WO2020167552A1 - System and method for forensic artifact analysis and visualization - Google Patents
System and method for forensic artifact analysis and visualization Download PDFInfo
- Publication number
- WO2020167552A1 WO2020167552A1 PCT/US2020/016796 US2020016796W WO2020167552A1 WO 2020167552 A1 WO2020167552 A1 WO 2020167552A1 US 2020016796 W US2020016796 W US 2020016796W WO 2020167552 A1 WO2020167552 A1 WO 2020167552A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- analysis
- artifact
- forensic
- module
- results
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/02—Addressing or allocation; Relocation
- G06F12/08—Addressing or allocation; Relocation in hierarchically structured memory systems, e.g. virtual memory systems
- G06F12/0802—Addressing of a memory level in which the access to the desired data or data block requires associative addressing means, e.g. caches
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/20—Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
- G06F16/24—Querying
- G06F16/245—Query processing
- G06F16/2458—Special types of queries, e.g. statistical queries, fuzzy queries or distributed queries
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F18/00—Pattern recognition
- G06F18/20—Analysing
- G06F18/24—Classification techniques
- G06F18/241—Classification techniques relating to the classification model, e.g. parametric or non-parametric approaches
- G06F18/2415—Classification techniques relating to the classification model, e.g. parametric or non-parametric approaches based on parametric or probabilistic models, e.g. based on likelihood ratio or false acceptance rate versus a false rejection rate
- G06F18/24155—Bayesian classification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/46—Multiprogramming arrangements
- G06F9/54—Interprogram communication
- G06F9/541—Interprogram communication via adapters, e.g. between incompatible applications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N20/00—Machine learning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/04—Processing captured monitoring data, e.g. for logfile generation
- H04L43/045—Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
Definitions
- the present invention relates to information technology (IT) security, and, more particularly, relates to a system and method for forensic artifact analysis and visualization.
- IT information technology
- Embodiments of the present invention disclosure provide a non-transitory computer- readable medium comprising instructions which, when executed by a computer system, cause the computer system to carry out a method of forensic artifact analysis including steps of receiving from an end user a request to analyze an artifact which is included with the request for potential maliciousness, identifying a type of the received artifact, delivering the artifact to an analyzer adapted to analyze the identified artifact type, wherein the analyzer produces an analysis output, generating a query to a central intelligence database based on the analysis output, analyzing the artifact and results of the query using a plurality of analysis modules to provide information regarding maliciousness of the artifact, and providing a visualization of results of the analysis by the plurality of analysis modules to the end user.
- the artifact can be either a file or a byte stream.
- non-transitory computer-readable medium further comprises instructions for causing the computer system to execute the step of queuing the requests after receipt from the end user.
- the end user can be a human analyst or another computing device.
- the non-transitory computer-readable medium further comprises instructions for causing the computer system to execute the step of storing the results of the analysis of the plurality of analysis modules in the central intelligence database. In some implementations, the non-transitory computer-readable medium further comprises instructions for causing the computer system to execute the step storing the results of the query and the results of the analysis of the plurality of analysis modules in a local memory cache prior to the central intelligence database. [0010] In certain embodiments, the non-transitory computer-readable medium further comprises instructions for causing the computer system to execute the step of generating a signature of the results of the analysis of the plurality of analysis modules in the central intelligence database. In some implementations, the signature includes at least one of a direct byte stream signature, a unique digest generated by a one-way function, and a metadata tag.
- the analysis modules can include a Naive Bayes (NB) classifier, a K-nearest neighbor (KNN) classifier, a learning vector quantization (LVQ) classifier, a self-organized map (SOM) algorithm, a multivariate adapted regression splines (MARS) analyzer, and an Expectation- Maximization (EM) algorithm.
- NB Naive Bayes
- KNN K-nearest neighbor
- LVQ learning vector quantization
- SOM self-organized map
- MERS multivariate adapted regression splines
- EM Expectation- Maximization
- Embodiments of the present invention also provide a forensic artifact analysis system.
- the system comprises one or more processors, the processors having access to program instructions that when executed, generate the following modules: i) an application program interface configured to receive a request from an end user to analyze an artifact which is included with the request for potential maliciousness; ii) a loader module coupled to the application program interface configured to identify a type of the received artifact; iii) an external analyzer API configured to deliver the artifact to an external analyzer adapted to analyze the identified artifact type, wherein the external analyzer produces an analysis output; iv) a query module configured to generate and send a query to a central intelligence database based on the analysis output; v) a specific analyzer module configured to analyze the artifact and results of the query using a plurality of analysis techniques to generate information regarding maliciousness of the artifact; and vi) a visualizer module configured to provide a visualization of results of the analysis by the plurality of analysis modules adapted for
- the one or more processors have access to program instructions that when executed, further generate a queue module configured to receive the artifact analysis request from the application program interface and to queue the request for further processing.
