Forensic Snapshot Analysis for Long-Dwell APT Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional monitoring-based cybersecurity measures are inadequate for detecting advanced persistent threats (APTs) and insider threats that maintain undetected presence over extended periods, as they focus on security events rather than long-term processes.

Innovation Solution

A differential analysis method that compares forensic snapshots of assets at different points in time to detect APTs by determining what is added, changed, or removed, using a distance metric to assess the security level and presence of threats based on asset states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional monitoring-based cybersecurity measures are used, then security events can be detected, but advanced persistent threats maintaining undetected presence over extended periods cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoidundetected presence duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs preliminary actions by capturing forensic snapshots of assets at multiple points in time before threats manifest as detectable events. These snapshots preserve the state of assets (files, processes, registry, network connections) at specific moments, enabling retrospective analysis to detect subtle changes that indicate APT presence, thereby extending detection capability beyond conventional real-time monitoring.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention transitions from temporal monitoring (detecting events as they occur) to a multi-dimensional approach by capturing assets in multiple forensic states across time. This adds a dimension of historical state comparison, allowing detection of gradual, persistent changes that conventional single-point-in-time monitoring cannot detect.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If forensic snapshots are collected at multiple points in time, then APTs can be detected through differential analysis, but system complexity increases

Engineering Contradiction:
ImproveAPT detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the forensic analysis process into distinct modules: snapshot collection, differential analysis, and threat detection. Each module handles specific tasks independently - the snapshot collector captures asset states, the differential analyzer compares changes between snapshots, and the threat detector identifies APT indicators. This segmentation reduces overall system complexity by making each component more manageable and reusable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The differential analysis engine acts as an intermediary between raw forensic snapshots and final threat detections. It processes the snapshots, identifies meaningful changes, and filters out noise, thereby simplifying the detection process. This intermediary layer abstracts the complexity of multi-point time comparison from the final detection logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If conventional monitoring measures are used, then implementation is simple, but they focus on security events rather than long-term processes

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddetection scope
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The forensic snapshot system provides multi-functionality by capturing multiple types of asset states (files, processes, registry, network connections) simultaneously at multiple time points. This universal approach enables detection of various threat types (APTs, insider threats, malware) and supports multiple analysis purposes (incident response, compliance auditing, forensics), thereby expanding detection scope without requiring separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250378158A1Systems and methods for detection of advanced persistent threats in an information network
Publication Date: 2025.12.11 BINALYZE YAZILIM AS
  • US20250378158A1 patent drawing

AI summary

Disclosed invention proposes a method of differential analysis of assets in an information system network which compares different states of at least one asset in its network, with one of said states corresponding to a certain point in time, whereas at least one other of said states at least corresponding to one other certain point in time. Disclosed invention also proposes a distance metric between said at least one state and at least one other state of an asset in the information system network, as well as a method to propose a method of determining presence of advanced persistent threats (APTs) or internal investigations in an information system network based on the qualitative and quantitative properties of 15 said distance metric.