Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Digital forensics" patented technology

Digital forensics (sometimes known as digital forensic science) is a branch of forensic science encompassing the recovery and investigation of material found in digital devices, often in relation to computer crime. The term digital forensics was originally used as a synonym for computer forensics but has expanded to cover investigation of all devices capable of storing digital data. With roots in the personal computing revolution of the late 1970s and early 1980s, the discipline evolved in a haphazard manner during the 1990s, and it was not until the early 21st century that national policies emerged.

Graphical user interface forensic analysis method based on multi-modal large language model

The invention provides a graphical user interface forensic analysis method based on a multi-mode large language model, and belongs to the technical field of man-machine interaction, artificial intelligence safety and digital forensic. The method comprises the steps of evidence capture and distillation, semantic analysis and record generation, storage and indexing, and retrieval and inquiry. Through evidence capture and distillation, on the premise that evidence integrity is guaranteed, the visual data volume needing to be analyzed is greatly reduced, and long-term and efficient evidence obtaining analysis on a mobile terminal becomes possible; by introducing the analysis capability of a multi-modal large language model, original and structurality-free visual evidence is converted into a structuralization intelligent evidence which can be understood and deeply excavated; a designed two-stage natural language evidence obtaining query engine supports a complete analysis process from macroscopic semantic retrieval to microscopic detail inquiry; the problems that a traditional evidence obtaining method depends on manual troubleshooting and is low in efficiency are solved, and unprecedented high efficiency and convenience are provided for backtracking and auditing of mass interaction records.
Owner:PEKING UNIV +1

A network threat forensics method, program product, electronic device and storage medium

The embodiment of the application provides a network threat forensics method, a program product, an electronic device and a storage medium, and relates to the technical field of artificial intelligence. The method comprises the following steps: obtaining original data; preprocessing the original data to obtain an initial digital forensics report; detecting an abnormal event on the initial digital forensics report, and generating a text forensics file based on the abnormal event; performing event blocking and vector embedding on the text forensics file to obtain a vector file; receiving query information input by a user, and generating a forensics report based on the query information and the vector file. The method can automatically detect abnormal events and perform event blocking and vector embedding, can extract key information of the events, improves the efficiency and accuracy of threat forensics, and solves the problem of low efficiency of threat forensics in the prior art.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Techniques for system feedback in remediating cybersecurity risks

A system and method for initiating cybersecurity remediation based on a digital forensic finding is presented. The method includes detecting a forensic artifact on a disk of a resource in a computing environment; generating an inspectable disk based on the disk of the resource; inspecting the inspectable disk for a cybersecurity object based on the forensic artifact; and initiating a remediation action on the disk based on the cybersecurity object detected on the inspectable disk.
Owner:WIZ INC

Deep image inpainting tampering detection method based on adaptive tampering trace learning

The application discloses a deep image inpainting tampering detection method based on adaptive tampering trace learning, and belongs to the technical field of digital image forensics. The method first processes the input image by using an adaptive differential convolution module to suppress image content and enhance tampering traces; then, multi-scale and fine-grained features are extracted in parallel by a multi-scale hollow convolution module and a dense connection network; next, a neural network structure search module is used to automatically optimize the feature extraction path to adapt to diversified tampering types; then, a global and local double-branch attention enhancement module is used to fuse multi-level features and simultaneously improve the internal consistency and boundary accuracy of the tampering area; finally, a decoder module is used to output a pixel-level tampering area mask. The application can adaptively learn tampering features and maintain high precision and strong robustness under post-processing conditions such as JPEG compression, scaling, noise addition and the like, and is suitable for fields such as digital forensics and media content security.
Owner:JIANGXI POLICE COLLEGE +1

Application key extraction method and device, equipment, medium and program product

The invention discloses an application key extraction method and device, equipment, a medium and a program product, and relates to the technical field of digital forensics, and the method comprises the steps: obtaining database feature information of a target application and a key type of the target application, and reading target memory data of a process corresponding to the target application and attribute information of the process; determining a target memory block comprising the database feature information in the target memory data according to the attribute information of the process; and extracting the key of the target application according to the initial address of the database feature information in the target memory block and the key type of the target application. According to the embodiment of the invention, the application key extraction success rate is improved.
Owner:SUZHOU LONGXIN INFORMATION TECH CO LTD

A video decoding based pirated video provenance system

This invention relates to the fields of video processing, copyright protection, and digital forensics, specifically a pirated video tracing system based on video decoding. The system includes a data acquisition module, a status assessment module, a strategy decision-making module, and a tracing execution module. It acquires video stream data and decoding pipeline status data, calculates the computing power overdraft rate, and predicts the decoding failure probability. The system compares the decoding failure probability with a preset failure probability threshold to generate a downgraded tracing instruction or a regular tracing instruction. Based on this, it performs low-computing-power tracing feature extraction or deep tracing feature extraction on the video stream data, and sends the obtained target tracing features to a tracing comparison terminal for comparison, outputting the tracing location result. This invention achieves a balance between tracing tasks and decoding stability, and reduces the risk of playback failure caused by continuous tracing operation.

