Distributed Forensic Analysis with Virtual Disk Imaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional forensic analysis in enterprise environments faces challenges in efficiently managing and analyzing data from multiple machines, particularly in scaling investigations to a large number of devices while maintaining evidentiary standards and minimizing response time.

Innovation Solution

A distributed forensic analysis system that uses a management device to communicate with client agents, allowing for serialized process flows to be suspended and resumed, with responses processed by workers in queues, enabling concurrent management of multiple devices and dynamic task dispatching to conserve resources and preserve privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional forensic acquisition methods are used (shutting down machines and manually copying drives), then evidentiary standards are maintained, but the investigation process becomes time-consuming and difficult to scale to large numbers of devices

Engineering Contradiction:
Improveevidentiary standardsVSAvoidinvestigation response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual copy (virtual machine) of the target device's disk state instead of physically copying the drive. The forensics engine generates a virtual disk image that can be analyzed without shutting down the actual device, maintaining evidentiary integrity while enabling concurrent analysis of multiple devices

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical process of physically shutting down devices and manually copying drives with an automated software-based forensics engine that can remotely create virtual disk images and analyze them programmatically, eliminating the need for manual intervention and enabling parallel processing

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual analysis of drive images is performed, then detailed forensic examination is possible, but the process cannot be scaled to analyze data from many machines concurrently

Engineering Contradiction:
Improveforensic analysis detailVSAvoidnumber of devices analyzed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The forensics engine performs automated analysis of virtual disk images without requiring manual intervention for each device. The system self-manages the creation, analysis, and correlation of forensic data from multiple devices, enabling scalable concurrent analysis while maintaining detailed examination capabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent divides the forensic analysis process into separate modular components: virtual machine creation, disk imaging, data analysis, and result correlation. Each component can process multiple devices independently and concurrently, allowing the system to scale analysis to large numbers of devices while maintaining detailed examination through the modular architecture

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If forensic analysis requires physical access and device shutdown, then complete control over the analysis process is achieved, but resource consumption increases and remote analysis becomes difficult

Engineering Contradiction:
Improvecontrol over analysis processVSAvoidcomputational resources
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent introduces a virtual machine as an intermediary layer between the forensics engine and the target device. The virtual machine captures disk state and presents it to the analysis engine, enabling remote forensic analysis without requiring physical access or device shutdown, while the engine maintains complete control through the virtualization interface

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy of the disk state that can be analyzed remotely without consuming the physical resources of the target device. This virtual copy enables the forensics engine to perform comprehensive analysis while the actual device continues to operate, reducing resource contention and enabling remote operation

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9191298B1Distributed forensic investigation
Publication Date: 2015.11.17 GOOGLE LLC
  • US9191298B1 patent drawing
  • US9191298B1 patent drawing
  • US9191298B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for distributed forensics analysis. In one aspect, a method includes sending one or more requests to a client as part of a serialized flow for performing forensics analysis associated with the client; suspending the serialized flow at a first state; receiving responses to the one or more requests; resuming the flow at the first state to process the received responses; and advancing the serialized flow to a second state.