Forensic Event Data Collection for Adversary Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions focus narrowly on detecting malware, leaving systems vulnerable to threats using compromised credentials and system tools without malware, as they fail to detect adversary activity at all stages of the intrusion cycle, including initial compromise, execution, and data exfiltration.
Innovation Solution
A system comprising a server and an endpoint agent that collects and analyzes forensic and event data, including process creation, network connection, and memory patterns, to detect compromises and adversary behaviors, even in the absence of malware, by correlating data across multiple endpoints and focusing on tactical, strategic, and behavioral indicators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing solutions focus narrowly on detecting malware, then malware detection capability is improved, but detection of adversary activity using compromised credentials and system tools deteriorates
Solution Approach 1:
The security system is designed to perform multiple detection functions beyond just malware detection. It monitors process creation, network connections, file system changes, and registry modifications to detect various types of adversary activities including those using compromised credentials and system tools, making the system versatile against different threat types
2Device complexity
If existing solutions detect only malware, then detection system complexity is reduced, but coverage of intrusion cycle stages deteriorates
Solution Approach 1:
The security monitoring system is divided into multiple specialized modules: process creation monitoring, network connection monitoring, file system monitoring, and registry monitoring. Each module focuses on specific indicators of compromise, allowing comprehensive coverage of intrusion cycle stages while maintaining manageable complexity through modular design
3Measurement precision
If comprehensive forensic and event data is collected across multiple endpoints, then detection accuracy of adversary behaviors is improved, but data processing complexity increases
Solution Approach 1:
A centralized server acts as an intermediary that receives, aggregates, and processes forensic and event data from multiple endpoint agents. The server performs correlation analysis across endpoints and implements detection logic, reducing the processing burden on individual endpoints while maintaining high detection accuracy through comprehensive multi-endpoint data analysis
Data Source
AI summary
A system for collection and analysis of forensic and event data comprising a server and an endpoint agent operating on a remote system. The server is configured to receive event data including process creation data, persistent process data, thread injection data, network connection data, memory pattern data, or any combination thereof, and analyze the event data to detect compromises of a remote system. The endpoint agent is configured to acquire event data, and communicate the event data to the server.