Containers-Based Forensics for Persistent and Stateless Containers

Comprehensive systems and methods for conducting digital forensics and incident response in containerized computing environments. The system converts stateless containers into persistent containers to prevent automatic termination during forensic investigations. It quarantines the containers using virtual switches and firewalls, captures detailed forensic data including snapshots of all filesystem layers, kernel syscalls, and process data, and mirrors network traffic for secure analysis. The system retrieves logs and artifacts from current and previous nodes, correlates and compares this data using machine learning algorithms, and securely duplicates all artifacts to immutable storage. Automated orchestration ensures consistent execution of forensic processes, and the system reverts containers to their original stateless state post-investigation. A detailed audit log and secure archival of all forensic data are maintained for future reference or legal compliance. The invention addresses the unique challenges of securing and analyzing data in dynamic, distributed containerized environments.
Owner:BANK OF AMERICA CORP

Device and method for collecting, analyzing and integrating log data of in-vehicle infotainment systems

A device and a method for collecting, analyzing and integrating log data of an in-vehicle infotainment (IVI) system are disclosed. The method for collecting, analyzing and integrating log data of an IVI system includes identifying model information of a vehicle to be a target of digital forensics, hardware information and software information related to the IVI system of the vehicle, collecting target data for the digital forensics based on the model information, the hardware information and the software information, and storing the collected target data in an integrated database.
Owner:IND ACADEMIC COOP FOUND YONSEI UNIV

Document tampering detection method based on dynamic kernel fusion and adaptive gradient modulation

ActiveCN121999502AAccurately capture frequencyAccurately capture subtle tampering differencesNeural learning methodsVisual technologyFeature extraction
The invention relates to a document tampering detection method based on dynamic kernel fusion and adaptive gradient modulation, and belongs to the technical field of digital forensics and computer vision. The method comprises the following steps: obtaining an RGB image of a to-be-detected document, constructing a feature encoder containing a double-branch feature extraction and feature updating module, taking ConvNeXt V2-Base as a backbone, combining visual and frequency domain features with a cross-domain feature calibration module, and obtaining optimized multi-scale features through learnable wavelet decomposition; a frequency domain adaptive feature decoder is constructed, dynamic kernel fusion is completed through Fourier frequency band grouping weight, kernel element precise modulation and space-frequency band dynamic matching, and a tampering prediction map is output; and during training, joint optimization of adaptive gradient cosine loss, cross entropy loss and LoWitz loss is adopted. According to the method, the frequency abnormity and tiny traces of document tampering can be accurately captured, the problem of class imbalance is effectively relieved, and the method has high detection precision and robustness in different compression scenes.
Owner:TIANJIN UNIVERSITY OF TECHNOLOGY +1

Cryptographic algorithm and operation mode classification method and system based on BCAM-LGST model

The invention discloses a cryptographic algorithm-mode classification method and system based on a BCAM-LGST model, and belongs to the technical field of information security and cryptographic analysis. Comprising the following steps: converting an original ciphertext into a fixed-length sequence and a grayscale image in parallel, and constructing complementary bimodal data representation; the method comprises the following steps: extracting high-level probability features of a sequence by adopting a LightGBM model as semantic priori, and carrying out cross-modal depth fusion on a priori-guided hierarchical dual-channel gating modulation mechanism and image structure features extracted by Swin Transform; and introducing spatial position association of a spatial perception enhancement matrix enhancement feature, and carrying out multi-scale feature modeling on a fusion feature under prior guidance by using layered window attention, so as to finally realize end-to-end joint classification. The block cipher algorithm-mode joint identification method can quickly, accurately and robustly realize block cipher algorithm-mode joint identification, and is suitable for practical engineering scenes such as network security level protection, cipher application security evaluation, digital forensics, encrypted traffic analysis and compliance auditing.
Owner:NINGXIA UNIVERSITY

Method and apparatus for data analysis processing of heterogeneous ship navigation based on digital forensics

