Cyber Recovery Forensics Kit Replays PITs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional forensic processes are limited in scope and insight, as they primarily rely on the most recent data point in time, which can be insufficient for comprehensive analysis of issues like malware, especially in understanding infection timelines and damage assessment.

Innovation Solution

A system that utilizes historical data snapshots across a time period, allowing for the dynamic analysis and visualization of data system changes by replaying events in reverse or forward chronological order, providing a 'live' dataset view to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional forensic processes use only the most recent data point, then the analysis is simple and quick, but the scope and insight are limited

Engineering Contradiction:
Improveforensic insightVSAvoidforensic process complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The forensic analysis process is segmented into multiple discrete point-in-time snapshots rather than analyzing a single continuous dataset. Each snapshot represents a distinct temporal state that can be independently analyzed and compared, enabling comprehensive forensic insight while maintaining manageable analysis units

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The forensic process transitions from analyzing data in a single temporal dimension (most recent state only) to multiple temporal dimensions by incorporating historical snapshots. This dimensional expansion allows investigators to trace infection paths and understand system evolution without proportionally increasing process complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If historical snapshots are analyzed to improve forensic scope, then comprehensive damage assessment is enabled, but data processing complexity increases

Engineering Contradiction:
Improvedamage assessment completenessVSAvoiddata processing complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

Multiple point-in-time snapshots are captured and preserved in advance before forensic analysis is needed. This preliminary data collection creates a ready-to-analyze historical record that enables comprehensive damage assessment without requiring complex real-time processing during the actual forensic investigation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of analyzing the live production system directly, the invention creates and analyzes copies of system states at different points in time. These snapshot copies preserve historical data while allowing complex processing to occur on the copies rather than the original system, reducing processing complexity

Inventive Principle:
Principle #26Copying

3Loss of time

If multiple PIT snapshots are stored for analysis, then infection timeline tracing is improved, but storage requirements increase

Engineering Contradiction:
Improveinfection timeline resolutionVSAvoiddata storage volume
Core Design Contradiction:
Loss of timeVSQuantity of substance

Solution Approach 1:

The snapshot data structure is designed with local quality optimization where each snapshot contains only the specific system state information relevant to that point in time, rather than duplicating entire system images. This enables precise infection timeline tracing while minimizing redundant storage of identical data across multiple snapshots

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240126870A1Cyber recovery forensics kit - run and observe over time
Publication Date: 2024.04.18 DELL PROD LP
  • US20240126870A1 patent drawing
  • US20240126870A1 patent drawing
  • US20240126870A1 patent drawing

AI summary

A method includes accessing a group that comprises a group of PITs, replaying the PITs according to respective times at which the snapshots were taken, analyzing the PITs as they are being replayed, and based on the analyzing, identifying an event that has occurred within a time frame spanned collectively by the PITs. Replaying the PITs includes presenting the PITs, in order from oldest to newest, as a continuous stream of events.