- the one or more processors have access to program instructions that when executed, further generate a user interface adapted to receive the artifact analyst request from a human user and to pass the received request to the application program interface.
- the application program interface can also receive the artifact analysis request from an external computing device.
- the forensic analysis system further comprises a local memory cache, wherein the query module and the specific analysis module send results to the local memory cache before results are sent to the central intelligence database.
- the one or more processors have access to program instructions that when executed, further generate a signature via a generation module configured to a signature of the results of the analysis of the plurality of analysis modules in the central intelligence database.
- the signature can include at least one of a direct byte stream signature, a unique digest generated by a one-way function, and a metadata tag.
- the analysis modules can include a Naive Bayes (NB) classifier, a K-nearest neighbor (KNN) classifier, a learning vector quantization (LVQ) classifier, a self- organized map (SOM) algorithm, a multivariate adapted regression splines (MARS) analyzer, and an Expectation-Maximization (EM) algorithm.
- NB Naive Bayes
- KNN K-nearest neighbor
- LVQ learning vector quantization
- SOM self- organized map
- MERS multivariate adapted regression splines
- EM Expectation-Maximization
- FIG. 1 is a schematic block diagram of a system for forensic artifact analysis according to an exemplary embodiment of the present invention.
- FIG. 2 is a schematic illustration of an exemplary embodiment of a specific analyzer module used in the system for forensic artifact analysis according to the present invention.
- FIG. 3 is a schematic block diagram of an exemplary embodiment of a signature generator module used in the system for forensic artifact analysis according to the present invention.
- FIG. 4 is a schematic block diagram of another embodiment of a system for forensic artifact analysis according to the present invention that is particularly adapted for file artifact metadata collection and analysis.
- FIG. 5 is a schematic flow diagram of an exemplary embodiment of the flow of functions performed by the cache module according to the present invention.
- FIG. 6 is a schematic block diagram of an exemplary embodiment of an analyzer module adapted for the embodiment of the analysis system shown in FIG. 4.
- FIG. 7 is a schematic block diagram of another embodiment of a system for forensic artifact analysis according to an exemplary embodiment of the invention.
- the systems and methods disclosed herein employ computing resources executing one or more program modules to perform a series of steps on forensic artifacts received (ingested) in an IT environment.
- a computing system executing one or more applications on one or more processors queues, loads, and analyzes and correlates the artifacts using an external analysis solution (“external analyzer”) that can be called through an application programming interface (API).
- the data output of the external analyzer can be used to search an external central intelligence database for further analysis.
- the artifact is then classified using an second analyzer module that applies a series of rigorous analysis methods to the artifacts.
- the resulting data set is then arranged by a visualizer for feedback to an autonomic system through an application programming interface (API) or to a human analyst through a graphic user- interface.
- API application programming interface
- Embodiments of the present invention disclosure also provide an external analyzer that recursively extracts embedded files, objects, streams, and metadata for analysis and correlation.
- the external analyzer comprises of a collector node and a central node.
- the collector node collects file artifacts and associated metadata from associated file shares or repositories and transfers the collected artifacts to the central node.
- the artifacts are processed in an analysis node that reviews the collected data for initial identification of the artifacts and recursively extracts further artifacts and metadata from the collected artifacts.
- the analysis node further utilizes algorithmic techniques such as signature matching, heuristic rule- based analysis, machine learning and deep learning algorithms to analyze the data and artifacts for maliciousness.
- algorithmic techniques such as signature matching, heuristic rule- based analysis, machine learning and deep learning algorithms to analyze the data and artifacts for maliciousness.
- the artifacts, meta-data, and analysis results are stored into a central intelligence database for further correlation and cyber intelligence analysis.
- module used in the description and accompanying figures is defined as program code and associated memory resources, that when read and executed by a computer processor, perform certain defined procedures.
- an“analyzer module” comprises program code that when executed by a computer processor, performs procedures related to analysis of file data, bit-stream data and/or metadata.
- System 100 comprises one or more computing devices having processors configured to execute a group of related program modules.
