The decoy system transmits user commands to the detection master node, which performs behavioral monitoring and feature detection on the user commands and sends the detection results to the forensic classification master node for analysis and processing.

[0010] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the real host terminal and the network decoy perception master node perform behavioral monitoring and detection of user commands, and are equipped with decoy nodes, decoy port nodes, fake traffic nodes, and polluted data nodes. The linked boundary devices, IDS / IPS, WAF and other security devices perform feature detection of user commands.

[0011] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the forensic classification master node is equipped with a data processing system and a log system; the data processing system receives the behavior monitoring and feature detection data received by the decoy system and sends it to the forensic analysis node, and performs analysis and processing through the forensic analysis node, then classifies the intrusion data instructions to obtain data analysis results and transmits them to the forensic management system to complete the logic.

[0012] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the forensic classification master node includes a trigger investigation and forensic node, an forensic storage module, an investigation and forensic node, an intrusion evidence classification node, and an forensic analysis node; the trigger investigation and forensic node receives data instructions from the data processing system and the log system, and begins to execute logical instructions downwards, performs data analysis through the investigation and forensic node, the analysis results are detected and classified by the intrusion evidence classification node, and then the forensic analysis node transmits the classified instructions to the forensic management system.

[0013] Preferably, in the above-mentioned system and method for obtaining evidence during a distributed attack process, the intrusion evidence classification nodes include: host evidence extraction nodes, network evidence extraction nodes, other evidence extraction nodes, evidence fusion nodes, trace preservation nodes, and tracking nodes. After the host evidence extraction nodes, network evidence extraction nodes, and other evidence extraction nodes analyze the data instructions, they are processed by the evidence fusion nodes, trace preservation nodes, and tracking nodes, respectively. The evidence fusion nodes and trace preservation nodes then distribute the analyzed data to the evidence analysis nodes.

[0014] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the logic of the real host terminal is as follows:

[0015] S1: The investigation and evidence collection node is triggered after the attack and intrusion command enters;

[0016] S2: The investigation and evidence collection node sends the processed intrusion commands to the evidence collection component and then to the terminal. The intrusion commands are then classified through system kernel event tracing (ETW).

[0017] S3: Store, log, and sign the classified intrusion commands as evidence, classify, analyze, and aggregate the investigation evidence, and finally transmit the analysis results to the evidence management system.

[0018] Preferably, in the above-mentioned system and method for forensic analysis of a distributed attack process, the system kernel event tracing (ETW) in S2 is divided into a system log analysis plugin, a network traffic analysis plugin, a browser analysis plugin, and an account activity analysis plugin; the system log analysis plugin also includes a memory analysis plugin and a process analysis plugin; the network traffic analysis plugin includes a file analysis plugin and a registry analysis plugin; the browser analysis plugin includes a history analysis plugin and a driver analysis plugin; and the account activity analysis plugin includes an auto-run plugin and a PowerShell analysis plugin.

[0019] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, the log system is used to obtain switch logs, router logs, and other system logs.

[0020] Preferably, in the above-mentioned system and method for forensic investigation of a distributed attack process, step S3 also generates samples and tracks them.

[0021] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a system and method for distributed attack process forensics. The present invention introduces a user-unnoticed, distributed active defense model into attack forensics, automatically constructs a highly realistic and high-density camouflage environment in the network, and constructs decoys and deception traps along the way in the network and terminals, actively spreading false information and polluting data to attackers. When the attacker intrudes, the forensics strategy and forensics components are issued in an agentless manner, and distributed non-intrusive dynamic forensics are achieved through system kernel event tracking, making up for and optimizing the shortcomings of existing attack forensics. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0023] Figure 1 The attached figure is a schematic diagram of the logic flow of the decoy construction system of the present invention.

[0024] Figure 2 The attached figure is a schematic diagram of the actual host terminal logic flow of the present invention. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] Please see the appendix Figure 1-2 This invention discloses a system and method for forensic investigation of a distributed attack process.

[0027] This invention includes the following steps:

[0028] S1: Construct a distributed active deception environment and a decoy system. The decoy system consists of real host terminals, network trapping and sensing master nodes, and linked boundary devices, IDS / IPS, WAF and other security devices. The decoy system transmits user commands to the detection master node. The detection master node performs behavioral monitoring and feature detection on the user commands and sends the detection results to the evidence collection and classification master node for analysis and processing.

