Endpoint Data Retention via Local Tamper-Resistant Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to retaining data on potential software-based attacks on endpoint computers rely on transmitting data to remote servers, which can be insecure and inefficient, and may require transmitting sensitive information over networks, posing reliability and security risks.

Innovation Solution

Implementing a local data store with tamper-resistant features on the endpoint computer to harvest and store data related to events, using a series of encrypted data containers with cryptographic fingerprints to prevent alteration and deletion, and employing machine learning models for data analysis and query response optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted to remote servers for retention and analysis, then centralized data management is achieved, but network security risks and data transmission efficiency are worsened

Engineering Contradiction:
Improvecentralized data managementVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of transmitting data to remote servers for storage and analysis, the patent inverts the approach by implementing local data stores on endpoint computers that autonomously harvest, store, and analyze data. The endpoint systems become the primary data management units, eliminating the need for continuous network transmission while maintaining effective data retention and analysis capabilities locally.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces encrypted data containers with cryptographic fingerprints as intermediaries between local data generation and remote server communication. These containers provide a secure buffer that allows data to be stored and processed locally without requiring continuous network connectivity, thus eliminating network security risks while maintaining data integrity through cryptographic protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data collection criteria are broadened to capture more forensic information, then threat detection capability is improved, but data storage requirements and processing complexity increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic data collection criteria that adapt based on threat levels. The system monitors security events and adjusts the breadth of data collection accordingly - using narrow criteria during normal operations and expanding to broad criteria when threats are detected. This dynamic adjustment maintains high threat detection capability while avoiding the constant overhead of collecting and processing all possible data types.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different data collection criteria to different security contexts and event types. Rather than using a single uniform broad criteria set, the system tailors data collection to the specific security situation, collecting comprehensive data for critical threats while using minimal collection for routine monitoring, thus reducing overall processing complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3420488B1Retention and accessibility of data characterizing events on an endpoint computer
Publication Date: 2022.09.21 CYLANCE INC
  • EP3420488B1 patent drawingFigure 1
  • EP3420488B1 patent drawingFigure 2
  • EP3420488B1 patent drawingFigure 3

AI summary

An endpoint computer system can harvest data relating to a plurality of events occurring within an operating environment of the endpoint computer system and can add the harvested data to a local data store maintained on the endpoint computer system. A query response can be generated, for example by identifying and retrieving responsive data from the local data store. The responsive data are related to an artifact on the endpoint computer system and/or to an event of the plurality of events. In some examples, the local data store can be an audit log and/or can include one or more tamper resistant features. Systems, methods, and computer program products are described.