Endpoint Vault for Secure Artifact Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for retaining data on potential software-based attacks on endpoint computers require transmitting large amounts of data over networks to remote servers, which is inefficient and may compromise sensitive information.

Innovation Solution

Implementing a local vault on each endpoint computer system to store and manage data related to events, allowing for local querying and reducing the need for extensive network data transfer, with features like encryption and machine learning for threat detection and data relevance analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted over network to remote servers for storage and analysis, then centralized security monitoring is achieved, but network resource consumption increases and data transfer time is extended

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system segments the security monitoring architecture by deploying local vaults on individual endpoint devices rather than relying solely on centralized server storage. Each endpoint maintains its own artifact vault, enabling local security analysis while reducing network dependency. This segmentation allows the system to achieve both centralized oversight and distributed efficiency.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If large amounts of event data are transmitted to remote servers, then comprehensive threat analysis is enabled, but data transfer time and network bandwidth consumption increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata transfer time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts and stores critical security artifacts locally in endpoint vaults rather than transmitting all raw event data to remote servers. By taking out only the essential artifacts needed for threat detection and storing them locally, the system maintains comprehensive threat analysis capability while dramatically reducing network data transfer requirements and time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary processing and filtering of event data at the endpoint before transmission, storing only relevant artifacts in local vaults. This preliminary action at the source reduces the volume of data requiring network transmission while ensuring that all necessary information for threat detection is preserved and readily accessible.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If all event data is retained and transmitted, then complete forensic analysis capability is maintained, but data storage requirements and network load increase

Engineering Contradiction:
Improveforensic data completenessVSAvoiddata volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system applies local quality by maintaining different data retention and storage characteristics at different locations in the architecture. Local vaults on endpoints store artifacts with high retention and fast access characteristics, while remote servers store aggregated and processed data. This local quality differentiation ensures forensic completeness is maintained where needed while reducing overall data volume through intelligent distribution.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3616114B1Endpoint detection and response system with endpoint-based artifact storage
Publication Date: 2024.01.24 CYLANCE INC
  • EP3616114B1 patent drawingFigure 1
  • EP3616114B1 patent drawingFigure 2
  • EP3616114B1 patent drawingFigure 3

AI summary

Each of a plurality of endpoint computer systems monitors data relating to a plurality of events occurring within an operating environment of the corresponding endpoint computer system. The monitoring can include receiving and/or inferring the data using one or more sensors executing on the endpoint computer systems Thereafter, for each endpoint computer system, artifacts used in connection with the events are stored in a vault maintained on such endpoint computer system. A query is later received by at least a subset of the plurality of endpoint computer systems from a server. Such endpoint computer systems, in response, identify and retrieve artifacts within the corresponding vaults response to the query. Results responsive to the query including or characterizing the identified artifacts is then provided by the endpoint computer systems receiving the query to the server.