Endpoint Forensic Analysis via Metadata Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current forensic analysis methods for endpoint devices connected to computer networks face challenges, including the need for costly dedicated hardware, computational burdens, and inefficiencies in monitoring encrypted file communications, which can lead to security risks and impracticality in detecting suspect behavior.

Innovation Solution

A method that collects file system call data and network communication metadata from endpoint devices, detects candidate data indicative of suspect activity, and analyzes it to determine if the data corresponds to such activity, without relying on dedicated hardware or file content, focusing on metadata independent of file content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware is installed to monitor network communication, then monitoring capability is improved, but cost and device complexity increase

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces dedicated hardware monitoring systems with software-based forensic analysis that collects and analyzes metadata from existing system calls. This substitutes mechanical/hardware monitoring with information-processing approaches, eliminating the need for physical hardware while maintaining monitoring capability through software agents that intercept and analyze system call metadata.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates copies of metadata from system calls rather than directly monitoring or intercepting actual file communications. By collecting metadata copies (file names, paths, timestamps, communication patterns) from system call interfaces, the system achieves monitoring capability without requiring dedicated hardware or interfering with actual data flows.

Inventive Principle:
Principle #26Copying

2Measurement precision

If file content is analyzed for forensic investigation, then detection accuracy is improved, but computational burden increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational burden
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts and analyzes only the metadata portion of file system operations, separating this from the actual file content. By taking out just the relevant metadata (system call parameters, file names, paths, timestamps, communication patterns) and analyzing only this extracted information, the system achieves sufficient detection accuracy while avoiding the prohibitive computational burden of analyzing complete file contents.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by analyzing only the necessary metadata components required for forensic detection rather than performing complete file content analysis. This partial analysis of metadata (file names, paths, timestamps, system call parameters) provides sufficient forensic insight while significantly reducing computational requirements compared to full content examination.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If encrypted file communication is monitored, then security detection is improved, but implementation complexity increases

Engineering Contradiction:
Improvesecurity detectionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses metadata as an intermediary layer between the forensic analysis system and encrypted file communications. Instead of attempting to decrypt or directly monitor encrypted data flows, the system collects metadata from system calls that occur during encrypted communication operations. This intermediary metadata approach enables security detection of encrypted communications without requiring decryption capabilities or complex implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If all data created by endpoint device is collected for forensic analysis, then completeness of evidence is improved, but data processing burden increases

Engineering Contradiction:
Improvecompleteness of evidenceVSAvoiddata processing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies local quality by selectively collecting and analyzing only specific types of metadata that are locally relevant to forensic detection needs. Rather than uniformly processing all data created by the endpoint device, the system focuses on metadata from file system calls and network communication operations, applying different collection strategies to different data categories based on their forensic relevance.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11032301B2Forensic analysis
Publication Date: 2021.06.08 FORTINET INC
  • US11032301B2 patent drawing
  • US11032301B2 patent drawing
  • US11032301B2 patent drawing

AI summary

A forensic analysis method performed in respect of an endpoint device connected to a computer network. The forensic analysis method comprises collecting file system call data from the endpoint device. The file system call data corresponds to a plurality of system calls relating to file system operations arising from activity performed on the endpoint device. The forensic analysis method also comprises collecting network communication metadata from the endpoint device. The network communication metadata is based on a plurality of system calls relating to communication operations over the computer network arising from activity performed on the endpoint device. The forensic analysis method further comprises detecting first candidate data comprised in one of the collected file system call data and the collected network communication metadata and identifying second candidate data in the other of the collected file system call data and the collected network communication metadata with the second candidate data corresponding to the first candidate data. The forensic analysis method yet further comprises analysing the second candidate data to determine whether or not the first and second candidate data correspond to suspect activity performed on the endpoint device.