Live Forensics Analysis Device for Malware State Reproduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current live forensics techniques face challenges in efficiently analyzing malware activity due to the need for high-speed storage devices and the difficulty in capturing and reproducing the state of analysis target equipment, especially when malware uses encryption and volatile memory, leading to limited resource utilization and incomplete data acquisition.

Innovation Solution

An analysis device with a dispatcher, data mapper, and data writer that generates and saves collection target data from the analysis target equipment, using tag information to efficiently store data in a high-speed storage device with a specific capacity, allowing for the reproduction of the equipment's state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data stored in volatile storage device is acquired for live forensics analysis, then malware activity can be captured and encryption keys can be obtained, but data loss occurs when system state changes or power is lost

Engineering Contradiction:
Improvemalware activity detection accuracyVSAvoiddata preservation reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by continuously capturing and storing snapshots of volatile storage data before malware can destroy evidence or before system state changes occur. The memory capture unit proactively memorizes storage device states at regular intervals, ensuring data is preserved before potential loss

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates copies of volatile storage data by generating memory snapshots that duplicate the state of the storage device at specific points in time. These snapshots are stored in a persistent manner, allowing forensic analysis without risking data loss from system changes or power loss

Inventive Principle:
Principle #26Copying

2Speed

If high-speed storage device is used to capture volatile memory data, then data acquisition speed is improved, but storage capacity is limited and costs increase

Engineering Contradiction:
Improvedata acquisition speedVSAvoidstorage capacity
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The storage system is segmented into multiple storage devices with different characteristics. High-speed storage devices are used for capturing time-critical volatile memory data, while lower-speed storage devices store less time-sensitive information. This segmentation allows the system to optimize for speed where needed while managing overall storage capacity and costs

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality levels of storage are applied to different types of data. Time-critical volatile memory snapshots are stored in high-speed storage with superior performance characteristics, while other forensic data can be stored in lower-speed storage. This local quality approach ensures critical data is captured at high speed without requiring all storage to be high-speed

Inventive Principle:
Principle #3Local quality

3Measurement precision

If encrypted data in non-volatile storage device is analyzed, then persistent malware traces can be detected, but decryption difficulty increases analysis complexity and time

Engineering Contradiction:
Improvemalware trace detection accuracyVSAvoiddata decryption complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary capture of encryption keys and decrypted data from volatile memory before malware can detect the analysis and trigger protective measures. By capturing this data in advance during the live forensics phase, the system obtains decryption capabilities without needing to break encryption during analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses volatile memory contents as an intermediary to obtain decryption keys. Instead of directly attacking encrypted data in non-volatile storage, the system first captures the decryption keys that temporarily reside in volatile memory, then uses these keys to decrypt and analyze the encrypted data, simplifying the overall analysis process

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If log data and communication records are collected for analysis, then comprehensive incident information is obtained, but analysis time increases significantly

Engineering Contradiction:
Improveincident information completenessVSAvoidanalysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system extracts only the most relevant and time-critical data from the vast amount of available logs and communication records. By focusing on volatile memory contents that contain active malware states and essential decryption keys, rather than analyzing all stored logs, the system achieves quick response while maintaining information completeness for critical incident elements

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs partial analysis by capturing essential volatile memory data that contains the most valuable forensic information about active malware. Rather than attempting to analyze all log data and communication records comprehensively, the system takes action on the critical subset of data in volatile memory, achieving rapid response with sufficient information for effective incident handling

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11436325B2Analysis device, analysis method, and storage medium in which analysis program is recorded
Publication Date: 2022.09.06 NEC CORP
  • US11436325B2 patent drawing
  • US11436325B2 patent drawing
  • US11436325B2 patent drawing

AI summary

Provided is an analysis apparatus including a first storage device configured to store data, and a processing circuitry that is configured to control the own apparatus to function as: a dispatcher that is communicably connected to an analysis target device that performs operational processing by use of a processor and a memory unit, and generates collection target data for reproducing at least part of a state of the operational processing in the analysis target device, in accordance with data being transmitted and received between the processor and the memory unit; a data mapper that assigns, to one or more areas included in the collection target data, tag information for identifying the area; and a data writer that saves the one or more areas into the first storage device in accordance with a first policy defining a procedure of saving the collection target data into the first storage device.