Endpoint Forensic Data Collection via Segmented Forwarders

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Efficiently collecting and correlating forensic data from distributed endpoint devices in networked computer systems to address complex security threats remains challenging due to the variety of endpoint types and user activities, as well as the need to monitor and remediate multi-layered security threats across disparate components.

Innovation Solution

A data intake and query system, similar to the SPLUNK ENTERPRISE system, is employed to collect and index forensic data from endpoint devices, allowing for correlation with non-forensic data from other sources, using forwarders to send data to indexers for analysis and storage, and enabling search queries across various data sources to identify security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If forensic data is collected from distributed endpoint devices, then security threat detection capability is improved, but system complexity increases due to multiple endpoint types and user activities

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex task of monitoring diverse endpoint devices by creating separate data intake components (forwarders) for different device types and separate indexing components (indexers) for different data types. Each forwarder handles specific endpoint types while each indexer manages specific data categories, dividing the overall complexity into manageable independent units that can be deployed selectively across the distributed environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized data intake and query system acting as an intermediary between distributed endpoint devices and security analysts. This intermediary layer (comprising forwarders and indexers) abstracts the complexity of multiple endpoint types and data formats, providing a unified interface for collecting, indexing, and querying forensic data from diverse sources without requiring analysts to directly manage the underlying complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-layered security threats are monitored across disparate components, then threat detection comprehensiveness is improved, but data collection efficiency deteriorates

Engineering Contradiction:
Improvethreat detection comprehensivenessVSAvoiddata collection efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The data intake and query system implements universality through forwarders that can collect data from multiple endpoint device types and indexer components that can process various data types (forensic, performance, configuration). This multi-functional design enables comprehensive monitoring of multi-layered threats across disparate components while maintaining collection efficiency through standardized universal interfaces rather than custom solutions for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges forensic data collection with existing performance monitoring infrastructure by combining forwarders and indexers into a unified data intake and query platform. This consolidation allows the system to collect and correlate forensic data with performance data from the same distributed components, improving data collection efficiency through shared resources while maintaining comprehensive threat detection across multiple layers.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If forensic data is collected and correlated with non-forensic data, then security analysis capability is improved, but data processing complexity increases

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments data processing by separating forensic data collection (handled by forwarders) from non-forensic data collection (handled by other data intake components), then merging them at the indexing stage. This segmentation allows specialized processing of each data type while maintaining the ability to correlate them through common identifiers, reducing overall processing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs data copying and indexing mechanisms that create standardized representations of data from various sources. By copying data into a unified indexed format with consistent fields and structures, the system simplifies the complexity of processing diverse data types together, enabling correlation between forensic and non-forensic data through standardized keys while maintaining the original data integrity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11750663B2Threat identification-based collection of forensic data from endpoint devices
Publication Date: 2023.09.05 CISCO TECHNOLOGY INC
  • US11750663B2 patent drawing
  • US11750663B2 patent drawing
  • US11750663B2 patent drawing

AI summary

Techniques and mechanisms are disclosed enabling efficient collection of forensic data from client devices, also referred to herein as endpoint devices, of a networked computer system. Embodiments described herein further enable correlating forensic data with other types of non-forensic data from other data sources. A network security application described herein further enables generating various dashboards, visualizations, and other interfaces for managing forensic data collection, and displaying information related to collected forensic data and information related to identified correlations between items of forensic data and other items of non-forensic data.