Endpoint Activity Forensic Analysis via Causal Event Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current forensic analysis techniques face challenges in identifying the root cause of security compromises in complex computing environments, particularly with sophisticated malware, where tracing causal relationships among computing objects is complex and time-sensitive.

Innovation Solution

A data recorder stores endpoint activity as sequences of events, generating an event graph that can be traversed in reverse order from a detected security event to identify causal relationships, applying cause identification rules to pinpoint the root cause and subsequently trace affected objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional forensic analysis techniques are used to investigate security compromises, then the analysis process can be performed, but the root cause identification becomes complex and time-consuming in sophisticated malware scenarios

Engineering Contradiction:
Improveroot cause identification accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by continuously recording causal relationships among computing objects before security compromises occur. The data recorder captures events and their causal connections in advance, creating a pre-organized database that enables rapid root cause analysis when security events are detected, eliminating the need for time-consuming retrospective investigation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies segmentation by dividing the complex computing environment into discrete computing objects (processes, files, registry entries, network connections) and their causal relationships. This segmentation allows the system to manage complexity through structured units that can be independently tracked and queried during forensic analysis.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If comprehensive monitoring of all computing objects is implemented, then complete forensic data is available, but the system complexity and data management burden increase significantly

Engineering Contradiction:
Improveforensic data completenessVSAvoiddata management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system applies local quality by recording only the causal relationships relevant to security events rather than all possible system interactions. The data recorder selectively captures events with their causal connections, maintaining forensic completeness for security-related activities while avoiding unnecessary data collection that would increase management complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary approach through the data recorder that acts as a mediator between comprehensive monitoring requirements and practical data management. The recorder processes and organizes causal relationships in a structured format, making the information accessible and manageable while maintaining completeness for forensic analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If real-time analysis of all system events is performed, then immediate security response is possible, but the computational resources and processing complexity increase substantially

Engineering Contradiction:
Improvesecurity response speedVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSPower

Solution Approach 1:

The system performs preliminary action by pre-recording causal relationships in a structured format, so that when security events are detected, the relevant information is already organized and ready for rapid analysis. This eliminates the need for real-time processing of all system events while enabling fast security responses through pre-prepared data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the necessary causal relationship information from the broader system events for forensic analysis. By selectively capturing and storing only the relevant causal connections rather than processing all system activity in real-time, the system reduces computational resource consumption while maintaining the ability to respond quickly to security compromises.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12052272B2Forensic analysis of computing activity
Publication Date: 2024.07.30 SOPHOS LTD
  • US12052272B2 patent drawing
  • US12052272B2 patent drawing
  • US12052272B2 patent drawing

AI summary

A data recorder stores endpoint activity on an ongoing basis as sequences of events that causally relate computer objects such as processes and files. When a security event is detected, an event graph may be generated based on these causal relationships among the computing objects. For a root cause analysis, the event graph may be traversed in a reverse order from the point of an identified security event (e.g., a malware detection event) to preceding computing objects, while applying one or more cause identification rules to identify a root cause of the security event. Once a root cause is identified, the event graph may be traversed forward from the root cause to identify other computing objects that are potentially compromised by the root cause.