Forensic Engine for Cyber Recovery Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection systems face challenges in effectively responding to and mitigating the impact of malware, as malware can infect both production systems and backups, leading to complex and time-consuming recovery processes, often involving law enforcement and insurance delays.

Innovation Solution

A forensic engine or kit is configured to evaluate and respond to malware by generating snapshots of infected systems, learning operational characteristics, and deploying these snapshots to controlled environments for analysis, allowing for proactive measures such as tricking the malware into sending responses back to its source or self-destructing if detected, while maintaining operational integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional backup systems are used to protect against data loss, then data redundancy is achieved, but malware can infect both production systems and backups making recovery complicated and time-consuming

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the backup environment into isolated working environments (sandboxes) that are separated from the production system. Each working environment is further divided into controlled experimentation zones where malware can be safely analyzed without affecting the main system. This segmentation prevents malware spread while enabling parallel recovery analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by proactively deploying suspicious files to multiple isolated working environments before they can infect the production system. Forensic analysis is conducted in advance on these isolated instances, allowing recovery strategies to be developed and tested before actual recovery is needed, significantly reducing recovery time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 3:

The system introduces an intermediary forensic engine that acts as a mediator between the infected backup and the production system. This forensic engine analyzes malware behavior in controlled environments and generates recovery insights without direct exposure between the infected backup and production systems, preventing further contamination while enabling recovery.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If forensic analysis is performed on malware-infected systems, then insights into malware behavior are generated, but the complexity of managing multiple working environments and scenarios increases

Engineering Contradiction:
Improvemalware insight generationVSAvoidforensic environment complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The forensic engine is designed as a universal system that can handle multiple types of malware, file formats, and analysis scenarios through a single integrated platform. It automatically adapts to different malware types and configures appropriate analysis scenarios without requiring separate specialized systems for each threat type, reducing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service through automated scenario selection and configuration. The forensic engine automatically analyzes suspicious files, determines the appropriate working environments and scenarios needed, configures isolation parameters, and executes analysis without manual intervention. This automation reduces the complexity burden on operators while maintaining comprehensive forensic capabilities.

Inventive Principle:
Principle #25Self-service

3Loss of information

If malware is allowed to operate in observed manner to learn operational characteristics, then malware behavior insights are obtained, but the risk of malware spreading or causing damage increases

Engineering Contradiction:
Improvemalware operational characteristicsVSAvoidmalware spread risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by creating distinct working environments with different isolation levels and observation capabilities tailored to specific analysis needs. Each environment has customized quality characteristics - some are highly isolated for safety, others allow more interaction for detailed behavioral analysis. This localized approach enables comprehensive malware observation while maintaining appropriate safety boundaries in each zone.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240111867A1Cyber recovery forensics kit - experimentation automation
Publication Date: 2024.04.04 DELL PROD LP
  • US20240111867A1 patent drawing
  • US20240111867A1 patent drawing
  • US20240111867A1 patent drawing

AI summary

Automated research experimentation on malware is disclosed. When malware is detected, an infected backup is generated. The infected backup is deployed to multiple working environments as recovered production systems, starting from the same state. Different scenarios are performed on the recovered production systems to learn the operational characteristics of the malware operating in the recovered production systems. The insights may be used to protect against the malware and/or other malware.