Enterprise Threat Detection Forensic Workspace Snapshot Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current enterprise threat detection (ETD) systems lack the ability to generate snapshots of forensic investigations, making it cumbersome to share and document potential threats across different timeframes, and inefficient for collaborative analysis and mitigation efforts.
Innovation Solution
The implementation of an ETD forensic workspace that allows for the creation of snapshots within a specific timeframe, enabling the selection of data types, generation of graphical charts, and organization of snapshots into logical groups for comprehensive analysis and collaboration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If information sharing is accomplished through email or messaging tools, then information can be transmitted between colleagues, but the sharing process becomes cumbersome and inefficient with incomplete information
Solution Approach 1:
The patent creates snapshot objects that are persistent copies of forensic investigation data, charts, and analysis results. These snapshots capture the complete state of the investigation at a point in time and can be shared with colleagues through the workspace, eliminating the need for cumbersome email exchanges while ensuring complete and accurate information transfer.
Solution Approach 2:
The patent introduces a workspace as an intermediary platform between investigators and colleagues. This workspace serves as a central repository where snapshots of forensic investigations can be stored, organized, and shared, facilitating efficient collaboration without requiring direct email or messaging tool interactions for each information exchange.
2Adaptability or versatility
If forensic investigation data is documented for sharing, then collaboration is enabled, but the system complexity increases due to the need for persistent storage and retrieval mechanisms
Solution Approach 1:
The patent segments the forensic investigation data into discrete snapshot objects that can be independently created, stored, and shared. Each snapshot encapsulates specific charts, data sets, and analysis results, allowing the system to manage complexity by breaking down the overall investigation into manageable, reusable units without requiring complex monolithic storage structures.
Solution Approach 2:
The patent performs preliminary actions by automatically capturing and preserving the state of forensic investigations at specific points in time through snapshot creation. This preliminary documentation enables future retrieval and sharing without requiring complex real-time synchronization or state management mechanisms, as the data is already preserved in its original state.
3Adaptability or versatility
If snapshots are organized into logical groups, then analysis from different contextual angles is enabled, but the organizational structure becomes more complex
Solution Approach 1:
The patent creates snapshot pages that serve multiple functions: they can contain multiple snapshots, be organized into different groups, shared with colleagues, and accessed from various entry points in the system. This multi-functionality allows the same organizational structure to support diverse analysis needs without requiring separate complex systems for each function.
Data Source
AI summary
An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.


