Correlating Forensic and Non-Forensic Data in IT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Efficiently collecting and correlating forensic data from distributed endpoint devices in networked computer systems to address complex security threats remains challenging due to the variety of endpoint types and user activities, as well as the complexity of multi-layered security threats that involve multiple components.

Innovation Solution

A data intake and query system, such as the SPLUNKĀ® ENTERPRISE system, is used to collect and index forensic data from endpoint devices, allowing for correlation with other data sources, employing techniques like late-binding schema, keyword indexing, and high-performance analytics to facilitate efficient data retrieval and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If forensic data is collected from distributed endpoint devices using traditional methods, then data collection can be performed, but the process becomes inefficient and difficult to correlate across multiple devices and data sources

Engineering Contradiction:
Improvedata collection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines forensic data collection, indexing, and correlation capabilities into a unified data intake and query system. This system merges multiple data sources (endpoint devices, security information, event management data) into a single platform that can efficiently collect, index, and correlate data across distributed devices, resolving the contradiction between collection efficiency and system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data intake and query system provides universal functionality by handling multiple types of data (forensic data, security events, network traffic) from diverse sources through a single system. This multi-functional approach eliminates the need for separate specialized tools for each data type, improving productivity while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional security monitoring applications are used, then known security threats can be detected, but complex multi-layered security threats involving multiple components cannot be efficiently monitored and remediated

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidability to handle complex threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to security monitoring by implementing a data correlation layer that connects forensic data with security information and event management data. This additional dimensional layer enables the system to detect complex multi-layered threats that span multiple devices and data sources, while maintaining the ability to detect known threats through traditional methods.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The data intake and query system acts as an intermediary between raw forensic data from endpoint devices and security analysis tools. This intermediary layer correlates and contextualizes data from multiple sources, enabling reliable detection of both known threats and complex emerging threats that require cross-referencing multiple data points.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If forensic data from multiple sources is correlated, then comprehensive security analysis is achieved, but data retrieval and analysis become time-consuming

Engineering Contradiction:
Improvecompleteness of security analysisVSAvoiddata retrieval time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically indexing forensic data from endpoint devices as it is collected, rather than waiting for analysis requests. This pre-indexing process organizes data in advance with appropriate metadata and relationships established, enabling rapid retrieval and correlation when security analysis is needed, thus reducing analysis time while maintaining completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11743285B2Correlating forensic and non-forensic data in an information technology environment
Publication Date: 2023.08.29 CISCO TECHNOLOGY INC
  • US11743285B2 patent drawing
  • US11743285B2 patent drawing
  • US11743285B2 patent drawing

AI summary

Techniques and mechanisms are disclosed enabling efficient collection of forensic data from client devices, also referred to herein as endpoint devices, of a networked computer system. Embodiments described herein further enable correlating forensic data with other types of non-forensic data from other data sources. A network security application described herein further enables generating various dashboards, visualizations, and other interfaces for managing forensic data collection, and displaying information related to collected forensic data and information related to identified correlations between items of forensic data and other items of non-forensic data.