Dynamic Auditing Level Adjustment for VM Forensic Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for capturing snapshots of memory in computing systems are resource-intensive and often fail to detect clever attacks that erase their tracks between snapshot intervals, leading to incomplete forensic data.

Innovation Solution

A method and system for capturing virtual machine resources for forensics, which involves receiving an indication of compromise, snapshotting volatile and non-volatile memory states, and increasing auditing levels to capture detailed access data during an attack, with snapshots taken before and after the attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If snapshots are captured at high frequency to ensure small delta and detect attacks, then measurement precision and reliability are improved, but processing and memory resources are excessively consumed

Engineering Contradiction:
Improveforensic data completenessVSAvoidprocessing and memory resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The auditing level is dynamically adjusted based on system state. During normal operation, standard auditing level is maintained to minimize resource consumption. When an indication of compromise is detected, the system transitions to heightened auditing level to capture detailed forensic data, then returns to standard level after the threat is resolved, creating a dynamic balance between forensic completeness and resource efficiency

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of auditing level from static to variable. By modifying the auditing level parameter in response to detected threats (standard → heightened → standard), the system achieves high measurement precision when needed while maintaining low resource consumption during normal operation, directly resolving the contradiction between forensic data quality and resource usage

Inventive Principle:
Principle #35Parameter changes

2Productivity

If standard auditing level is maintained to minimize resource consumption, then processing resources are preserved, but detailed forensic data is lost during attacks

Engineering Contradiction:
Improvesystem performanceVSAvoidforensic data
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary action by detecting indications of compromise before attacks fully execute. When such indications are detected, the auditing level is proactively increased to heightened level, capturing detailed forensic data before the attack completes and potentially erases its tracks. This preliminary response prevents information loss while maintaining normal performance during non-threat periods

Inventive Principle:
Principle #10Preliminary action

3Reliability

If heightened auditing is maintained continuously to capture all attack details, then forensic data completeness is improved, but system performance deteriorates

Engineering Contradiction:
Improveforensic data accuracyVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic action by alternating between standard and heightened auditing levels based on detected threats. Heightened auditing is activated only during periods when indications of compromise are detected, and deactivated when threats are resolved. This periodic switching ensures high forensic data accuracy during attacks while maintaining normal system performance during non-threat periods, resolving the contradiction between reliability and productivity

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250094205A1Behavior-based VM resource capture for forensics
Publication Date: 2025.03.20 GOOGLE LLC
  • US20250094205A1 patent drawing
  • US20250094205A1 patent drawing
  • US20250094205A1 patent drawing

AI summary

A method including monitoring, using a standard level of auditing, one or more processes of a VM and, based on monitoring the process(es), detecting aberrant behavior indicating that an attack against the VM is imminent. Based on detecting aberrant behavior indicating that the attack is imminent, the method includes monitoring, using a heightened level of auditing, the process(es), the heightened level of auditing generating log data representative of memory accesses performed by the VM, and notifying a user of the VM that the imminent attack is detected. During the attack against the VM, maintaining the monitoring of the process(es) using the heightened level of auditing, the method includes determining that the attack has concluded and, based on determining that the attack has concluded, processing the log data to determine an action performed by the detected attack; and monitoring, using the standard level of auditing, the process(es).