[0029] S2: Obtain user action commands through the data center and detect attack commands;

[0030] S3: After receiving the attack command, the evidence collection and classification master node collects, classifies, and uploads the evidence. It analyzes the evidence collection service command and, based on the analysis results, distributes the evidence collection service request to the appropriate evidence collection slave node of the evidence collection master node so that the evidence collection slave node can execute the evidence collection process.

[0031] To further optimize the above technical solution, the real host terminal and the network trapping and sensing master node perform behavioral monitoring and detection of user commands, and are equipped with decoy nodes, decoy port nodes, fake traffic nodes, and polluting data nodes. The linked boundary devices, IDS / IPS, WAF and other security devices perform feature detection of user commands.

[0032] To further optimize the above technical solution, the main node for evidence classification is equipped with a data processing system and a log system. The data processing system receives the behavior monitoring and feature detection data received by the decoy system and sends it to the evidence analysis node. The evidence analysis node then analyzes and processes the data, classifies the intrusion data commands to obtain data analysis results, and transmits them to the evidence management system to complete the logic. The log system is used to obtain switch and router logs as well as logs from other systems.

[0033] To further optimize the above technical solution, the evidence classification master node includes a trigger investigation and evidence collection node, an evidence storage module, an investigation and evidence collection node, an intrusion evidence classification node, and an evidence analysis node. The trigger investigation and evidence collection node receives data instructions from the data processing system and the log system, and begins to execute logical instructions downwards. Data analysis is performed through the investigation and evidence collection node, and the analysis results are detected and classified by the intrusion evidence classification node. Then, the evidence analysis node transmits the classified instructions to the evidence management system.

[0034] To further optimize the above technical solution, the intrusion evidence classification nodes include: host evidence extraction node, network evidence extraction node, other evidence extraction node, evidence fusion node, trace preservation node, and tracking node. After the host evidence extraction node, network evidence extraction node, and other evidence extraction node analyze the data instructions, they are processed by the evidence fusion node, trace preservation node, and tracking node, respectively. The evidence fusion node and trace preservation node then send the analyzed data to the evidence collection and analysis node.

[0035] To further optimize the above technical solution, the logic of the evidence collection and classification master node is as follows:

[0036] S1: The investigation and evidence collection node is triggered after the attack and intrusion command enters;

[0037] S2: The investigation and evidence collection node sends the processed intrusion commands to the evidence collection component and then to the terminal. The intrusion commands are then categorized by the System Kernel Event Tracing (ETW). The System Kernel Event Tracing (ETW) includes plugins for system log analysis, network traffic analysis, browser analysis, and account activity analysis. The system log analysis plugin further includes memory analysis and process analysis plugins. The network traffic analysis plugin includes file analysis and registry analysis plugins. The browser analysis plugin includes history analysis and driver analysis plugins. The account activity analysis plugin includes auto-run and PowerShell analysis plugins.

[0038] S3: Store, log, and sign the classified intrusion commands as evidence, classify, analyze, and aggregate the investigation evidence, and finally transmit the analysis results to the evidence management system.

[0039] To further optimize the above technical solution, after the user inputs the evidence request data command, it is verified by the decoy system through the reception of real host terminals, network decoy sensing master nodes, and linked boundary devices, IDS / IPS, WAF, and other security devices. The real host terminal and network decoy sensing master nodes, after detecting the user's evidence request data command through decoy nodes, decoy port nodes, fake traffic nodes, and polluted data nodes, transmit it back to the real host terminal and network decoy sensing master nodes, and then generate behavior monitoring detection data commands and transmit them to the behavior monitoring detection nodes. The linked boundary devices, IDS / IPS, WAF, and other security devices... The data generates feature detection instructions. The behavior monitoring detection data instructions and feature detection instructions are then aggregated by the data processing system and the log system and sent to the evidence classification master node, triggering the investigation and evidence collection node to process them. The investigation and evidence collection node sends the processed intrusion instructions to the evidence collection component to the terminal. Then, through the system kernel event tracing (ETW), the intrusion instructions are classified, saved and tracked by the host evidence extraction node, network evidence extraction node, other evidence extraction node, evidence fusion node, trace preservation node and tracking node. The evidence fusion node and trace preservation node generate detection result instructions from the detection data and submit them to the evidence management system to complete the logic.

