IP Library Granted Patent US 11,698,828
Granted Patent B2
US 11,698,828 · App. 17/396,905 · Granted Jul 11, 2023

Systems and methods for cross-referencing forensic snapshot over time for root-cause analysis

Inventors: Nikolay Grebennikov (Sofia, BG); Candid Wüest (Basserdorf, CH); Serguei Beloussov (Costa del Sol, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F11/079G06F11/0754G06F11/0781G06F11/1451G06F11/1453G06F11/1469G06F2201/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,698,828
App. No.
17/396,905
Granted
Jul 11, 2023
Kind
B2
Abstract

Aspects of the disclosure describe methods and systems for cross-referencing forensic snapshots over time. In one exemplary aspect, a method may comprise receiving a first snapshot of a computing device at a first time and a second snapshot of the computing device at a second time and applying a pre-defined filter to the first snapshot and the second snapshot, wherein the pre-defined filter includes a list of files that are to be extracted from each snapshot. The method may comprise subsequent to applying the pre-defined filter, identifying differences in the list of files extracted from the first snapshot and the second snapshot. The method may comprise creating a change map for the computing device that comprises the differences in the list of files over a period of time, wherein the period of time comprises the first time and the second time, and outputting the change map in a user interface.

Claims (55)

1. A method for cross-referencing forensic snapshots over time, the method comprising:

receiving a first snapshot of a computing device at a first time and a second snapshot of the computing device at a second time;

applying a pre-defined filter to the first snapshot and the second snapshot, wherein the pre-defined filter includes a list of files that are to be extracted from each snapshot;

subsequent to applying the pre-defined filter, identifying differences in the list of files extracted from the first snapshot and the second snapshot;

creating a change map for the computing device that comprises the differences in the list of files over a period of time, wherein the period of time comprises the first time and the second time;

outputting the change map in a user interface, wherein the change map indicates changes made by the user and changes made by an unauthorized entity; and

filtering the change map to not show the changes made by the user.

2. The method of claim 1 , further comprising:

receiving a third snapshot of the computing device at a third time;

applying the pre-defined filter to the third snapshot;

identifying differences in the list of files extracted from the second snapshot and the third snapshot;

modifying the change map for the computing device to further include differences in the list of files at the third time, wherein the period of time further comprises the third time.

3. The method of claim 2 , wherein the differences in the list of files at the third time is relative to the second time.

4. The method of claim 2 , wherein the differences in the list of files at the third time is relative to the first time.

5. The method of claim 1 , wherein the change map is visually outputted in a user interface as a timeline with a plurality of selectable time points each representing a snapshot of the computing device, further comprising:

receiving a selection of a time point; and

generating a window with respective differences between a filtered snapshot associated with the time point and a prior filtered snapshot.

6. The method of claim 5 , wherein the time point selected is the second time associated with the second snapshot, and wherein the window presents the differences in the list of files extracted from the first snapshot and the second snapshot.

7. The method of claim 5 , wherein the window is interactive and presents drill-down analysis for each file in the respective differences.

8. The method of claim 1 , wherein outputting the change map in the user interface is in response to detecting an error in the computing device.

9. The method of claim 8 , wherein outputting the change map further comprises transmitting an alert to a forensic investigation entity, wherein the alert comprises access to the change map.

10. The method of claim 1 , wherein filtering the change map to not show the changes made by the user comprises:

classifying each change in the change map using a machine learning algorithm trained on a dataset that indicates a plurality of changes and an identifier of an entity that executed each of the plurality of changes.

11. The method of claim 1 , further comprising:

retrieving, for the first snapshot and the second snapshot, metadata that indicates states of the computing device at the first time and the second time;

determining a first performance score based on a state of the computing device at the first time and a second performance score based on a state of the computing device at the second time;

determining a change differential between the first performance score and the second performance score; and

marking a time point in the change map if the change differential is greater than a threshold change differential.

12. A system for cross-referencing forensic snapshots over time, the system comprising:

a hardware processor configured to:

receive a first snapshot of a computing device at a first time and a second snapshot of the computing device at a second time;

apply a pre-defined filter to the first snapshot and the second snapshot, wherein the pre-defined filter includes a list of files that are to be extracted from each snapshot;

subsequent to applying the pre-defined filter, identify differences in the list of files extracted from the first snapshot and the second snapshot;

create a change map for the computing device that comprises the differences in the list of files over a period of time, wherein the period of time comprises the first time and the second time;

output the change map in a user interface, wherein the change map indicates changes made by the user and changes made by an unauthorized entity; and

filter the change map to not show the changes made by the user.

13. The system of claim 12 , wherein the hardware processor is further configured to:

receive a third snapshot of the computing device at a third time;

apply the pre-defined filter to the third snapshot;

identify differences in the list of files extracted from the second snapshot and the third snapshot;

modify the change map for the computing device to further include differences in the list of files at the third time, wherein the period of time further comprises the third time.

14. The system of claim 13 , wherein the differences in the list of files at the third time is relative to the second time.

15. The system of claim 13 , wherein the differences in the list of files at the third time is relative to the first time.

16. The system of claim 12 , wherein the change map is visually outputted in a user interface as a timeline with a plurality of selectable time points each representing a snapshot of the computing device, wherein the hardware processor is further configured to:

receive a selection of a time point; and

generate a window with respective differences between a filtered snapshot associated with the time point and a prior filtered snapshot.

17. The system of claim 16 , wherein the time point selected is the second time associated with the second snapshot, and wherein the window presents the differences in the list of files extracted from the first snapshot and the second snapshot.

18. The system of claim 16 , wherein the window is interactive and presents drill-down analysis for each file in the respective differences.

19. A non-transitory computer readable medium storing thereon computer executable instructions for cross-referencing forensic snapshots over time, including instructions for:

receiving a first snapshot of a computing device at a first time and a second snapshot of the computing device at a second time;

applying a pre-defined filter to the first snapshot and the second snapshot, wherein the pre-defined filter includes a list of files that are to be extracted from each snapshot;

subsequent to applying the pre-defined filter, identifying differences in the list of files extracted from the first snapshot and the second snapshot;

creating a change map for the computing device that comprises the differences in the list of files over a period of time, wherein the period of time comprises the first time and the second time;

outputting the change map in a user interface, wherein the change map indicates changes made by the user and changes made by an unauthorized entity; and

filtering the change map to not show the changes made by the user.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENTS LISTED BY DELETING PATENT APPLICATION NO. 18388907 FROM SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 66797 FRAME 766. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 13, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 069594/0136 →
SECURITY INTEREST Recorded Mar 14, 2024
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 066797/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2023
From: GREBENNIKOV, NIKOLAY; WÜEST, CANDID; BELOUSSOV, SERGUEI; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 063771/0200 →