Endpoint Activity Forensic Analysis via Causal Event Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current forensic analysis techniques face challenges in identifying the root cause of security compromises in complex computing environments, particularly with sophisticated malware, where tracing causal relationships among computing objects is complex and time-sensitive.
Innovation Solution
A data recorder stores endpoint activity as sequences of events, generating an event graph that can be traversed in reverse order from a detected security event to identify causal relationships, applying cause identification rules to pinpoint the root cause and subsequently trace affected objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional forensic analysis techniques are used to investigate security compromises, then the analysis process can be performed, but the root cause identification becomes complex and time-consuming in sophisticated malware scenarios
Solution Approach 1:
The system performs preliminary action by continuously recording causal relationships among computing objects before security compromises occur. The data recorder captures events and their causal connections in advance, creating a pre-organized database that enables rapid root cause analysis when security events are detected, eliminating the need for time-consuming retrospective investigation.
Solution Approach 2:
The patent applies segmentation by dividing the complex computing environment into discrete computing objects (processes, files, registry entries, network connections) and their causal relationships. This segmentation allows the system to manage complexity through structured units that can be independently tracked and queried during forensic analysis.
2Loss of information
If comprehensive monitoring of all computing objects is implemented, then complete forensic data is available, but the system complexity and data management burden increase significantly
Solution Approach 1:
The system applies local quality by recording only the causal relationships relevant to security events rather than all possible system interactions. The data recorder selectively captures events with their causal connections, maintaining forensic completeness for security-related activities while avoiding unnecessary data collection that would increase management complexity.
Solution Approach 2:
The patent introduces an intermediary approach through the data recorder that acts as a mediator between comprehensive monitoring requirements and practical data management. The recorder processes and organizes causal relationships in a structured format, making the information accessible and manageable while maintaining completeness for forensic analysis.
3Speed
If real-time analysis of all system events is performed, then immediate security response is possible, but the computational resources and processing complexity increase substantially
Solution Approach 1:
The system performs preliminary action by pre-recording causal relationships in a structured format, so that when security events are detected, the relevant information is already organized and ready for rapid analysis. This eliminates the need for real-time processing of all system events while enabling fast security responses through pre-prepared data.
Solution Approach 2:
The patent extracts only the necessary causal relationship information from the broader system events for forensic analysis. By selectively capturing and storing only the relevant causal connections rather than processing all system activity in real-time, the system reduces computational resource consumption while maintaining the ability to respond quickly to security compromises.
Data Source
AI summary
A data recorder stores endpoint activity on an ongoing basis as sequences of events that causally relate computer objects such as processes and files. When a security event is detected, an event graph may be generated based on these causal relationships among the computing objects. For a root cause analysis, the event graph may be traversed in a reverse order from the point of an identified security event (e.g., a malware detection event) to preceding computing objects, while applying one or more cause identification rules to identify a root cause of the security event. Once a root cause is identified, the event graph may be traversed forward from the root cause to identify other computing objects that are potentially compromised by the root cause.


