Security Client Event Tracking for Forensic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing environments, identifying and addressing security breaches is inefficient due to the difficulty in tracking malicious activity, as malicious actors often cover their tracks, requiring extensive digital forensics and secondary data analysis.

Innovation Solution

A security client is configured to detect and record events on computing systems, generating unique event identifiers and records that include details of the events, allowing for efficient tracking and forensic analysis of security incidents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If digital forensics and secondary data analysis are used to identify security breaches, then investigation completeness can be improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improveinvestigation completenessVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by implementing event tracking and recording mechanisms that continuously capture security-relevant events before incidents occur. The system pre-establishes event sources, data models, and tracking pipelines so that when a security breach occurs, the information is already captured and organized, eliminating the need for time-consuming post-incident forensic analysis while maintaining complete investigation capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer between security events and analysis processes. The event tracking system acts as a mediator that continuously monitors, captures, and stores security events in a structured format. This intermediary infrastructure enables rapid incident response by providing pre-processed, organized event data without requiring direct forensic investigation of raw system data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed digital forensics investigation is performed to determine attack scope and impact, then accuracy of incident assessment is improved, but productivity and response speed decrease

Engineering Contradiction:
Improveincident assessment accuracyVSAvoidresponse speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary action by continuously tracking and recording security events in real-time, maintaining an up-to-date picture of system state and security incidents. This pre-captured event data enables rapid incident assessment because the information about attack scope and impact is already organized and available, eliminating the need for slow, detailed forensic investigations while preserving assessment accuracy

Inventive Principle:
Principle #10Preliminary action

3Productivity

If comprehensive event tracking and recording infrastructure is implemented, then incident response efficiency is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveincident response efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the event tracking system into distinct modular components: event sources that generate events, data models that define event structures, event trackers that capture events, and recording systems that store events. This modular architecture improves incident response efficiency while managing system complexity through clear separation of concerns and independent, reusable components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by designing a comprehensive event tracking framework that can monitor multiple types of security events across different systems and applications through a unified interface. The standardized data models and tracking mechanisms provide multi-functional capability, allowing the same infrastructure to track various incident types without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11182478B2Systems and methods for tracking and recording events in a network of computing systems
Publication Date: 2021.11.23 VMWARE INC
  • US11182478B2 patent drawing
  • US11182478B2 patent drawing
  • US11182478B2 patent drawing

AI summary

A security client can be configured to operate on the one or more computing systems and record all events occurring on the one or more computing systems. The security client can operate as a “security camera” for the computing systems by identifying and retaining data and information that describes and details different events that occur on the computing systems. The security client can be configured to generate event records for the events that are uniquely associated with the process that requested or performed event. Likewise, the security client can be configured to uniquely associate the event records with the specific computing system associated with the event.