Sensor Agent Forensic Visibility via Event Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network forensic tools lack the ability to provide end-to-end visibility within computing devices, failing to capture detailed system changes and data communication events, leading to incomplete analysis and guesswork in identifying malware impacts.
Innovation Solution
A system and method utilizing six components: low-level system filters, a local aggregator and interpreter, a context analyzer, a global perspective module, an event priority module, and an event distributor, which gather, process, and contextualize events to provide comprehensive forensic visibility across computing devices, including contextual state and global perspective information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If network edge devices are used to monitor network traffic, then network traffic between hosts can be captured, but detailed system changes and events within the host cannot be obtained
Solution Approach 1:
The system divides the forensic monitoring function into two segments: a sensor agent deployed within each host to capture detailed system events, and a network edge device to aggregate and analyze the data. This segmentation allows both intra-host visibility and network-wide monitoring without requiring a single complex device to perform all functions.
Solution Approach 2:
The sensor agent acts as an intermediary between the host operating system and the network edge device. It captures detailed system events locally and forwards selected information to the network edge device, enabling the edge device to gain visibility into host events without directly accessing or complicating the host system architecture.
2Loss of information
If all system events are captured and transmitted, then complete forensic visibility is achieved, but network bandwidth and processing overhead increase
Solution Approach 1:
The sensor agent extracts only the most relevant and actionable event data from the complete set of system events. It applies filtering and prioritization logic to extract high-value information such as security-relevant events, system changes, and anomalies, while discarding routine or low-value events. This extraction maintains forensic completeness for critical events while significantly reducing data volume for transmission.
Solution Approach 2:
The system implements partial action by capturing and transmitting only a subset of all possible system events - specifically those deemed forensically valuable. Rather than transmitting every event without discrimination, the sensor agent selectively forwards events based on predefined criteria, achieving sufficient forensic visibility with reduced bandwidth consumption.
3Measurement precision
If detailed contextual information is collected for every event, then forensic analysis accuracy improves, but data processing time and storage requirements increase
Solution Approach 1:
The sensor agent performs preliminary filtering, categorization, and prioritization of events before transmission to the network edge device. It pre-processes events by assigning relevance scores, categorizing event types, and filtering out low-value data locally. This preliminary action reduces the processing burden on the network edge device and accelerates subsequent forensic analysis by presenting pre-sorted, high-value data.
Data Source
AI summary
Methods and systems for providing forensic visibility into systems and networks are provided. More particularly, a sensor agent may receive events defining an action of a first object acting on a target. The object, the event, and the target are then correlated to at least one originating object such that an audit trail for each individual event is created. A global perspective indicating an age, popularity, a determination as to whether the object may be malware, and IP/URL information associated with the event may then be applied to at least one of the object, the event, the target, and the originating object. A priority may then be determined and assigned to the event based on at least the global perspective. An event line containing event information is then transmitted to an end recipient where the information may be heuristically displayed.


