Endpoint Forensic Data Collection via Segmented Forwarders
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Efficiently collecting and correlating forensic data from distributed endpoint devices in networked computer systems to address complex security threats remains challenging due to the variety of endpoint types and user activities, as well as the need to monitor and remediate multi-layered security threats across disparate components.
Innovation Solution
A data intake and query system, similar to the SPLUNK ENTERPRISE system, is employed to collect and index forensic data from endpoint devices, allowing for correlation with non-forensic data from other sources, using forwarders to send data to indexers for analysis and storage, and enabling search queries across various data sources to identify security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If forensic data is collected from distributed endpoint devices, then security threat detection capability is improved, but system complexity increases due to multiple endpoint types and user activities
Solution Approach 1:
The system segments the complex task of monitoring diverse endpoint devices by creating separate data intake components (forwarders) for different device types and separate indexing components (indexers) for different data types. Each forwarder handles specific endpoint types while each indexer manages specific data categories, dividing the overall complexity into manageable independent units that can be deployed selectively across the distributed environment.
Solution Approach 2:
The patent introduces a centralized data intake and query system acting as an intermediary between distributed endpoint devices and security analysts. This intermediary layer (comprising forwarders and indexers) abstracts the complexity of multiple endpoint types and data formats, providing a unified interface for collecting, indexing, and querying forensic data from diverse sources without requiring analysts to directly manage the underlying complexity.
2Reliability
If multi-layered security threats are monitored across disparate components, then threat detection comprehensiveness is improved, but data collection efficiency deteriorates
Solution Approach 1:
The data intake and query system implements universality through forwarders that can collect data from multiple endpoint device types and indexer components that can process various data types (forensic, performance, configuration). This multi-functional design enables comprehensive monitoring of multi-layered threats across disparate components while maintaining collection efficiency through standardized universal interfaces rather than custom solutions for each device type.
Solution Approach 2:
The system merges forensic data collection with existing performance monitoring infrastructure by combining forwarders and indexers into a unified data intake and query platform. This consolidation allows the system to collect and correlate forensic data with performance data from the same distributed components, improving data collection efficiency through shared resources while maintaining comprehensive threat detection across multiple layers.
3Reliability
If forensic data is collected and correlated with non-forensic data, then security analysis capability is improved, but data processing complexity increases
Solution Approach 1:
The system segments data processing by separating forensic data collection (handled by forwarders) from non-forensic data collection (handled by other data intake components), then merging them at the indexing stage. This segmentation allows specialized processing of each data type while maintaining the ability to correlate them through common identifiers, reducing overall processing complexity through modular design.
Solution Approach 2:
The patent employs data copying and indexing mechanisms that create standardized representations of data from various sources. By copying data into a unified indexed format with consistent fields and structures, the system simplifies the complexity of processing diverse data types together, enabling correlation between forensic and non-forensic data through standardized keys while maintaining the original data integrity.
Data Source
AI summary
Techniques and mechanisms are disclosed enabling efficient collection of forensic data from client devices, also referred to herein as endpoint devices, of a networked computer system. Embodiments described herein further enable correlating forensic data with other types of non-forensic data from other data sources. A network security application described herein further enables generating various dashboards, visualizations, and other interfaces for managing forensic data collection, and displaying information related to collected forensic data and information related to identified correlations between items of forensic data and other items of non-forensic data.


