Forensic Data Collection in Cloud UC Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Collecting and analyzing forensic evidence in cloud-based Unified Communications as a Service (UCaaS) systems is challenging due to the complexity of cloud environments and limited user control, leading to increased time and effort in investigations.

Innovation Solution

A structured method for systematic collection and analysis of forensic data in UCaaS systems, integrating evidence collection mechanisms with the cloud environment, generating models of normal behavior, monitoring for unauthorized actions, and using intrusion detection systems to transmit alarms and collect data, which is then formatted for use by forensic software tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If forensic data collection is performed in cloud-based UCaaS systems using traditional methods, then investigators can collect evidence, but the process requires excessive time and manual effort due to cloud environment complexity and limited user control

Engineering Contradiction:
Improveforensic analysis timeVSAvoidcloud environment complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by deploying automated evidence collection mechanisms and generating models of normal behavior in advance within the cloud environment. These mechanisms are pre-configured to automatically monitor and collect forensic data when incidents occur, eliminating the need for manual data gathering during investigations. The baseline models are generated beforehand to enable rapid comparison and detection of unauthorized actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service through automated intrusion detection that monitors the unified communications system continuously. When unauthorized actions are detected, the system automatically transmits alarms and triggers evidence collection without requiring investigator intervention. The forensic controller autonomously builds footprint data structures and formats evidence for analysis tools, making the system self-sufficient in the forensic investigation process.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If traditional forensic tools are used in cloud environments, then evidence can be collected, but user control is limited and requires negotiation with cloud service providers

Engineering Contradiction:
Improveevidence collection easeVSAvoidcloud model adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary forensic controller that bridges the gap between investigators and cloud infrastructure. This controller manages the evidence collection process, coordinates with cloud service providers, and handles the complexity of cloud environment access. The intrusion detection system acts as another intermediary layer that monitors the unified communications system and automatically triggers evidence collection when incidents are detected.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the forensic investigation process into distinct modular components: evidence collection mechanisms integrated with cloud infrastructure, baseline model generation modules, intrusion detection systems, and forensic analysis tools. Each component operates independently but coordinates through standardized interfaces, allowing the system to adapt to different cloud service models (IaaS, PaaS, SaaS) without requiring complete redesign.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive forensic monitoring is implemented in UCaaS systems, then better security coverage is achieved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidforensic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing evidence collection mechanisms that can operate across multiple cloud service models (IaaS, PaaS, SaaS) and unified communications services (voice, video, messaging). The forensic controller and intrusion detection system serve multiple functions: monitoring system activities, detecting unauthorized actions, collecting evidence, building footprint data structures, and formatting evidence for various analysis tools. This multi-functionality reduces the need for separate specialized systems for each cloud model or service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11080392B2Method for systematic collection and analysis of forensic data in a unified communications system deployed in a cloud environment
Publication Date: 2021.08.03 THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY
  • US11080392B2 patent drawing
  • US11080392B2 patent drawing
  • US11080392B2 patent drawing

AI summary

A method for systematic collection and analysis of forensic data in a unified communications system deployed in a cloud environment. Three primary forensic components, namely, evidence collectors, a forensic controller and self-forensic investigators, are utilized in the method to interface with the components of the cloud environment and of the unified communications network. The method invokes a cloud evidence collection process which collects footprint data structures continuously at runtime to enable effective real-time collection of cloud forensic evidence and a cloud evidence analyzing process which generates evidence data that can be consumed by standard forensics tools.