Endpoint Data Retention via Local Tamper-Resistant Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches to retaining data on potential software-based attacks on endpoint computers rely on transmitting data to remote servers, which can be insecure and inefficient, and may require transmitting sensitive information over networks, posing reliability and security risks.
Innovation Solution
Implementing a local data store with tamper-resistant features on the endpoint computer to harvest and store data related to events, using a series of encrypted data containers with cryptographic fingerprints to prevent alteration and deletion, and employing machine learning models for data analysis and query response optimization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is transmitted to remote servers for retention and analysis, then centralized data management is achieved, but network security risks and data transmission efficiency are worsened
Solution Approach 1:
Instead of transmitting data to remote servers for storage and analysis, the patent inverts the approach by implementing local data stores on endpoint computers that autonomously harvest, store, and analyze data. The endpoint systems become the primary data management units, eliminating the need for continuous network transmission while maintaining effective data retention and analysis capabilities locally.
Solution Approach 2:
The patent introduces encrypted data containers with cryptographic fingerprints as intermediaries between local data generation and remote server communication. These containers provide a secure buffer that allows data to be stored and processed locally without requiring continuous network connectivity, thus eliminating network security risks while maintaining data integrity through cryptographic protection.
2Reliability
If data collection criteria are broadened to capture more forensic information, then threat detection capability is improved, but data storage requirements and processing complexity increase
Solution Approach 1:
The patent implements dynamic data collection criteria that adapt based on threat levels. The system monitors security events and adjusts the breadth of data collection accordingly - using narrow criteria during normal operations and expanding to broad criteria when threats are detected. This dynamic adjustment maintains high threat detection capability while avoiding the constant overhead of collecting and processing all possible data types.
Solution Approach 2:
The patent applies different data collection criteria to different security contexts and event types. Rather than using a single uniform broad criteria set, the system tailors data collection to the specific security situation, collecting comprehensive data for critical threats while using minimal collection for routine monitoring, thus reducing overall processing complexity while maintaining detection effectiveness.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An endpoint computer system can harvest data relating to a plurality of events occurring within an operating environment of the endpoint computer system and can add the harvested data to a local data store maintained on the endpoint computer system. A query response can be generated, for example by identifying and retrieving responsive data from the local data store. The responsive data are related to an artifact on the endpoint computer system and/or to an event of the plurality of events. In some examples, the local data store can be an audit log and/or can include one or more tamper resistant features. Systems, methods, and computer program products are described.