Enterprise Threat Detection Forensic Workspace Snapshot Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current enterprise threat detection (ETD) systems lack the ability to generate snapshots of forensic investigations, making it cumbersome to share and document potential threats across different timeframes, and inefficient for collaborative analysis and mitigation efforts.

Innovation Solution

The implementation of an ETD forensic workspace that allows for the creation of snapshots within a specific timeframe, enabling the selection of data types, generation of graphical charts, and organization of snapshots into logical groups for comprehensive analysis and collaboration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If information sharing is accomplished through email or messaging tools, then information can be transmitted between colleagues, but the sharing process becomes cumbersome and inefficient with incomplete information

Engineering Contradiction:
Improveinformation sharing efficiencyVSAvoidinformation sharing convenience
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent creates snapshot objects that are persistent copies of forensic investigation data, charts, and analysis results. These snapshots capture the complete state of the investigation at a point in time and can be shared with colleagues through the workspace, eliminating the need for cumbersome email exchanges while ensuring complete and accurate information transfer.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a workspace as an intermediary platform between investigators and colleagues. This workspace serves as a central repository where snapshots of forensic investigations can be stored, organized, and shared, facilitating efficient collaboration without requiring direct email or messaging tool interactions for each information exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If forensic investigation data is documented for sharing, then collaboration is enabled, but the system complexity increases due to the need for persistent storage and retrieval mechanisms

Engineering Contradiction:
Improvecollaborative analysis capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the forensic investigation data into discrete snapshot objects that can be independently created, stored, and shared. Each snapshot encapsulates specific charts, data sets, and analysis results, allowing the system to manage complexity by breaking down the overall investigation into manageable, reusable units without requiring complex monolithic storage structures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by automatically capturing and preserving the state of forensic investigations at specific points in time through snapshot creation. This preliminary documentation enables future retrieval and sharing without requiring complex real-time synchronization or state management mechanisms, as the data is already preserved in its original state.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If snapshots are organized into logical groups, then analysis from different contextual angles is enabled, but the organizational structure becomes more complex

Engineering Contradiction:
Improvemulti-angle analysis capabilityVSAvoiddata organization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates snapshot pages that serve multiple functions: they can contain multiple snapshots, be organized into different groups, shared with colleagues, and accessed from various entry points in the system. This multi-functionality allows the same organizational structure to support diverse analysis needs without requiring separate complex systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10673879B2Snapshot of a forensic investigation for enterprise threat detection
Publication Date: 2020.06.02 SAP SE
  • US10673879B2 patent drawing
  • US10673879B2 patent drawing
  • US10673879B2 patent drawing

AI summary

An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.