Live Forensics Analysis Device for Malware State Reproduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current live forensics techniques face challenges in efficiently analyzing malware activity due to the need for high-speed storage devices and the difficulty in capturing and reproducing the state of analysis target equipment, especially when malware uses encryption and volatile memory, leading to limited resource utilization and incomplete data acquisition.
Innovation Solution
An analysis device with a dispatcher, data mapper, and data writer that generates and saves collection target data from the analysis target equipment, using tag information to efficiently store data in a high-speed storage device with a specific capacity, allowing for the reproduction of the equipment's state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If data stored in volatile storage device is acquired for live forensics analysis, then malware activity can be captured and encryption keys can be obtained, but data loss occurs when system state changes or power is lost
Solution Approach 1:
The system performs preliminary actions by continuously capturing and storing snapshots of volatile storage data before malware can destroy evidence or before system state changes occur. The memory capture unit proactively memorizes storage device states at regular intervals, ensuring data is preserved before potential loss
Solution Approach 2:
The invention creates copies of volatile storage data by generating memory snapshots that duplicate the state of the storage device at specific points in time. These snapshots are stored in a persistent manner, allowing forensic analysis without risking data loss from system changes or power loss
2Speed
If high-speed storage device is used to capture volatile memory data, then data acquisition speed is improved, but storage capacity is limited and costs increase
Solution Approach 1:
The storage system is segmented into multiple storage devices with different characteristics. High-speed storage devices are used for capturing time-critical volatile memory data, while lower-speed storage devices store less time-sensitive information. This segmentation allows the system to optimize for speed where needed while managing overall storage capacity and costs
Solution Approach 2:
Different quality levels of storage are applied to different types of data. Time-critical volatile memory snapshots are stored in high-speed storage with superior performance characteristics, while other forensic data can be stored in lower-speed storage. This local quality approach ensures critical data is captured at high speed without requiring all storage to be high-speed
3Measurement precision
If encrypted data in non-volatile storage device is analyzed, then persistent malware traces can be detected, but decryption difficulty increases analysis complexity and time
Solution Approach 1:
The system performs preliminary capture of encryption keys and decrypted data from volatile memory before malware can detect the analysis and trigger protective measures. By capturing this data in advance during the live forensics phase, the system obtains decryption capabilities without needing to break encryption during analysis
Solution Approach 2:
The invention uses volatile memory contents as an intermediary to obtain decryption keys. Instead of directly attacking encrypted data in non-volatile storage, the system first captures the decryption keys that temporarily reside in volatile memory, then uses these keys to decrypt and analyze the encrypted data, simplifying the overall analysis process
4Loss of information
If log data and communication records are collected for analysis, then comprehensive incident information is obtained, but analysis time increases significantly
Solution Approach 1:
The system extracts only the most relevant and time-critical data from the vast amount of available logs and communication records. By focusing on volatile memory contents that contain active malware states and essential decryption keys, rather than analyzing all stored logs, the system achieves quick response while maintaining information completeness for critical incident elements
Solution Approach 2:
The system performs partial analysis by capturing essential volatile memory data that contains the most valuable forensic information about active malware. Rather than attempting to analyze all log data and communication records comprehensively, the system takes action on the critical subset of data in volatile memory, achieving rapid response with sufficient information for effective incident handling
Data Source
AI summary
Provided is an analysis apparatus including a first storage device configured to store data, and a processing circuitry that is configured to control the own apparatus to function as: a dispatcher that is communicably connected to an analysis target device that performs operational processing by use of a processor and a memory unit, and generates collection target data for reproducing at least part of a state of the operational processing in the analysis target device, in accordance with data being transmitted and received between the processor and the memory unit; a data mapper that assigns, to one or more areas included in the collection target data, tag information for identifying the area; and a data writer that saves the one or more areas into the first storage device in accordance with a first policy defining a procedure of saving the collection target data into the first storage device.


