Forensic Event Data Collection for Adversary Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions focus narrowly on detecting malware, leaving systems vulnerable to threats using compromised credentials and system tools without malware, as they fail to detect adversary activity at all stages of the intrusion cycle, including initial compromise, execution, and data exfiltration.

Innovation Solution

A system comprising a server and an endpoint agent that collects and analyzes forensic and event data, including process creation, network connection, and memory patterns, to detect compromises and adversary behaviors, even in the absence of malware, by correlating data across multiple endpoints and focusing on tactical, strategic, and behavioral indicators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing solutions focus narrowly on detecting malware, then malware detection capability is improved, but detection of adversary activity using compromised credentials and system tools deteriorates

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddetection of adversary activity
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The security system is designed to perform multiple detection functions beyond just malware detection. It monitors process creation, network connections, file system changes, and registry modifications to detect various types of adversary activities including those using compromised credentials and system tools, making the system versatile against different threat types

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If existing solutions detect only malware, then detection system complexity is reduced, but coverage of intrusion cycle stages deteriorates

Engineering Contradiction:
Improvedetection system complexityVSAvoidcoverage of intrusion cycle stages
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The security monitoring system is divided into multiple specialized modules: process creation monitoring, network connection monitoring, file system monitoring, and registry monitoring. Each module focuses on specific indicators of compromise, allowing comprehensive coverage of intrusion cycle stages while maintaining manageable complexity through modular design

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive forensic and event data is collected across multiple endpoints, then detection accuracy of adversary behaviors is improved, but data processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

A centralized server acts as an intermediary that receives, aggregates, and processes forensic and event data from multiple endpoint agents. The server performs correlation analysis across endpoints and implements detection logic, reducing the processing burden on individual endpoints while maintaining high detection accuracy through comprehensive multi-endpoint data analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10645124B2System and method for collection of forensic and event data
Publication Date: 2020.05.05 SECUREWORKS CORP
  • US10645124B2 patent drawing
  • US10645124B2 patent drawing
  • US10645124B2 patent drawing

AI summary

A system for collection and analysis of forensic and event data comprising a server and an endpoint agent operating on a remote system. The server is configured to receive event data including process creation data, persistent process data, thread injection data, network connection data, memory pattern data, or any combination thereof, and analyze the event data to detect compromises of a remote system. The endpoint agent is configured to acquire event data, and communicate the event data to the server.