- Forensic analysis system 100 is in communication with end users, including human end users 10 and external computer systems 20 that provide data to and receive analysis output from the forensic analysis system.
- the human end users 10 can interact with the system 100 via a user interface 102 and can submit artifacts to the system 100 for forensic analysis, including, but not limited to files, bitstreams, URLs, IP addresses, email messages, domains, and MAC Addresses.
- API application program interface
- non-human (computing/network device) end users for example, external applications or platforms, can submit artifacts and analysis requests directly to the API module 104.
- the API module 104 includes program code that when executed manages traffic between the end users and the rest of the forensic analysis system.
- the API module 104 enters the submitted artifacts into a queue module 112.
- the queue module 112 temporarily stores submitted artifacts to provide an ordered flow of artifact analysis procedures.
- the queue module 112 can provide for a first-in first-out (FIFO), last-in first-out (LIFO) or other known method for both ensuring that the system does not get overloaded and that every submission is processed.
- FIFO first-in first-out
- LIFO last-in first-out
- submissions are delivered from the queue module 112 in an orderly flow to a loader module 114.
- the loader module 114 comprises code for enabling a processor to review the artifact and to identify it as belonging to a general artifact type. By classifying the artifacts by type, the loader 114 allows the artifacts to be sorted and delivered to analyzer modules adapted for the specific artifact types.
- the loader 114 is coupled to an external analyzer module 116 which can be implemented as an application program interface that is communicatively coupled to a plurality of external analyzers 130.
- the external analyzer module 116 is operative to select one or more appropriate external analyzers for each artifact ingested from the loader 114 and to open a communication channel with the selected external analyzers.
- Program logic is employed to determine which external analyzer is appropriate for a given artifact being processed (e.g., ingested from the loader).
- the external analyzers 130 include dynamic analyzers adapted to analyze file artifacts. The dynamic analyzers can be used to gather additional forensic artifacts as a result of dynamic analysis of the file such as registry contents, transient files, memory contents consisting of data and executable operation codes, network communications packet captures, referenced runtime API’s, and all related metadata.
- the external analyzers also include applications adapted to process less complex artifacts such as IP addresses, domains, URL’s, MAC addresses, strings, etc. to find relevant data and metadata.
- the output generated by the external analyzers is communicated to a shared central intelligence database 140.
- the central intelligence database 140 is a secure database that is hosted externally to system 100 and receives the contributions of numerous systems for intelligence gathering and storage.
- the central intelligence database 140 can operate, for example, as a SQL server and can provide data in response to queries.
- the external analyzer module 116 directs the results from the external analyzers 130 to a query module 118.
- the query module 118 is configured to parse the results received from the external analyzer module 116 to obtain relevant fields for constructing a query to the central intelligence database 140.
- the relevant fields of the query can include the original artifact, additional relevant forensic artifacts discovered by dynamic analysis, and associated metadata.
- the query module 118 then executes the query against the central intelligence database. At the central database, execution of the query triggers a search for matching artifacts and associated data in the database. If there are no matches, all of the information provided in the query is stored in the central intelligence database 140.
- the central intelligence database 140 stores the result query set.
- a reference to the stored location of the query set is provided to an in-memory cache 120 which comprises memory storage capacity, such as chip cache memory, within system 100, enabling rapid access and retrieval of the query set data.
- the query module 118 provides the output from the external analyzers 130 and any query set results (“result dataset”) received from the central intelligence database 140 to a specific analyzer module 122.
- An exemplary embodiment of a specific analyzer module according to the present invention is shown in FIG. 2.
- the result dataset is delivered to a local memory cache 202 of the specific analyzer module in which the result dataset is stored.
- the specific analyzer module 122 includes a plurality of sub-modules configured to perform a specific type of analysis on the dataset.
- the sub-modules include a Naive Bayes classifier 212, a K-Nearest Neighbor KNN classifier 214, an Learning Vector Quantization (LVQ) classifier 216, an Self-Organized Map (SOM) algorithm 218, a Multivariate Adapted Regression Splines (MARS) analyzer 220, and Expectation-Maximization (EM) algorithm 222.
- the result datasets are sent from the memory cache 202 to an intermediary processing module 204.
- the intermediary processing module 204 passes the results dataset to the submodules 212-222 in series or in parallel depending on its configuration.
- the result dataset can be normalized by the intermediary processing module 204 prior to classification and analysis in sub-modules 212-222.
