Forensic Snapshot Analysis for Long-Dwell APT Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional monitoring-based cybersecurity measures are inadequate for detecting advanced persistent threats (APTs) and insider threats that maintain undetected presence over extended periods, as they focus on security events rather than long-term processes.
Innovation Solution
A differential analysis method that compares forensic snapshots of assets at different points in time to detect APTs by determining what is added, changed, or removed, using a distance metric to assess the security level and presence of threats based on asset states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional monitoring-based cybersecurity measures are used, then security events can be detected, but advanced persistent threats maintaining undetected presence over extended periods cannot be detected
Solution Approach 1:
The system performs preliminary actions by capturing forensic snapshots of assets at multiple points in time before threats manifest as detectable events. These snapshots preserve the state of assets (files, processes, registry, network connections) at specific moments, enabling retrospective analysis to detect subtle changes that indicate APT presence, thereby extending detection capability beyond conventional real-time monitoring.
Solution Approach 2:
The invention transitions from temporal monitoring (detecting events as they occur) to a multi-dimensional approach by capturing assets in multiple forensic states across time. This adds a dimension of historical state comparison, allowing detection of gradual, persistent changes that conventional single-point-in-time monitoring cannot detect.
2Reliability
If forensic snapshots are collected at multiple points in time, then APTs can be detected through differential analysis, but system complexity increases
Solution Approach 1:
The system segments the forensic analysis process into distinct modules: snapshot collection, differential analysis, and threat detection. Each module handles specific tasks independently - the snapshot collector captures asset states, the differential analyzer compares changes between snapshots, and the threat detector identifies APT indicators. This segmentation reduces overall system complexity by making each component more manageable and reusable.
Solution Approach 2:
The differential analysis engine acts as an intermediary between raw forensic snapshots and final threat detections. It processes the snapshots, identifies meaningful changes, and filters out noise, thereby simplifying the detection process. This intermediary layer abstracts the complexity of multi-point time comparison from the final detection logic.
3Ease of manufacture
If conventional monitoring measures are used, then implementation is simple, but they focus on security events rather than long-term processes
Solution Approach 1:
The forensic snapshot system provides multi-functionality by capturing multiple types of asset states (files, processes, registry, network connections) simultaneously at multiple time points. This universal approach enables detection of various threat types (APTs, insider threats, malware) and supports multiple analysis purposes (incident response, compliance auditing, forensics), thereby expanding detection scope without requiring separate specialized systems for each function.
Data Source
AI summary
Disclosed invention proposes a method of differential analysis of assets in an information system network which compares different states of at least one asset in its network, with one of said states corresponding to a certain point in time, whereas at least one other of said states at least corresponding to one other certain point in time. Disclosed invention also proposes a distance metric between said at least one state and at least one other state of an asset in the information system network, as well as a method to propose a method of determining presence of advanced persistent threats (APTs) or internal investigations in an information system network based on the qualitative and quantitative properties of 15 said distance metric.
