Endpoint Data Acquisition Agent for Offline Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for remote data acquisition from computing devices on shared networks require the device of interest to be online, making it difficult to access data from globally distributed employees or suspects, especially in cases where physical access is limited.
Innovation Solution
A system and method involving an examiner device that deploys an executable agent to a target endpoint system to establish a connection, request, and transfer targeted data, which includes logical or binary copies, memory, and live system information, allowing data acquisition even when the device is not connected to the network, with automatic reconnection and viability signaling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If current remote data acquisition systems are used, then data can be accessed from shared networks, but the target device must be online which limits access to globally distributed devices
Solution Approach 1:
The system performs preliminary actions by deploying data acquisition agents to target devices in advance. These agents are installed on the remote devices before data acquisition is needed, allowing the system to bypass the requirement for devices to be online during data collection. The agents remain dormant or active on the devices, ready to transmit data when contacted by the central server.
Solution Approach 2:
The patent introduces intermediary components including data acquisition agents on target devices and a central server that coordinates communication. These intermediaries enable indirect data access by having the agent on the remote device communicate with the central server, which then provides the data to investigators, eliminating the need for direct connection to the target device during data retrieval.
2Reliability
If agents are deployed to target endpoint systems, then targeted data can be acquired without requiring the device to be online, but the system complexity increases
Solution Approach 1:
The system segments the data acquisition function into separate components: data acquisition agents deployed on individual target devices and a central server that coordinates and collects data. This segmentation allows each component to operate independently, improving reliability by isolating failures to individual devices while simplifying the overall management through the centralized server.
Solution Approach 2:
The data acquisition agents operate autonomously on target devices, performing self-service functions by monitoring local systems, collecting requested data, and automatically transmitting it to the central server when connected. This self-service capability reduces the need for manual intervention and complex centralized control, balancing autonomy with manageable system complexity.
Data Source
AI summary
A computer system, method, and device perform targeted acquisition of data. The system includes an examiner device having a processor and a memory, an agent in the form of an executable program for finding and transferring targeted data, and a target endpoint system. The examiner device is configured to deploy the agent to the target endpoint system. The agent is configured to establish a connection with the examiner device. The examiner device is configured to send a request for targeted data to the agent. The agent is configured to locate the targeted data on the target endpoint system. The agent is configured to transfer the targeted data to the examiner device.


