Forensic Isolation of Cloud Storage Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current forensic investigation techniques are hindered in cloud environments due to ongoing modifications by authorized users after unauthorized access, making it difficult to perform a comprehensive analysis.

Innovation Solution

A system and method for forensically isolating a production cloud computing and storage environment by detecting unauthorized access, deploying a forensic isolation application to freeze resources, duplicating them, and storing the duplicates outside the environment for analysis while rerouting authorized requests to the isolated resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authorized users continue to access and modify cloud resources after unauthorized access is detected, then normal operations can be maintained, but forensic investigation capability is compromised

Engineering Contradiction:
Improvenormal operationsVSAvoidforensic investigation capability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system segments cloud resources into two distinct copies: a frozen forensic copy for investigation and an operational copy for continued business operations. This segmentation allows forensic analysis to proceed without interference from ongoing modifications while maintaining service continuity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a duplicate copy of the compromised cloud resources. The original resources remain operational while the copied resources are frozen for forensic analysis, allowing both investigative integrity and operational continuity to coexist.

Inventive Principle:
Principle #26Copying

2Reliability

If cloud resources are frozen for forensic analysis, then forensic investigation integrity is improved, but operational availability deteriorates

Engineering Contradiction:
Improveforensic investigation integrityVSAvoidoperational availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of freezing the original operational resources, the system creates a separate duplicate copy for forensic analysis. This copying approach preserves the integrity of forensic investigation while leaving the original resources available for continued operations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces a forensic isolation environment as an intermediary layer between the operational resources and the forensic analysis process. This intermediary allows investigators to analyze a replicated environment without affecting the availability of production resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional forensic isolation techniques are applied to individual hard drives or computers, then forensic analysis can be performed, but cloud environment complexity prevents implementation

Engineering Contradiction:
Improveforensic analysis capabilityVSAvoidcloud environment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system provides a universal forensic isolation solution that works across diverse cloud resource types (storage buckets, databases, compute instances, etc.) through a unified approach of resource duplication and freezing, rather than requiring resource-specific forensic techniques.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies a consistent copying mechanism across all cloud resource types, creating frozen duplicates that can be analyzed forensically. This universal copying approach simplifies the complexity of implementing different forensic techniques for different resource types.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12072977B2Forensic isolation of a production cloud computing and storage environment
Publication Date: 2024.08.27 CAPITAL ONE SERVICES LLC
  • US12072977B2 patent drawing
  • US12072977B2 patent drawing
  • US12072977B2 patent drawing

AI summary

Embodiments disclosed are directed to a computing system that performs steps to forensically isolate a compromised storage resource (e.g., bucket) of a production cloud computing and storage environment. In response to detecting an unauthorized access to resources (e.g., objects) stored in storage resource of the production cloud computing and storage environment, the computing system deploys a forensic isolation application that freezes the compromised storage resource so that a forensic analysis can be performed, duplicates the compromised storage resource's resources, and stores the duplicate resources as forensically isolated resources in a storage device outside of the production cloud computing and storage environment. The forensic isolation application then stores the duplicate resources as operational resources. Subsequently, the forensic isolation application reroutes authorized requests for the frozen resource to the operational copy of the frozen resource.