Forensic Data Loss Projections Using Pre-Attack Snapshots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack accurate and effective means to assess the extent of data loss during cyber incidents, particularly when data is compromised or lost, complicating the valuation of diverse data sets with varying importance and sensitivity, which hinders processes such as insurance claim determination and regulatory compliance.

Innovation Solution

A system that utilizes data snapshots to quantify data loss by determining forensic projections based on changes in data volumes, incorporating parameters like sensitivity and criticality to calculate data loss metrics, enabling precise valuation and insurance claim assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data snapshots are used to quantify data loss, then measurement precision of data loss is improved, but device complexity increases

Engineering Contradiction:
Improvedata loss quantification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system takes preliminary snapshots of data volumes before cyberattacks occur. These snapshots serve as baseline records that enable accurate measurement of data loss after attacks, without requiring complex real-time monitoring during the attack itself. The preliminary action of capturing data state beforehand simplifies the overall measurement process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of data volumes through snapshots, which preserve the data state at specific points in time. These copies can be analyzed to determine data loss without manipulating the actual data, simplifying the measurement process while maintaining accuracy. The snapshot copies serve as measurable proxies for the actual data state.

Inventive Principle:
Principle #26Copying

2Loss of information

If forensic projections are developed using snapshots, then loss of information is reduced, but loss of time increases

Engineering Contradiction:
Improvedata loss assessment accuracyVSAvoidassessment time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

By capturing data snapshots in advance before attacks occur, the system prepares measurement baselines that can be quickly compared against post-attack states. This preliminary preparation enables rapid data loss assessment without requiring time-consuming analysis during the critical assessment period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The snapshot serves as an intermediary reference point between the pre-attack data state and post-attack state. By using this intermediary, the system can efficiently calculate data loss through comparison without directly analyzing the entire data volume, reducing both information loss and assessment time.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data valuation standardization is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvedata valuation process simplicityVSAvoidstandardization system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system changes the parameters used for data valuation by introducing snapshot-based measurement metrics. This transforms complex, subjective data valuation into objective measurements based on snapshot comparisons, simplifying the valuation process while maintaining the ability to handle diverse data types through standardized parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260003957A1Developing Forensic Projections For Data Volumes Using Snapshots
Publication Date: 2026.01.01 NETAPP INC
  • US20260003957A1 patent drawing
  • US20260003957A1 patent drawing
  • US20260003957A1 patent drawing

AI summary

The disclosure describes a system for developing a forensic projection for data lost in a cyberattack. After identifying a cyberattack causing a loss of data in the data volume, the system identifies a snapshot of the portion of the data volume affected by the cyberattack. The system estimates, based on the snapshot, an amount of lost data caused by the cyberattack. The system then determines based at least on the amount of lost data, a data loss metric.