Sensor Agent Forensic Visibility via Event Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network forensic tools lack the ability to provide end-to-end visibility within computing devices, failing to capture detailed system changes and data communication events, leading to incomplete analysis and guesswork in identifying malware impacts.

Innovation Solution

A system and method utilizing six components: low-level system filters, a local aggregator and interpreter, a context analyzer, a global perspective module, an event priority module, and an event distributor, which gather, process, and contextualize events to provide comprehensive forensic visibility across computing devices, including contextual state and global perspective information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If network edge devices are used to monitor network traffic, then network traffic between hosts can be captured, but detailed system changes and events within the host cannot be obtained

Engineering Contradiction:
Improvevisibility into system eventsVSAvoidsystem architecture
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system divides the forensic monitoring function into two segments: a sensor agent deployed within each host to capture detailed system events, and a network edge device to aggregate and analyze the data. This segmentation allows both intra-host visibility and network-wide monitoring without requiring a single complex device to perform all functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sensor agent acts as an intermediary between the host operating system and the network edge device. It captures detailed system events locally and forwards selected information to the network edge device, enabling the edge device to gain visibility into host events without directly accessing or complicating the host system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If all system events are captured and transmitted, then complete forensic visibility is achieved, but network bandwidth and processing overhead increase

Engineering Contradiction:
Improvecompleteness of event dataVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

The sensor agent extracts only the most relevant and actionable event data from the complete set of system events. It applies filtering and prioritization logic to extract high-value information such as security-relevant events, system changes, and anomalies, while discarding routine or low-value events. This extraction maintains forensic completeness for critical events while significantly reducing data volume for transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements partial action by capturing and transmitting only a subset of all possible system events - specifically those deemed forensically valuable. Rather than transmitting every event without discrimination, the sensor agent selectively forwards events based on predefined criteria, achieving sufficient forensic visibility with reduced bandwidth consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If detailed contextual information is collected for every event, then forensic analysis accuracy improves, but data processing time and storage requirements increase

Engineering Contradiction:
Improveforensic analysis accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The sensor agent performs preliminary filtering, categorization, and prioritization of events before transmission to the network edge device. It pre-processes events by assigning relevance scores, categorizing event types, and filtering out low-value data locally. This preliminary action reduces the processing burden on the network edge device and accelerates subsequent forensic analysis by presenting pre-sorted, high-value data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10257224B2Method and apparatus for providing forensic visibility into systems and networks
Publication Date: 2019.04.09 OPEN TEXT CORPORATION
  • US10257224B2 patent drawing
  • US10257224B2 patent drawing
  • US10257224B2 patent drawing

AI summary

Methods and systems for providing forensic visibility into systems and networks are provided. More particularly, a sensor agent may receive events defining an action of a first object acting on a target. The object, the event, and the target are then correlated to at least one originating object such that an audit trail for each individual event is created. A global perspective indicating an age, popularity, a determination as to whether the object may be malware, and IP/URL information associated with the event may then be applied to at least one of the object, the event, the target, and the originating object. A priority may then be determined and assigned to the event based on at least the global perspective. An event line containing event information is then transmitted to an end recipient where the information may be heuristically displayed.