Endpoint Forensic Agent Memory-Only Artifact Collection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in efficiently investigating and responding to security incidents due to difficulties in collecting and analyzing data, particularly in preserving forensic artifacts and correlating endpoint monitoring data with forensic artifacts.
Innovation Solution
A computer-implemented method that involves an agent installed on an endpoint collecting endpoint monitoring data, transmitting it to a cloud server, and upon detecting a security incident, identifying and transmitting forensic artifacts to a destination server without writing to non-volatile storage, thereby preserving data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If forensic artifacts are collected and stored on non-volatile storage medium, then data persistence is improved, but data integrity is worsened due to risk of modification or loss
Solution Approach 1:
The patent extracts the forensic artifact data from the non-volatile storage medium and loads it into random access memory (RAM) for analysis. This separation allows the original forensic artifacts to remain preserved on storage while working copies are analyzed in memory, preventing modification of the original evidence during the investigation process.
Solution Approach 2:
The system creates copies of forensic artifacts from non-volatile storage and loads them into random access memory for analysis. Multiple copies can be created and manipulated in memory without affecting the original forensic artifacts stored on the non-volatile medium, enabling thorough analysis while preserving evidence integrity.
2Loss of information
If comprehensive forensic artifact collection is performed, then investigation completeness is improved, but system performance is worsened due to memory constraints
Solution Approach 1:
The patent segments the forensic artifact collection process by organizing artifacts into different categories and loading them into random access memory in manageable portions. This segmentation allows the system to handle comprehensive artifact collections without overwhelming memory resources, enabling complete investigation while maintaining system performance.
Solution Approach 2:
The system loads forensic artifacts into random access memory as needed for specific analysis tasks rather than loading all artifacts simultaneously. This partial action approach allows comprehensive investigation capabilities while managing memory consumption efficiently by loading only the necessary artifacts for each analytical step.
3Speed
If forensic analysis is performed on the endpoint device, then analysis speed is improved, but forensic artifact preservation is worsened due to potential contamination
Solution Approach 1:
The patent uses random access memory as an intermediary between the non-volatile storage medium and the analysis processes. Forensic artifacts are loaded into RAM for analysis, allowing fast processing on the endpoint device while the original artifacts remain preserved on storage. The RAM acts as a temporary workspace that prevents direct contamination of the original evidence.
Data Source
AI summary
The present disclosure is related to endpoint monitoring and forensic artifact collection. In some embodiments, forensic artifacts and endpoint monitoring data are collected on an endpoint using the same agent. In some embodiments, forensic artifacts are chunked prior to being transferred to a cloud server for analysis. In some embodiments, forensic artifacts are categorized and processed according to the category. In some embodiments, the agent operates in memory and does not write to disk. In some embodiments, the agent does not write to disk during the transfer of forensic artifacts to a cloud server. In some embodiments, a cloud server can enable natural language queries of monitoring data and/or forensic artifacts. In some embodiments, the cloud server provides summaries. In some embodiments, the cloud server identifies the most relevant data in monitoring data and/or forensic artifacts.


