Dynamic Auditing Level Adjustment for VM Forensic Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for capturing snapshots of memory in computing systems are resource-intensive and often fail to detect clever attacks that erase their tracks between snapshot intervals, leading to incomplete forensic data.
Innovation Solution
A method and system for capturing virtual machine resources for forensics, which involves receiving an indication of compromise, snapshotting volatile and non-volatile memory states, and increasing auditing levels to capture detailed access data during an attack, with snapshots taken before and after the attack.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If snapshots are captured at high frequency to ensure small delta and detect attacks, then measurement precision and reliability are improved, but processing and memory resources are excessively consumed
Solution Approach 1:
The auditing level is dynamically adjusted based on system state. During normal operation, standard auditing level is maintained to minimize resource consumption. When an indication of compromise is detected, the system transitions to heightened auditing level to capture detailed forensic data, then returns to standard level after the threat is resolved, creating a dynamic balance between forensic completeness and resource efficiency
Solution Approach 2:
The patent changes the parameter of auditing level from static to variable. By modifying the auditing level parameter in response to detected threats (standard → heightened → standard), the system achieves high measurement precision when needed while maintaining low resource consumption during normal operation, directly resolving the contradiction between forensic data quality and resource usage
2Productivity
If standard auditing level is maintained to minimize resource consumption, then processing resources are preserved, but detailed forensic data is lost during attacks
Solution Approach 1:
The system performs preliminary action by detecting indications of compromise before attacks fully execute. When such indications are detected, the auditing level is proactively increased to heightened level, capturing detailed forensic data before the attack completes and potentially erases its tracks. This preliminary response prevents information loss while maintaining normal performance during non-threat periods
3Reliability
If heightened auditing is maintained continuously to capture all attack details, then forensic data completeness is improved, but system performance deteriorates
Solution Approach 1:
The system implements periodic action by alternating between standard and heightened auditing levels based on detected threats. Heightened auditing is activated only during periods when indications of compromise are detected, and deactivated when threats are resolved. This periodic switching ensures high forensic data accuracy during attacks while maintaining normal system performance during non-threat periods, resolving the contradiction between reliability and productivity
Data Source
AI summary
A method including monitoring, using a standard level of auditing, one or more processes of a VM and, based on monitoring the process(es), detecting aberrant behavior indicating that an attack against the VM is imminent. Based on detecting aberrant behavior indicating that the attack is imminent, the method includes monitoring, using a heightened level of auditing, the process(es), the heightened level of auditing generating log data representative of memory accesses performed by the VM, and notifying a user of the VM that the imminent attack is detected. During the attack against the VM, maintaining the monitoring of the process(es) using the heightened level of auditing, the method includes determining that the attack has concluded and, based on determining that the attack has concluded, processing the log data to determine an action performed by the detected attack; and monitoring, using the standard level of auditing, the process(es).


