IP Library Granted Patent US 11,080,392
Granted Patent B2
US 11,080,392 · App. 16/508,103 · Granted Aug 3, 2021

Method for systematic collection and analysis of forensic data in a unified communications system deployed in a cloud environment

Inventors: Juan Carlos Bennett (Temecula, CA); Mamadou H. Diallo (Santee, CA)
Assignee: United States of America as Represented by the Secretary of the Navy
G06F21/552G06F16/1734G06F21/554G06F21/566G06F21/567
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,392
App. No.
16/508,103
Filed
Jul 10, 2019
Granted
Aug 3, 2021
Kind
B2
Examiner
ZEE, EDWARD
Art Unit
2435
USPC
726/23
Abstract

A method for systematic collection and analysis of forensic data in a unified communications system deployed in a cloud environment. Three primary forensic components, namely, evidence collectors, a forensic controller and self-forensic investigators, are utilized in the method to interface with the components of the cloud environment and of the unified communications network. The method invokes a cloud evidence collection process which collects footprint data structures continuously at runtime to enable effective real-time collection of cloud forensic evidence and a cloud evidence analyzing process which generates evidence data that can be consumed by standard forensics tools.

Claims (31)

1. A method for systematic collection and analysis of data in a unified communications system deployed in a cloud environment, comprising the steps of:

integrating at least one evidence collection mechanism with the unified communications system, wherein said at least one evidence collection mechanism is operative to capture forensic data related to operation of the unified communications system and at least one component in the cloud environment;

generating at least one model which captures the normal behavior of the unified communications system;

monitoring, by at least one intrusion detection system, the unified communications system for an occurrence of an unauthorized action using captured said forensic data and the at least one model;

upon the occurrence of an unauthorized action, transmitting, by said at least one intrusion detection system, an alarm to a forensic controller;

upon the transmission of the alarm to said forensic controller, collecting, by said at least one evidence collection mechanism, said forensic data;

building, by said forensic controller, at least one footprint data structure from the collected forensic data;

formatting said at least one footprint data structure, wherein the step of formatting enables said at least one footprint data structure to be used by at least one forensics software application tool;

generating at least one self-forensic investigator for use to detect any malicious behavior in the unified communications system, wherein said at least one self-forensic investigator is generated using said at least one footprint data structure; and

alerting, by said at least one self-forensic investigator, said forensic controller upon the detection of any malicious behavior in the unified communications system.

2. A method for systematic collection and analysis of data in a unified communications system deployed in a cloud environment, comprising the steps of:

integrating at least one evidence collection mechanism with the unified communications system, wherein said at least one evidence collection mechanism is operative to capture forensic data related to operation of the unified communications system and at least one component in the cloud environment;

generating at least one model which captures the normal behavior of the unified communications system;

monitoring, by at least one intrusion detection system, the unified communications system for an occurrence of an unauthorized action using captured said forensic data and the at least one model;

upon the occurrence of an unauthorized action, transmitting, by said at least one intrusion detection system, an alarm to a forensic controller, wherein said forensic controller is operatively connected to but physically and logically separate from the cloud environment;

upon the transmission of the alarm to said forensic controller, collecting, by said at least one evidence collection mechanism, said forensic data;

building, by said forensic controller, at least one footprint data structure from the collected forensic data;

formatting said at least one footprint data structure, wherein the step of formatting enables said at least one footprint data structure to be used by at least one forensics software application tool;

generating at least one self-forensic investigator for use to detect any malicious behavior in the unified communications system, wherein said at least one self-forensic investigator is generated using said at least one footprint data structure; and

alerting, by said at least one self-forensic investigator, said forensic controller upon the detection of any malicious behavior in the unified communications system.

3. A method for systematic collection and analysis of data in a unified communications system deployed in a cloud environment, comprising the steps of:

integrating at least one evidence collection mechanism with the unified communications system, wherein said at least one evidence collection mechanism is attached to at least one component in the cloud environment and operative to capture forensic data related to operation of the unified communications system and the at least one component the cloud environment;

generating at least one model which captures the normal behavior of the unified communications system;

monitoring, by at least one intrusion detection system, the unified communications system for an occurrence of an unauthorized action using captured said forensic data and the at least one model;

upon the occurrence of an unauthorized action, transmitting, by said at least one intrusion detection system, an alarm to a forensic controller, wherein said forensic controller is operatively connected to but physically and logically separate from the at least one component in the cloud environment;

upon the transmission of the alarm to said forensic controller, collecting, by said at least one evidence collection mechanism, said forensic data;

storing, by said forensic controller, collected forensic data in an evidence database that is operatively connected to but physically and logically separate from the at least one component in the cloud environment;

building, by said forensic controller, at least one footprint data structure from the collected forensic data; and

formatting said at least one footprint data structure, wherein the step of formatting enables said at least one footprint data structure to be used by at least one forensics software application tool;

generating at least one self-forensic investigator for use to detect any malicious behavior in the unified communications system, wherein said at least one self-forensic investigator is generated using said at least one footprint data structure; and

alerting, by said at least one self-forensic investigator, said forensic controller upon the detection of any malicious behavior in the unified communications system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2019
From: DIALLO, MAMADOU H.
To: UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY
Reel/Frame 050361/0826 →
Continuity (1)
Related Publication 20210011999A1 · Jan 14, 2021
Cited By (14)
US 12,267,345 US 12,309,185 US 12,323,449 US 12,348,545 US 12,355,793 US 12,418,555 US 12,489,771 US 12,556,559 US 12,563,071 US 12,592,950 US 12,621,324 US 12,652,302 US 12,689,640 US 12,719,896