Unified Forensic Analysis via Network Storage Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network forensic tools and Continuous Data Protection (CDP) solutions provide limited views into computing system operations, as they operate in separate domains and struggle to capture transient activities of virtual machines, leading to difficulties in detecting malicious events, especially in virtual environments where traces are quickly overwritten.

Innovation Solution

An improved technique that captures and associates multiple streams of information, including network and storage activities, using a common timing reference to create a comprehensive history of a computing machine's operations, enabling coordinated examination and tracing of suspect or malicious occurrences across domains, even in transient virtual machine environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network forensic tools are used to monitor network activity, then network security analysis is improved, but the ability to detect malicious events that propagate through machines without suspect network activity is worsened

Engineering Contradiction:
Improvenetwork activity detectionVSAvoidmalicious event detection
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines network forensic tools with Continuous Data Protection (CDP) solutions to create a unified forensic analysis system. This merging allows the system to correlate network activity with disk and memory activities, enabling detection of malicious events that may not manifest as obvious network traffic but leave traces in storage and memory domains.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If CDP solutions are used to track disk activity, then disk change tracking is improved, but the ability to detect threats that do not involve disk activity is worsened

Engineering Contradiction:
Improvedisk activity trackingVSAvoidthreat detection
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent merges CDP disk tracking capabilities with network forensic monitoring and memory forensics. This combination allows the system to detect threats that may not involve disk activity by examining network traffic patterns and memory states, while still maintaining the detailed disk change tracking capability of CDP for threats that do affect storage.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If forensic analysis is performed on virtual machines after they are destroyed, then the ability to analyze physical machines is maintained, but the ability to retrieve evidence from transient virtual environments is worsened

Engineering Contradiction:
Improveforensic analysis capabilityVSAvoidvirtual machine evidence
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by continuously capturing and archiving network, disk, and memory activities while virtual machines are running. This continuous forensic data collection occurs before virtual machines are destroyed or their storage overwritten, ensuring evidence is preserved in a secure archive that can be analyzed later even after the virtual machine instances are gone.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If separate network and storage forensic domains are used, then domain-specific analysis is improved, but the ability to trace suspect activity across domains is worsened

Engineering Contradiction:
Improvedomain-specific analysisVSAvoidcross-domain activity tracing
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges separate network and storage forensic domains into an integrated analysis platform that uses common timing references to correlate events across domains. This unified system maintains the analytical depth of domain-specific tools while adding the capability to trace suspect activity as it moves across network, disk, and memory domains by matching timestamped events between domains.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8683592B1Associating network and storage activities for forensic analysis
Publication Date: 2014.03.25 EMC IP HLDG CO LLC
  • US8683592B1 patent drawing
  • US8683592B1 patent drawing
  • US8683592B1 patent drawing

AI summary

An improved technique for performing forensic investigations in an electronic system includes capturing and associating multiple streams of information. The streams include a network stream and a storage stream. The network stream includes a record of network activities. The storage stream includes a record of storage activities. In some examples, the storage stream includes both disk activities and memory activities, including both reads and writes. Records of the captured streams are stored in a data storage array and are associated by applying a common timing reference to the records. A comprehensive history is thus obtained, with both network and storage activities coordinated in time, to enable examination and tracing of suspect or malicious occurrences across network and storage domains. The improved technique can be used in both physical and virtual computing environments and affords particular advantages in virtual and cloud environments where forensic analysis has proven to be difficult.