An apparatus for analyzing and handling heterogeneous navigation data includes an evidence collection unit that collects evidence material relating to an accident; an evidence data analysis unit that verifies the integrity of the collected evidence material, and if the collected evidence material is collected from a plurality of manufacturers' equipment models, restores navigation data by analyzing evidence data relating to the collected evidence material; an integrated navigation data handling unit that generates an evidence-based integrated navigation pattern for different forms of navigation data, including original information, information on relevance to the original information, and an evidential material for extraction to be used as evidence, and stores the integrated navigation pattern in a standard format; and an accident reconstruction analysis management unit that simultaneously presents multiple pieces of heterogeneous data by layering the integrated navigation pattern, and reconstructs and analyzes the accident for each time slot of each track.
Owner:ELECTRONICS & TELECOMM RES INST

Image tampering positioning method based on edge guidance and multi-scale feature fusion

The invention discloses an image tampering positioning method and system based on edge guidance and multi-scale feature fusion. The method comprises the following steps: firstly, constructing a deep learning framework based on a Vision Transformer (ViT) backbone network, and realizing efficient modeling of local and global tampering features in an image in combination with a content awareness residual module; in order to improve the accuracy and robustness of tampering region detection, an edge guiding strategy is designed, and the strategy combines a Sobel operator, morphological operation and an edge segmentation loss function to reinforce tampering boundary feature expression, so that the sensitivity to an unnaturally fused region is improved. The invention further provides a multi-scale supervision mechanism, a coordinate attention module is combined, the model is guided to fuse semantic features under different scales, and the adaptive detection capability of the model on tampering regions with different scales is enhanced. In the implementation process, in the training stage, the detection performance of the model on image tampering is gradually improved by optimizing all modules of the deep learning network; and then, inputting an image to be detected by using the trained network, and automatically identifying and positioning a tampering region in the image. The method can effectively detect and position the tampering area of the image, has a wide application prospect, and can provide a more reliable and efficient image tampering detection solution especially in the fields of digital forensics, image content security and the like.
Owner:CENTRAL SOUTH UNIVERSITY OF FORESTRY AND TECHNOLOGY

Method for detecting document tampering based on dynamic nuclear fusion and adaptive gradient modulation

ActiveCN121999502BVisual technologyRgb image
The present application relates to a kind of based on dynamic nuclear fusion and adaptive gradient modulation document tampering detection method, belong to digital forensics and computer vision technical field.It includes the following steps: obtaining the RGB image of the document to be detected, constructs the feature encoder containing double-branch feature extraction and feature update module, with ConvNeXt V2-Base as backbone, fusion visual and frequency domain features are combined with cross-domain feature calibration module, and optimized multi-scale feature is obtained by learnable wavelet decomposition;Frequency domain adaptive feature decoder is then constructed, dynamic nuclear fusion is completed by Fourier band grouping weight, kernel element accurate modulation and space-band dynamic matching, and tampering prediction map is output;Adaptive gradient cosine loss, cross-entropy loss and lovasz loss are used during training Joint optimization.The present application can accurately capture the frequency anomaly and subtle traces of document tampering, effectively alleviate the class imbalance problem, and has high detection accuracy and robustness under different compression scenarios.
Owner:TIANJIN UNIVERSITY OF TECHNOLOGY +1

A method and system for detecting rumors on social media based on the BLRQ-BV model

This invention discloses a method and system for detecting social media rumors based on the BLRQ-BV model, belonging to the technical field of social media content security and information authenticity identification. It includes: encoding each rumor event as a whole into a text modality and a grayscale image modality, constructing a bimodal data representation that maintains semantic integrity; using a BiLSTM network to extract sequence features from the text, employing a specially designed low-discrimination-information-loss quantum hybrid network LIL-QHN to extract quantum features from the text, and using a ResNet-18 network to extract visual structural features from the grayscale image; losslessly fusing the three modal features through an innovative spherical spatial vector synthesis method VC-BS, preserving the feature strength and directional relationships; and introducing a joint loss function to collaboratively optimize each branch, ultimately achieving end-to-end rumor detection. This invention can robustly achieve automatic identification of social media rumors and is applicable to scenarios such as network content security management, public opinion monitoring and early warning, and digital forensics.
Owner:NINGXIA UNIVERSITY

Audio and video counterfeit segment time sequence positioning method and system

PendingCN122640583AMediaFLOEngineering
The present application relates to a kind of audio and video counterfeit segment timing positioning method and system, facing audio and video depth counterfeit content analysis scene, video modal feature and audio modal feature are jointly modeled, and through hierarchical timing coding, multiscale feature fusion, candidate quality evaluation and boundary positioning processing, the automatic positioning of the start time of counterfeit segment is realized.The present application is deployed in general electronic equipment by program mode, for audio and video content review, media authenticity verification, digital forensics analysis and related content security scene, the present application can improve candidate sorting reliability and boundary positioning precision, improve the positioning precision of counterfeit segment in short time local scene and candidate sorting quality.
Owner:TIANJIN UNIV

