Forensic Event Record Resequencing via Timestamp Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Timestamp errors in log files can lead to inaccurate ordering of events, making it difficult for forensic tools to trace the precise sequence of events and propagate malicious activity across electronic systems, especially when dealing with multiple devices with drifting clocks.

Innovation Solution

A technique that involves receiving event records from forensic agents across an electronic system, applying timing information such as vector clocks or timestamps from a common timestamp server to resequence the records accurately, ensuring correct ordering and synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If timestamps are obtained from local device clocks, then each device can independently record events, but clock drift between devices causes timing errors and incorrect event ordering

Engineering Contradiction:
Improveindependent event recording capabilityVSAvoidevent timing accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent introduces a timestamp server as an intermediary that provides centralized time synchronization to multiple devices. The server issues authoritative timestamps that all devices use to stamp their event records, eliminating clock drift issues while preserving independent recording capabilities. This mediator resolves the contradiction by providing both centralized timing coordination and distributed event capture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates equipotentiality in timing across all devices by having them all reference the same timestamp server. Instead of each device operating at its own potentially drifting clock level, all devices are elevated to the same timing reference level, ensuring consistent event ordering across the distributed system.

Inventive Principle:
Principle #12Equipotentiality

2Productivity

If event records are written to log files in real-time, then events are captured as they occur, but variable delays cause records to be posted out of sequence

Engineering Contradiction:
Improveevent capture speedVSAvoidevent sequence accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by attaching the authoritative timestamp to the event record at the moment the event occurs, before any processing or queuing delays can affect the timing. This preliminary timing assignment ensures that even though records may be written at different speeds, their original temporal relationships are preserved in the timestamp data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback by comparing the timestamp of incoming event records with previously recorded timestamps to detect and correct out-of-sequence postings. The system monitors the timing relationships and can identify when variable delays have caused incorrect ordering, allowing for post-processing correction of the event sequence.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If forensic analysis is performed on log files with timing errors, then analysis can be conducted, but the ability to trace event sequences and cause-effect relationships is compromised

Engineering Contradiction:
Improveforensic analysis capabilityVSAvoidevent sequence information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The timestamp server acts as an intermediary that preserves the true temporal relationships between events. By using these authoritative timestamps as a mediator in the forensic analysis process, analysts can reconstruct accurate event sequences even when the original log files contain timing errors, preventing loss of critical sequence information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8825848B1Ordering of event records in an electronic system for forensic analysis
Publication Date: 2014.09.02 EMC IP HLDG CO LLC
  • US8825848B1 patent drawing
  • US8825848B1 patent drawing
  • US8825848B1 patent drawing

AI summary

An improved technique for logging events in an electronic system for forensic analysis includes receiving event records by a recording unit from different forensic agents of the electronic system and applying timing information included within the event records to resequence the event records in the recording unit in a more accurate order. In some examples, the timing information includes a vector clock established among the agents of the electronic system for storing sequences of events. The vector clock provides sequence information about particular events occurring among the forensic agents, which is applied to correct the order of reported event records. In other examples, the timing information includes timestamps published to the agents from a common timestamp server. In yet other examples, the timing information includes timestamps of the devices on which the agents are running, or any combination of the foregoing examples of timing information.