[0040] To further optimize the above technical solutions, better prevent unknown network intrusion attacks, and more accurately and efficiently collect evidence of network attacks, a user-unnoticed, distributed proactive defense model is introduced into attack forensics based on the deception and trapping concept. This model automatically constructs a highly realistic and dense camouflage environment within the network, building decoys and traps along the network and terminals to actively spread false information and polluted data to attackers. Once an attacker intrudes, forensic strategies and components are distributed using an agent-less approach, and distributed, non-intrusive dynamic forensics are achieved through system kernel event tracing, thus addressing and optimizing the shortcomings of existing attack forensics methods.

[0041] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0042] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for forensic investigation during a distributed attack process, characterized in that... This includes the following steps: S1: Construct a distributed active deception environment and a decoy system simultaneously; S2: Receive user action commands and detect attack commands; S3: After receiving the attack command, the evidence collection and classification master node collects evidence, classifies it, and uploads it. It analyzes the evidence collection service command and, based on the analysis results, distributes the evidence collection service request to the appropriate evidence collection slave node of the evidence collection master node so that the evidence collection slave node can execute the evidence collection process. The decoy system constructed in S1 consists of a real host terminal, a network decoy sensing master node, and linked boundary devices, IDS / IPS, and WAF security devices. The decoy system transmits user action commands to the detection master node, which performs behavioral monitoring and feature detection on the user action commands and sends the detection results to the evidence collection and classification master node for analysis and processing. The real host terminal and network trapping and sensing master node perform behavioral monitoring and detection of user action commands, and are equipped with decoy nodes, decoy port nodes, fake traffic nodes, and polluting data nodes. The linked boundary device, IDS / IPS, and WAF security device perform feature detection of user action commands. The main node for evidence collection and classification is equipped with a data processing system and a log system. The data processing system receives the behavior monitoring and feature detection data received by the decoy system and sends it to the evidence collection and analysis node. The evidence collection and analysis node then analyzes and processes the data, classifies the intrusion data commands to obtain data analysis results, and transmits them to the evidence collection and management system to complete the logic. The evidence collection and classification master node includes a trigger investigation and evidence collection node, an evidence storage module, an investigation and evidence collection node, an intrusion evidence classification node, and an evidence analysis node. The trigger investigation and evidence collection node receives data instructions from the data processing system and the log system, and begins to execute logical instructions downwards. Data analysis is performed through the investigation and evidence collection node, and the analysis results are detected and classified by the intrusion evidence classification node. Then, the evidence analysis node transmits the classified instructions to the evidence collection and management system. The logic of the real host terminal is as follows: a: The attack / intrusion command triggers the investigation and evidence collection node upon entry; b: The investigation and evidence collection node sends the processed intrusion commands to the evidence collection component and then to the terminal. The intrusion commands are then classified through system kernel event tracing (ETW). c: Store, log, and sign the classified intrusion commands as evidence, classify, analyze, and aggregate the investigation evidence, and finally transmit the analysis results to the evidence management system.

2. The method for forensic investigation of a distributed attack process according to claim 1, characterized in that... The intrusion evidence classification nodes include: host evidence extraction nodes, network evidence extraction nodes, other evidence extraction nodes, evidence fusion nodes, trace preservation nodes, and tracking nodes. After the host evidence extraction nodes, network evidence extraction nodes, and other evidence extraction nodes analyze the data instructions, they are processed by the evidence fusion nodes, trace preservation nodes, and tracking nodes, respectively. The evidence fusion nodes and trace preservation nodes then send the analyzed data to the evidence collection and analysis nodes.

3. The method for forensic investigation of a distributed attack process according to claim 1, characterized in that... The system kernel event tracing (ETW) in S2 is divided into a system log analysis plugin, a network traffic analysis plugin, a browser analysis plugin, and an account activity analysis plugin. The system log analysis plugin also includes a memory analysis plugin and a process analysis plugin. The network traffic analysis plugin includes a file analysis plugin and a registry analysis plugin. The browser analysis plugin includes a history analysis plugin and a driver analysis plugin. The account activity analysis plugin includes an auto-run plugin and a PowerShell analysis plugin.

4. The method for forensic investigation of a distributed attack process according to claim 1, characterized in that... The log system is used to obtain switch and router logs as well as other system logs.

5. The method for forensic investigation of a distributed attack process according to claim 1, characterized in that... In step S3, samples are also generated and tracked.

Citation Information

Patent Citations

  • A network tracking system

    CN101262351A

  • Evidence obtaining and tracing method and device for terminal attack and computer equipment

    CN112287340A