Forensic Data Analysis for Security Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus solutions are ineffective in detecting security incidents in computerized environments, leading to undetected malicious activity and overwhelming security teams with false alerts, as they rely on signature-based detection methods that are not sufficient for real-time assessment of damages.

Innovation Solution

A system and method that continuously collect forensic data from network-connected user devices to determine normal behavior patterns, identify abnormal behaviors, and generate security incident notifications, providing real-time damage assessment and contextual data for accurate incident attribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based detection methods are used, then known viruses can be detected, but malicious activity may go undetected and false alerts overwhelm security teams

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary forensics investigations and behavior pattern analysis before security incidents occur. By continuously collecting forensic data and establishing baseline behavior patterns in advance, the system can proactively detect anomalies and prevent incidents rather than merely reacting to known signatures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical signature-matching systems with a behavioral analysis system that uses machine learning and pattern recognition. Instead of relying on predetermined virus signatures, the system analyzes actual device behavior patterns and detects deviations, substituting static detection mechanics with dynamic behavioral analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If traditional anti-virus applications are deployed, then security alerts are generated, but security teams are overwhelmed with thousands of alerts requiring days to respond

Engineering Contradiction:
Improveincident response speedVSAvoidresponse time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements automated self-service capabilities through machine learning models that autonomously analyze forensic data, identify security incidents, and generate prioritized alerts. The behavioral analysis system automatically distinguishes between genuine threats and false positives, enabling the system to serve itself in detecting and prioritizing incidents without overwhelming human security teams.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where security incident outcomes and analyst decisions are fed back into the machine learning models. This continuous feedback refines behavior patterns and improves detection accuracy over time, reducing false alerts and enabling faster response by learning from past incidents and security team decisions.

Inventive Principle:
Principle #23Feedback

3Loss of information

If basic virus signature searching is performed, then known viruses are identified, but real-time damage assessment is not provided

Engineering Contradiction:
Improvecontextual informationVSAvoiddata collection complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments forensic data collection into distinct categories (device information, application data, network traffic, file system data) and processes each segment separately through specialized analysis modules. This segmentation allows comprehensive data collection while maintaining manageable complexity through modular processing and focused analysis of specific data types.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The forensic data collection and analysis system is designed with multi-functionality to serve multiple purposes simultaneously: detecting security incidents, providing real-time damage assessment, generating contextual information for incident response, and establishing baseline behavior patterns. This universal system handles diverse data types and analysis tasks through a unified platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10652274B2Identifying and responding to security incidents based on preemptive forensics
Publication Date: 2020.05.12 PALO ALTO NETWORKS INC
  • US10652274B2 patent drawing
  • US10652274B2 patent drawing
  • US10652274B2 patent drawing

AI summary

A system is connected to a plurality of user devices coupled to an enterprise's network. The system continuously collects, stores, and analyzes forensic data related to the enterprise's network. Based on the analysis, the system is able to determine normal behavior of the network and portions thereof and thereby identify abnormal behaviors within the network. Upon identification of an abnormal behavior, the system determines whether the abnormal behavior relates to a security incident. Upon determining a security incident in any portion of the enterprise's network, the system extracts forensic data respective of the security incident and enables further assessment of the security incident as well as identification of the source of the security incident. The system provides real-time damage assessment respective of the security incident as well as the security incident's attributions.