Cloud Forensic Workflow Engine for Parallel Incident Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and size of computer networks make forensic analysis and incident remediation burdensome, time-consuming, and computationally intensive, especially for large-scale security incidents, due to the difficulty in efficiently processing and analyzing forensic data across multiple devices and systems.
Innovation Solution
A scalable, cloud-based computer architecture that processes forensic data by splitting tasks into overlapping processing units, using a dynamic number of computing resources based on the workload, to efficiently analyze and remediate security incidents in multi-tenant environments, including premises and cloud networks, while maintaining a chain of custody and providing user-assisted workflows for non-expert users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional forensic analysis methods are used on complex networks, then analysis completeness can be maintained, but analysis time and computational resources increase significantly
Solution Approach 1:
The patent divides forensic analysis into multiple workflow tasks that can be executed in parallel. The workflow engine breaks down complex analysis procedures into discrete, manageable tasks that can be distributed across multiple computing resources, enabling simultaneous processing of different forensic artifacts and reducing overall analysis time while maintaining completeness.
Solution Approach 2:
The patent introduces a temporal dimension to forensic analysis by implementing overlapping task execution. Tasks are scheduled to run in overlapping time periods rather than strictly sequentially, allowing multiple analysis operations to progress concurrently. This temporal parallelism reduces analysis time while preserving the logical dependencies required for complete forensic examination.
2Productivity
If more computing resources are allocated to process forensic data, then processing speed improves, but system complexity and resource management difficulty increase
Solution Approach 1:
The workflow engine automatically manages computing resource allocation based on task requirements. It dynamically provisions and deprovisions computing resources as needed, eliminating the need for manual resource management. The system self-adjusts resource allocation to match workload demands, improving processing speed while avoiding the complexity of manual resource orchestration.
Solution Approach 2:
The patent creates a universal workflow engine that can handle multiple types of forensic analysis tasks through a single platform. This multi-functional system can process various forensic artifacts (logs, memory dumps, disk images) using the same infrastructure, reducing system complexity compared to having separate specialized systems for each analysis type.
3Measurement precision
If forensic analysis is performed manually by experts, then analysis accuracy is maintained, but operational burden and time consumption increase
Solution Approach 1:
The workflow engine automatically executes forensic analysis tasks without requiring continuous expert intervention. It autonomously manages task scheduling, resource allocation, and result aggregation, significantly reducing operational burden. Expert knowledge is embedded in the workflow definitions, allowing automated execution while maintaining analysis accuracy that would otherwise require manual expert review.
4Productivity
If cloud-based parallel processing is implemented, then processing efficiency improves, but resource coordination complexity increases
Solution Approach 1:
The workflow engine serves as an intermediary between forensic analysis tasks and cloud computing resources. It abstracts the complexity of resource coordination by providing a standardized interface for task submission and result retrieval. The engine handles resource provisioning, task distribution, and result aggregation, improving processing efficiency while shielding users from coordination complexity.
Data Source
AI summary
Disclosed are techniques for analyzing forensic data and remediating security incidents in a multi-tenant environment. The techniques comprises receiving the forensic data from a network by receiving a copy of data from each a computing device and a containerized systems which accesses the network, wherein the network includes a premises network and/or a cloud network. Further, processing the forensic data received from the network by determining if the network has been accessed by an unauthorized computing system by parsing the forensic data, wherein processing is performed by splitting the processing of the forensic data into a number of tasks and processing the number of tasks in overlapping time using a number of working resources, the group of working resources are scaled based on the number of tasks, Finally, processing the number of tasks if it is determining that the unauthorized computing device has accessed the network.