- Sub-modules 212-222 use different techniques to classify the artifact in a received dataset based upon other known artifacts.
- the NB classifier 212 applies Bayes’ Theorem to classify artifacts
- KNN classifier 214 employs a non-parametric approach for classification
- the LVQ classifier employs a prototype-based approach
- the SOM algorithm 218 employs a dimensionality-reduction technique
- the MARS analyzer like the KNN classifier, uses a non-parametric technique
- the EM algorithm employs a non-linear dimensionality-reduction technique.
- sub-modules 212-222 classify the artifact in a binary category as being either“suspicious” or“not suspicious” based on their analyses of the result dataset.
- the intermediary processing module 215 also performs data lookups to the central intelligence database 140, as well as stores and updates data in a local memory cache 218. For example, during series processing the classification results of the NB classifier 202 can be delivered to the intermediary processing module 215, which then can store the results in memory cache 218 prior to the next analysis by the KNN classifier 204.
- the techniques employed by such sub-modules are complementary to the extent that they use different approaches, and to the extent they yield similar results, provide a high degree of confidence of accuracy.
- the specific analyzer module 112 can be implemented in a cluster form for faster performance and can utilize specialized processors such as graphics processing units (GPUs) or field programmable gate arrays (FPGAs).
- Signature generator module 124 includes three sub-modules that create“signatures” of the received outputs.
- the sub-modules can include a direct generator module 304, a Fuzzy generator module 306 and a Meta Enhancer module 308.
- the direct signature generator sub-module 304 creates signatures directly from bytestream content, such as header text.
- the signatures enable rapid identification of the artifact or resulting component(s) of the artifact during on-going and subsequent analyses in which the artifacts having signatures are matched against other artifacts that are newly observed during daily cybersecurity operational processes.
- a direct signature can be a hexadecimal bytestream value such as 6a 75 67 67 65 72 6e 61 75 74, which when converted to ASCII code is“juggernaut.”
- the hexadecimal value can be stored use subsequent as a direct bytestream signature match of the artifact or portions thereof.
- the Fuzzy generator sub-module 306 uses a one-way function to create a rolling hash, referred to as a“context-triggered piecewise hash,” of the artifact or a component thereof which can be used as a signature. Creating these types of hashes across the component as a whole and its derived subcomponents allows for proximity and nearness relational matches (i.e., matches that compares the total content of an artifact or subcomponent) that are very useful for intelligence purposes in identifying adversaries, tactics, threats, and their tools. Utilizing this approach on the component as a whole and derived subcomponents allows for correlation of intelligence data that can otherwise be overlooked.
- the Meta Enhancer sub-module 308 uses metadata extracted from the original artifact and tags the artifact, and in some
- Metadata tags also facilitate correlation against existing and newly found other artifacts for intelligence purposes.
- the analysis output and associated signatures are transmitted to a local memory cache 310.
- the memory cache then synchronously or asynchronously transmits the analysis output and signatures to the central intelligence database 140 for long-term storage.
- signature generator module 124 sends the analysis output and associated signatures to a visualizer module 126.
- Visualizer module 126 includes code which configures a processor to convert the received data into a format that is adapted for graphic representation.
- the converted output of the visualizer module 126 is provided to the API module 104 where it is forwarded to the requesting end users 10, 20 (via user interface module 102 for presentation to a human end user 10).
- the converted data is represented graphically and syntactically to the human end user 10.
- the human end user 10 can review and confirm the newly created signatures, digests, and meta-tags and confirm insertion and reanalysis of associated and related existing data in the central intelligence database 140. This results in a recursive query and analysis using the process disclosed, employing the signatures instead of the artifact data. The results can be added to the dataset in the central intelligence database 140. This recursive process can continue as needed to finalize various analysis and investigations.
- FIG. 4 is a schematic block diagram of another embodiment of a system for forensic artifact analysis according to the present invention that is particularly adapted for file artifact metadata collection and analysis.
- the system 400 comprises a collector node 410 and a central node 420.
- the collector node 410 and central node 420 can each comprise one or more computing devices such as application servers or, in some implementations, can be co-located in a single computing device as separate applications.
- the collector node 410 includes a collector module 412 that is configured to retrieve artifacts (e.g., file artifacts) from a plurality of computing resources in which files are stored or linked.
- artifacts e.g., file artifacts
- the collector module 412 can be configured to retrieve files from a specific source location such as a file share associated with cloud-based services, servers, desktops, mobile systems and devices, databases, and specific applications that store files.
