Contextual Forensic Data for Cybersecurity Incident Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions face challenges in accurately detecting cyber-attacks due to the large amount of raw data from user activities, which lacks the necessary information for effective identification and mitigation.

Innovation Solution

The method involves identifying discrete user actions and correlating them with subsequent system changes to provide contextual forensic data, taking snapshots before and after user actions, and correlating user activities with software vulnerabilities to determine the root cause of issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If raw user activity data is collected from multiple systems and devices, then the quantity of data increases, but the ability to accurately detect cyber-attacks deteriorates due to lack of contextual information

Engineering Contradiction:
Improvequantity of dataVSAvoidaccuracy of cyber-attack detection
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary processing system that collects raw user activity data from multiple sources and transforms it into contextualized forensic data. This intermediary layer correlates user actions with system changes, adding contextual information that enables accurate cyber-attack detection while managing the complexity of large-scale data collection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms raw user activity data into contextualized forensic data by changing the parameters of data representation. It identifies specific user actions and correlates them with system changes, converting unstructured raw data into structured forensic records with temporal and contextual parameters that enable precise security analysis.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If snapshots are taken frequently to capture system changes, then the precision of forensic analysis improves, but the loss of time and computational resources increases

Engineering Contradiction:
Improveprecision of forensic analysisVSAvoidtime and computational resources
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent takes preliminary snapshots of system state before user actions occur and correlates them with post-action system changes. This preliminary action approach captures only relevant state transitions rather than continuous monitoring, providing sufficient forensic precision while minimizing time and computational resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential before-and-after system states related to specific user actions, rather than capturing all system changes continuously. This extraction of relevant state transitions provides adequate forensic analysis precision while significantly reducing the time and computational overhead associated with comprehensive continuous monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If comprehensive user activity data is collected from all systems and devices, then the coverage of monitoring improves, but the device complexity increases due to data processing requirements

Engineering Contradiction:
Improvecoverage of monitoringVSAvoidcomplexity of data processing system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex task of comprehensive security monitoring into manageable components: collecting user activity data from multiple sources, identifying specific user actions, correlating actions with system changes, and generating contextualized forensic records. This segmentation maintains broad monitoring coverage while reducing overall system complexity through modular processing stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal forensic data generation system that handles multiple data sources, user actions, and system changes through a single correlated processing framework. This multi-functional approach provides comprehensive monitoring coverage across diverse systems while avoiding the complexity of separate processing systems for each data source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11979424B2Providing contextual forensic data for user activity-related security incidents
Publication Date: 2024.05.07 PALO ALTO NETWORKS INC
  • US11979424B2 patent drawing
  • US11979424B2 patent drawing
  • US11979424B2 patent drawing

AI summary

Techniques for providing contextual forensic data based on user activities. A first method includes identifying a user action in user activity data, wherein the user action is a discrete event initiated by a user, wherein the user action is performed with respect to a portion of a system; and correlating the identified user action with at least one system change, wherein the at least one system change is related to the portion of the system, wherein the at least one system change occurred after the user action. A second method includes taking a first snapshot before a user action occurs, wherein the user action is a discrete event initiated by a user, wherein the first snapshot is taken of at least a portion of a system; and taking a second snapshot after the user action occurs, wherein the second snapshot is taken of the at least a portion of the system.