Model copyright evidence obtaining and authority control method based on multi-party cooperation

The invention belongs to the technical field of information security and digital forensics, and particularly relates to a multi-party cooperation-based model copyright forensics and authority control method, which comprises the steps of binary copyright information generation, share segmentation and image mapping, trigger distribution, trigger mechanism embedding, forensics image output and copyright information reconstruction. By introducing a share management and threshold control mechanism of multi-party cooperation, single-party abuse and single-point leakage are effectively prevented, the safety and credibility of the copyright verification process are improved, and the method is suitable for complex scenes such as joint development, cross-organization cooperation and judicial evidence collection.
Owner:SICHUAN POLICE COLLEGE +1

Face changing defense method and device for black box face operation model

The application discloses a face changing defense method and device for a black box face operation model, belongs to the technical field of digital forensics active defense, and relates to a face changing defense method for a black box face operation model, which adds adversarial disturbance to a source face image of a target object through a pre-trained proxy operation model, and generates an adversarial image with the adversarial disturbance, so that the black box face operation model generates a generated image different from the identity content of the source face image of the target object according to the adversarial image, the generation process of the black box face operation model is disturbed, malicious operation of the black box face operation model is prevented, and the problem of poor generalization performance of the face changing operation defense for the black box face operation model is solved.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

A diffusion model-oriented digital watermark embedding and detection method and system

This invention belongs to the field of information security and digital forensics technology, and relates to a method and system for digital watermark embedding and detection based on diffusion models. This method does not require modification of the network structure and model parameters of the diffusion model, nor does it require additional training of any detection or discrimination model. Instead, it embeds multi-bit watermark information intrinsically into the initial latent noise of the diffusion model, enabling the generated image to naturally carry detectable, extractable, and traceable identification information during the generation stage. Diffusion models typically assume that the initial latent variables follow a standard normal distribution when generating images. This invention, while maintaining the consistency of this statistical distribution, encodes the binary information to be traced as a weak frequency domain structural perturbation in the latent variables, and gradually integrates this perturbation with the image semantics during diffusion sampling and multi-step denoising. This achieves effective detection and tracing of the source of the generated image without reducing the visual quality and diversity of the generated image.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Containers-based forensics for persistent and stateless containers

Comprehensive systems and methods for conducting digital forensics and incident response in containerized computing environments. The system converts stateless containers into persistent containers to prevent automatic termination during forensic investigations. It quarantines the containers using virtual switches and firewalls, captures detailed forensic data including snapshots of all filesystem layers, kernel syscalls, and process data, and mirrors network traffic for secure analysis. The system retrieves logs and artifacts from current and previous nodes, correlates and compares this data using machine learning algorithms, and securely duplicates all artifacts to immutable storage. Automated orchestration ensures consistent execution of forensic processes, and the system reverts containers to their original stateless state post-investigation. A detailed audit log and secure archival of all forensic data are maintained for future reference or legal compliance. The invention addresses the unique challenges of securing and analyzing data in dynamic, distributed containerized environments.
Owner:BANK OF AMERICA CORP

Digital forensics access and extraction

In one example, a system comprises a digital forensic access device executing instructions to install an access agent on a target device and to replace the access agent with an extraction agent after the access agent locates and copies data in the target device into a data structure; and a computing device running an extraction server comprising instructions to store a copy of the data structure in storage and to remove the extraction agent from the target device.
Owner:MAGNET FORENSICS LLC

Computer system and method for mobile device digital forensic investigations

A system and method for providing a visual representation of content contained on a mobile device is provided herein. the system comprises a data collection module for detecting an operating system of a mobile device and collecting device data from the mobile device, an application filtering module for searching the device data for applications and determining an application type for each of the applications; a data filtering module for filtering the device data based on the applications to determine device data associated with each of the applications, and a graphical user interface (GUI) generation module for generating a first GUI which mimics an operating system of the mobile device and includes graphical icons for the applications, and generating a second GUI upon selection of a graphical icon of one of the plurality of applications, wherein the second GUI displays the device data associated with the selected application.
Owner:MAGNET FORENSICS INC

Digital forensic image verification system

A digital forensic image verification system according to an embodiment of the present disclosure includes an imaging device having a imaging unit configured to produce an image, a first hash value generator configured to generate a first hash value for the image, and a transmitting unit configured to transmit the image and the first hash value; and an image storage device having a receiving unit configured to receive the image and the first hash value from the imaging device, a second hash value generator configured to generate a second hash value for the image, and a controller configured to compare the first hash value and the second hash value with each other.
Owner:4DREAM +1