Forensic Copying for Cloud Disk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital forensics in cloud computing environments face challenges such as resource obstruction and unnecessary resource allocation during suspected breach investigations, as existing methods require direct access to disks for analysis, even if no breach has occurred.

Innovation Solution

The solution involves generating an inspectable disk from a resource's disk in the computing environment, mounting it on a forensic analyzer, and configuring the analyzer to perform forensic analysis without disrupting the original disk, allowing for targeted remediation actions only when a breach is confirmed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If forensic analysis is performed directly on the original disk, then analysis accuracy is improved, but resource obstruction and disruption to normal operation occur

Engineering Contradiction:
Improveforensic analysis accuracyVSAvoidnormal operation continuity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent creates a forensic copy (inspectable disk) of the original disk, allowing forensic analysis to be performed on the copy while the original disk continues to operate normally. This resolves the contradiction by enabling accurate forensic analysis without disrupting normal operations, as the analysis is performed on the copied data rather than the live disk.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent separates the forensic analysis function from the original disk operations by creating a distinct forensic copy. This segmentation allows the original disk to maintain its normal operations while the forensic copy handles analysis tasks, eliminating resource obstruction and ensuring operational continuity.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If forensic analysis resources are allocated proactively, then response time to potential breaches is improved, but unnecessary resource allocation occurs when no breach exists

Engineering Contradiction:
Improvebreach response timeVSAvoidresource allocation efficiency
Core Design Contradiction:
Loss of timeVSLoss of energy

Solution Approach 1:

The patent prepares forensic copies and analysis resources in advance but only activates them when breach suspicion arises. The system can quickly generate forensic copies and deploy analysis resources when needed, providing rapid response to actual breaches while avoiding continuous resource allocation during normal operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic resource allocation where forensic analysis resources are activated only when breach suspicion is detected and deactivated when not needed. This dynamic approach optimizes resource usage by matching resource allocation to actual security needs, reducing waste while maintaining rapid response capability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If disk access operations are devoted to forensic analysis, then detection capability is improved, but productivity of the original resource decreases

Engineering Contradiction:
Improvebreach detection capabilityVSAvoidoriginal resource productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a forensic copy of the disk that can be accessed and analyzed without affecting the original disk's productivity. The forensic copy captures the necessary data for breach detection while the original disk continues to serve its primary functions, thus maintaining both detection capability and resource productivity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The forensic copy acts as an intermediary between the original disk and the forensic analysis process. It allows detection operations to be performed on the copy while the original disk remains unaffected, thereby maintaining productivity while improving breach detection capability through dedicated forensic access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240303325A1System and method for providing remediation in cybersecurity incident response
Publication Date: 2024.09.12 WIZ INC
  • US20240303325A1 patent drawing
  • US20240303325A1 patent drawing
  • US20240303325A1 patent drawing

AI summary

A system and method for cybersecurity remediation based on a digital forensic finding is disclosed. In an embodiment, the method includes generating an inspectable disk from a disk of a resource deployed in a computing environment; mounting the inspectable disk at a mount point on a forensic analyzer; configuring the forensic analyzer to generate a forensic finding based on the inspectable disk; and initiating a remediation action based on the forensic finding.