Automated Forensic Data Collection and Analysis System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cybersecurity threat identification processes are time-consuming, costly, and inefficient due to the ad hoc nature of data collection and analysis, often resulting in inconsistent and incomplete results, especially in cases like investigating departing employees or data breaches.

Innovation Solution

A computer-implemented system and method for automatic collection, analysis, and reporting of cybersecurity threats, using a graphical user interface to configure and generate an executable that collects forensic data, encrypts it, and analyzes it with a forensic toolset, producing customizable reports for clients within a short timeframe.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional manual forensic analysis process is used, then comprehensive analysis can be performed, but the process takes days or weeks and is costly

Engineering Contradiction:
Improveanalysis completenessVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service through automated forensic data collection, analysis, and reporting. The executable automatically collects forensic data from client systems, the system automatically analyzes the encrypted data using forensic tools, and reports are automatically generated and delivered to clients, eliminating the need for manual consultant intervention at each step while maintaining comprehensive analysis quality

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring forensic collection parameters through the graphical user interface, pre-encrypting data before transmission, and pre-processing data using forensic tools before final report generation. This preliminary automation prepares the analysis pipeline in advance, reducing overall processing time from days to hours

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional manual process is used, then forensic data can be collected, but results are inconsistent and not comprehensive due to ad hoc nature

Engineering Contradiction:
Improveprocess simplicityVSAvoidresult consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes parameters by transforming manual, variable forensic processes into automated, standardized operations. The graphical user interface allows configuration of specific forensic parameters, and the automated execution ensures consistent application of collection, encryption, and analysis parameters across all cases, eliminating ad hoc variations that led to inconsistent results

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system achieves universality through a single executable that performs multiple functions: collecting forensic data from various sources, encrypting data securely, transmitting to the system, and enabling automated analysis. This multi-functional automated system replaces multiple manual steps, ensuring consistent and comprehensive results across different forensic scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If consultant travels to client site for forensic analysis, then direct access to systems is possible, but the process becomes costly and burdensome to manage

Engineering Contradiction:
Improveforensic data qualityVSAvoidprocess complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces an intermediary encrypted data package as the medium between client systems and the forensic analysis system. The executable collects forensic data locally at the client site, encrypts it, and transmits the encrypted package to the system for automated analysis. This intermediary approach maintains forensic data quality through local collection while eliminating the complexity of consultant travel and manual data handling

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11381592B2System and method for identifying cybersecurity threats
Publication Date: 2022.07.05 KPMG LLP
  • US11381592B2 patent drawing
  • US11381592B2 patent drawing
  • US11381592B2 patent drawing

AI summary

The invention relates to a computer-implemented system and method for automatic collection, analysis and reporting of data relating to a cybersecurity threat. The method may comprise the steps of: presenting an interface through which an executable can be configured and automatically generated; transmitting the executable to a client to enable the client to execute the executable on client systems to automatically collect forensic data; receiving from the client an encrypted data package that includes the forensic data; using a forensic toolset to automatically analyze the forensic data; presenting an option to select one or more of at least two types of output reports designed for different types of readers; inputting the analysis files into an automatic report generator to automatically generate the types of output reports selected by the client; and sending the output reports selected by the client to the client.