- the collection module 412 can be configured to collect files of specific types, based on a rule base configuration that identifies the systems or devices to collect from, the file types, file names, file extensions, and related criteria based on file creation, file modification timestamps, permissions, or file sizes.
- the collection node also includes a cache module 414 having local memory resources to which the collector node passes retrieved files.
- the cache module 414 is configured to execute a hash function, such as MD5, SHA1, SHA2, etc., to uniquely identify each file received from the collector module 412. Once a file hash is computed, the cache module 414 performs a lookup of the hash in the cache memory to see if the file has been analyzed before. If the hash is found in the lookup procedure, then a response is provided, allowing the cache module to discard the currently queued file. Otherwise, the file hash is stored and the file is passed to an encoder module 416 for encoding. The operations of the cache module 414 prevents duplication of efforts by avoiding analyzing the same file more than once.
- a hash function such as MD5, SHA1, SHA2, etc.
- FIG. 5 is a schematic flow diagram of an exemplary embodiment of the flow of functions performed by the cache module 414 according to the present invention that can be used in the forensic analysis systems disclosed herein.
- artifacts received are input to a hash function 462, which, as noted, can be a standard hash function well-known in the art such as MD5, SHA1, SHA2.
- the hash is passed to a lookup function 464 which access memory cache 466 to determine if the hash has been generated previously.
- the memory cache can periodically load data to a cache database 468, which, in turn, can upload data to the central intelligence database 140.
- a response procedure 472 automatically generates a notification which is passed to the end users 10, 20.
- the notification can include text or other codes to inform the end users the ingested artifact has already been analyzed by the forensic system 400. If it is determined that the hash is new, the hash is stored 474 and the memory cache 466 is updated with an entry of the new hash.
- the encoding module 416 is configured to perform an encoding operation, such as simple byte level XOR based encoding with a key or utilizes any symmetric encryption algorithm with a key to encode the original file.
- the encoding allows the file to be transferred and stored without triggering alerts or active responses by system or network-based security apparatus or modules that detect out-of-policy files, malicious files, or patterns.
- the encoder module 416 passes the encoded file artifact to a queue module 417.
- the queue module 417 works in tandem with a transfer module 418.
- the queue module 417 temporarily stores the file artifact in a queue until the transfer module 418 de queues the file artifact and transfers it to a queue module 422 residing on the central node 420.
- the timing of the queuing and de-queuing is determined by the workflow pipeline. For example, when the queue module 422 of the central node 420 signals to the transfer module 418 of the collector node that it is ready to accept a new file artifact for processing, the transfer module 418 is prompted to upload the file artifact to the queue module.
- the file artifact is de-queued at the queue module 422 and then passed to a decoder module 424 for decoding.
- the decoder module 424 can decode the module using standard byte stream based XOR, with a symmetric or asymmetric key.
- cache module 426 analyzes the file for duplicates by lookup in a similar manner as the cache node 414 of the collection node. If the file artifact has not been analyzed, it is passed to an additional queue module 428.
- the file artifact is temporarily stored by queue module 428 until it is de-queued by the identifier module 432 of an analysis node 430 which is a component of the central node 420.
- the analysis node can be implemented using one or more separate computing devices coupled to the other parts of the central node 420 as shown, or may be implemented in the same computing device.
- the identifier module 432 is configured to parse the file artifact into a byte- stream and identifies it as a specific type of file with a specific format. Additionally, the identifier module 432 is configured to interrogate the file internally utilizing various methods such as byte-stream based“magic header” matching via tables of known file signatures, format indicators, machine and human linguistic syntax analysis to further analyze the file for various characteristics such as for strings (ASCII, Unicode, etc.) and embedded artifacts. These techniques are used to further identify embedded files, objects, streams, human and machine language, general executable byte-code patterns, and random or encrypted byte patterns that can be present in a file artifact. Identifications are stored in the central intelligence database 140.
- the artifact is passed to a recursive extractor 434 that extracts the embedded items from the artifact recursively.
- the recursive extractor 434 continues to break down the artifact into parts until all embedded portions have been extracted and no further meaningful data can be obtained from the original artifact (i.e., the artifact has been broken down into its minimal constituent elements).
- One way this can be determined is when an extraction steps yield the same artifacts and data as a previous extraction step, indicating that no further data can be yielded from the artifact.
