Endpoint Vault for Secure Artifact Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current approaches for retaining data on potential software-based attacks on endpoint computers require transmitting large amounts of data over networks to remote servers, which is inefficient and may compromise sensitive information.
Innovation Solution
Implementing a local vault on each endpoint computer system to store and manage data related to events, allowing for local querying and reducing the need for extensive network data transfer, with features like encryption and machine learning for threat detection and data relevance analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is transmitted over network to remote servers for storage and analysis, then centralized security monitoring is achieved, but network resource consumption increases and data transfer time is extended
Solution Approach 1:
The system segments the security monitoring architecture by deploying local vaults on individual endpoint devices rather than relying solely on centralized server storage. Each endpoint maintains its own artifact vault, enabling local security analysis while reducing network dependency. This segmentation allows the system to achieve both centralized oversight and distributed efficiency.
2Measurement precision
If large amounts of event data are transmitted to remote servers, then comprehensive threat analysis is enabled, but data transfer time and network bandwidth consumption increase
Solution Approach 1:
The system extracts and stores critical security artifacts locally in endpoint vaults rather than transmitting all raw event data to remote servers. By taking out only the essential artifacts needed for threat detection and storing them locally, the system maintains comprehensive threat analysis capability while dramatically reducing network data transfer requirements and time.
Solution Approach 2:
The system performs preliminary processing and filtering of event data at the endpoint before transmission, storing only relevant artifacts in local vaults. This preliminary action at the source reduces the volume of data requiring network transmission while ensuring that all necessary information for threat detection is preserved and readily accessible.
3Loss of information
If all event data is retained and transmitted, then complete forensic analysis capability is maintained, but data storage requirements and network load increase
Solution Approach 1:
The system applies local quality by maintaining different data retention and storage characteristics at different locations in the architecture. Local vaults on endpoints store artifacts with high retention and fast access characteristics, while remote servers store aggregated and processed data. This local quality differentiation ensures forensic completeness is maintained where needed while reducing overall data volume through intelligent distribution.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Each of a plurality of endpoint computer systems monitors data relating to a plurality of events occurring within an operating environment of the corresponding endpoint computer system. The monitoring can include receiving and/or inferring the data using one or more sensors executing on the endpoint computer systems Thereafter, for each endpoint computer system, artifacts used in connection with the events are stored in a vault maintained on such endpoint computer system. A query is later received by at least a subset of the plurality of endpoint computer systems from a server. Such endpoint computer systems, in response, identify and retrieve artifacts within the corresponding vaults response to the query. Results responsive to the query including or characterizing the identified artifacts is then provided by the endpoint computer systems receiving the query to the server.