Cloud Forensic Worker Orchestration for Scalable Artifact Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and size of computer networks make forensic analysis after security incidents burdensome and computationally intensive, particularly when dealing with large amounts of computing devices, as existing methods are inefficient in collecting and processing forensic artifacts.

Innovation Solution

A scalable, cloud-based computer architecture that collects forensic evidence, processes it using automated and parallel processing techniques, and provides a contextual user-assisted workflow to guide users through the analysis, dynamically generating workers to handle tasks and terminating them to reduce processing burdens on cloud resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional forensic analysis methods are used on complex networks, then comprehensive artifact collection is achieved, but the process becomes extremely time-consuming and computationally intensive

Engineering Contradiction:
Improveforensic artifact collection completenessVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the forensic analysis process into discrete tasks that are stored in a task queue. Each task represents a specific analysis operation that can be independently executed. This segmentation allows the system to process forensic artifacts in manageable units rather than as a monolithic process, enabling parallel execution and reducing overall analysis time while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to the forensic analysis process by implementing phased execution. The system collects artifacts first, then processes them in subsequent phases using multiple workers. This dimensional change from sequential to phased parallel processing allows comprehensive artifact collection to be maintained while dramatically reducing the time required for analysis through concurrent task execution.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If more computational resources are allocated to process forensic tasks, then analysis speed increases, but cloud resource processing burden increases

Engineering Contradiction:
Improveforensic analysis speedVSAvoidcloud resource processing burden
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements dynamic worker generation and termination based on task queue conditions. Workers are generated when tasks are available and terminated when the queue is empty, allowing the system to adapt computational resource allocation to actual workload demands. This dynamic approach maximizes analysis speed when needed while minimizing resource burden during idle periods, creating an elastic resource utilization model.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent discards worker processes after task completion and recovers cloud resources for future use. Rather than maintaining persistent workers that consume resources continuously, the system spawns workers only when necessary, executes tasks, then terminates them to free resources. This approach maintains high productivity during active analysis while reducing the processing burden on cloud infrastructure during idle periods.

Inventive Principle:
Principle #34Discarding and recovering

3Ease of operation

If manual forensic analysis processes are used, then detailed investigation is possible, but the complexity of managing multiple devices and artifacts increases operator burden

Engineering Contradiction:
Improveforensic analysis operational complexityVSAvoidnetwork device and artifact management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the system automatically generates tasks, manages worker processes, queues jobs, and coordinates analysis operations without manual intervention. The automated worker orchestration system handles the complexity of managing multiple devices and artifacts by autonomously generating appropriate tasks based on collected evidence and executing them through managed workers, significantly reducing operator burden while maintaining investigative thoroughness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11785031B2Automated and scalable worker orchestration for cloud-based computer forensic analysis
Publication Date: 2023.10.10 DARKTRACE HLDG LTD
  • US11785031B2 patent drawing
  • US11785031B2 patent drawing
  • US11785031B2 patent drawing

AI summary

Disclosed are techniques for performing forensic analysis of computer systems in a cloud network. The techniques can include using a scalable, cloud-based, specialized computer architecture for performing the forensic analysis of computer systems.