- the items are extracted, they are passed through to a cache module which performs lookups to determine if the embedded artifacts have been previously analyzed.
- the embedded artifacts are delivered back to the identifier module 432 to continue the same analysis process.
- Results are stored or updated in the central intelligence database 140.
- each artifact file, object, stream, byte-code patterns
- it is passed to a metadata extractor 436 to further extract any additional metadata such as string patterns, byte-code patterns, magic identifiers, author, creation timestamps, modification timestamps, programming language syntax identification, human language identification, URL’s, emails, domains, IP addresses, MAC addresses, Geo-Location identifiers, phone numbers, physical addresses, etc.
- FIG. 6 is a schematic block diagram of an exemplary embodiment of an analyzer module 438 adapted for the embodiment of the analysis system shown in FIG. 4.
- the analyzer module 438 includes a plurality of analysis modules that can be used in series or in parallel to analyze artifacts and metadata.
- a signature matching module 442 is configured to statically identify the file as malicious using known malicious signatures.
- a heuristic matching module 444 is configured to perform heuristic analysis of the file based on rule-sets to identify it as malicious itself or an artifact known to be used by a known malicious entity.
- a machine learning module 446 is configured to execute one or more machine learning algorithms to classify and/or analyze the artifact.
- a deep learning module 448 is configured to execute one or more deep learning algorithms, such as neural networks, to further gain an understanding of the artifact and its relationship to closely related and other related and unrelated artifacts. All findings and results of the analysis modules 442-448 are passed to an intermediary processing module 450 and then to an in-memory cache 452 which is used for rapid memory access on an as-needed basis for lookup requests sent by the analysis modules (via the intermediary processing module 450). The data in the cache 452 is transmitted for storage in the central intelligence database 140 at set intervals.
- deep learning algorithms such as neural networks
- FIG. 7 depicts another embodiment of a system for forensic artifact analysis that employs a plurality of collector nodes and clusters of queue and analysis nodes to provide load balanced and simultaneous analysis for a large enterprise.
- the system 500 includes three enterprise segments 502, 504, 506, each comprises a plurality of computing resources. Segment 502 supplies artifacts to collector nodes 511 and 512. Segment 504 supplies artifacts to collector nodes 513 and 514, while segment 506 supplies artifacts to collector nodes 515 and 516.
- the collector nodes 511-516 can be similar to those described above. Collector nodes 511-516 send the collected file artifacts to a central queue cluster 520.
- the queue cluster can include a plurality of queue, decoder and cache modules that can each operate similarly to the modules 422-428 described above with respect to FIG. 4.
- the cluster of modules of the queue cluster 520 operate in parallel to process large request loads.
- the queue cluster queues requests for an analysis cluster 530 that includes a plurality of analysis nodes similar to the analysis node 430 described above.
- the plurality of analysis nodes in the analysis cluster 530 also operate in parallel to provide load balanced, simultaneous analysis of file artifacts to handle higher volumes of file artifacts.
- the analysis cluster 530 delivers analysis output to the central intelligence database 140.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Data Mining & Analysis (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mathematical Physics (AREA)
- Artificial Intelligence (AREA)
- Probability & Statistics with Applications (AREA)
- Evolutionary Computation (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Medical Informatics (AREA)
- Databases & Information Systems (AREA)
- Fuzzy Systems (AREA)
- Computational Linguistics (AREA)
- Bioinformatics & Computational Biology (AREA)
- Life Sciences & Earth Sciences (AREA)
- Bioinformatics & Cheminformatics (AREA)
- Evolutionary Biology (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/272,542 US20200259857A1 (en) | 2019-02-11 | 2019-02-11 | System and method for forensic artifact analysis and visualization |
| US16/272,542 | 2019-02-11 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020167552A1 true WO2020167552A1 (en) | 2020-08-20 |
Family
ID=69743958
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2020/016796 Ceased WO2020167552A1 (en) | 2019-02-11 | 2020-02-05 | System and method for forensic artifact analysis and visualization |
Country Status (2)
| Country | Link |
|---|---|
| US (1) | US20200259857A1 (en) |
| WO (1) | WO2020167552A1 (en) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR102690535B1 (en) * | 2019-05-28 | 2024-07-31 | 삼성에스디에스 주식회사 | Method and system for data security and apparatus for executing the same |
| US11188546B2 (en) * | 2019-09-24 | 2021-11-30 | International Business Machines Corporation | Pseudo real time communication system |
| US11425211B1 (en) | 2021-04-28 | 2022-08-23 | Red Hat, Inc. | Signing files via a publish-subscribe message service |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9224067B1 (en) * | 2012-01-23 | 2015-12-29 | Hrl Laboratories, Llc | System and methods for digital artifact genetic modeling and forensic analysis |
| US20160156658A1 (en) * | 2010-08-26 | 2016-06-02 | Verisign, Inc. | Method and system for automatic detection and analysis of malware |
| US20170251002A1 (en) * | 2016-02-29 | 2017-08-31 | Palo Alto Networks, Inc. | Malware analysis platform for threat intelligence made actionable |
| WO2017151515A1 (en) * | 2016-02-29 | 2017-09-08 | Palo Alto Networks, Inc. | Automatically grouping malware based on artifacts |
| US20190207966A1 (en) * | 2017-12-28 | 2019-07-04 | Fireeye, Inc. | Platform and Method for Enhanced Cyber-Attack Detection and Response Employing a Global Data Store |
-
2019
- 2019-02-11 US US16/272,542 patent/US20200259857A1/en not_active Abandoned
-
2020
- 2020-02-05 WO PCT/US2020/016796 patent/WO2020167552A1/en not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160156658A1 (en) * | 2010-08-26 | 2016-06-02 | Verisign, Inc. | Method and system for automatic detection and analysis of malware |
| US9224067B1 (en) * | 2012-01-23 | 2015-12-29 | Hrl Laboratories, Llc | System and methods for digital artifact genetic modeling and forensic analysis |
| US20170251002A1 (en) * | 2016-02-29 | 2017-08-31 | Palo Alto Networks, Inc. | Malware analysis platform for threat intelligence made actionable |
| WO2017151515A1 (en) * | 2016-02-29 | 2017-09-08 | Palo Alto Networks, Inc. | Automatically grouping malware based on artifacts |
| US20190207966A1 (en) * | 2017-12-28 | 2019-07-04 | Fireeye, Inc. | Platform and Method for Enhanced Cyber-Attack Detection and Response Employing a Global Data Store |
Also Published As
| Publication number | Publication date |
|---|---|
| US20200259857A1 (en) | 2020-08-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11347851B2 (en) | System and method for file artifact metadata collection and analysis | |
| US9430564B2 (en) | System and method for providing data protection workflows in a network environment | |
| US12063229B1 (en) | System and method for associating cybersecurity intelligence to cyberthreat actors through a similarity matrix | |
| US8635706B2 (en) | System and method for data mining and security policy management | |
| US10367786B2 (en) | Configuration management for a capture/registration system | |
| US9805099B2 (en) | Apparatus and method for efficient identification of code similarity | |
| US8918359B2 (en) | System and method for data mining and security policy management | |
| US20220277219A1 (en) | Systems and methods for machine learning data generation and visualization | |
| KR101868720B1 (en) | Compiler for regular expressions | |
| US12388866B2 (en) | Systems and methods for malicious URL pattern detection | |
| US20120054129A1 (en) | Method for classification of objects in a graph data stream | |
| US20070226510A1 (en) | Signature distribution in a document registration system | |
| US20070226504A1 (en) | Signature match processing in a document registration system | |
| US20220247763A1 (en) | Dynamic Computer Threat Alert System and Method | |
| WO2020167552A1 (en) | System and method for forensic artifact analysis and visualization | |
| US20220385675A1 (en) | System and methods for detecting malware adversary and campaign identification | |
| US8141149B1 (en) | Keyword obfuscation | |
| US12549599B2 (en) | System and method for intercepting and classifying suspicious text messages between user devices | |
| US20250328640A1 (en) | System and Method for Classifying Suspicious Text Messages Received by a User Device | |
| US20250071130A1 (en) | Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program | |
| US12360962B1 (en) | Semantic data determination using a large language model | |
| Jose et al. | Gigabit network intrusion detection system using extended Bloom filter in reconfigurable hardware | |
| US12323396B1 (en) | Network data decoding and encoding | |
| US12519822B1 (en) | Domain name system data exfiltration detection using machine learning techniques | |
| Ritchey | System Log File Reduction and Detection of Malicious Behavior |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20709425 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 11/11/2021) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20709425 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 521430014 Country of ref document: SA |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 521430014 Country of ref document: SA |
|
| WWR | Wipo information: refused in national office |
Ref document number: 521430014 Country of ref document: SA |