Digital Forensic Acquisition Kit for Automated Evidence Preservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer forensic tools face challenges in efficiently collecting and preserving digital evidence from active and non-active computer systems without altering timestamps or data, and there is a lack of economical solutions for identifying computer activity and evidence, especially in network-critical systems where invasive techniques can be detected.

Innovation Solution

A digital forensic acquisition kit that uses a bit-stream copy process for automated data collection and preservation, including pre-loaded software for autonomous data capture, and the option for a virtual machine file set for further examination, ensuring minimal data alteration and secure evidence handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated bit-stream copy process is used for data collection, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvedata collection efficiencyVSAvoidforensic tool complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The forensic acquisition tool is designed to automatically execute the bit-stream copy process without requiring user intervention. The system self-configures, self-executes, and self-validates the forensic image creation, maintaining high productivity while managing complexity through automation rather than manual procedures

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring the forensic environment, pre-validating storage capacity, and pre-establishing the bit-stream copy parameters before actual data acquisition begins. This prepares the system in advance to handle the complexity of automated forensic imaging

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If forensic analysis software is used to manage large volumes of computer data, then measurement precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata analysis accuracyVSAvoiduser operation difficulty
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system creates a precise bit-stream copy (forensic image) of the original storage device that maintains exact data integrity and timestamps. This copy can be analyzed without affecting the original evidence, achieving high measurement precision while simplifying operations by working with the replica rather than the original complex data structure

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The forensic analysis process is segmented into distinct automated stages: data acquisition, image creation, validation, and analysis. Each segment handles specific tasks independently, maintaining precision through specialized processing while reducing operational complexity by automating the transition between segments

Inventive Principle:
Principle #1Segmentation

3Loss of time

If automated imaging process is used for evidence collection, then loss of time is reduced, but reliability may be affected

Engineering Contradiction:
Improveevidence collection timeVSAvoidevidence integrity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The automated imaging process incorporates continuous feedback mechanisms including real-time validation of data transfer, cryptographic hash verification (MD5/SHA), and integrity checks throughout the acquisition process. This feedback ensures reliability is maintained even as the process is accelerated through automation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation checks before completing the forensic image creation, including verifying storage capacity, validating bit-stream copy accuracy, and confirming data integrity. These cushioning measures are built into the automated process to prevent errors while maintaining rapid evidence collection

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Ease of operation

If virtual machine file set is provided for customer examination, then ease of operation is improved, but loss of information may increase

Engineering Contradiction:
Improveevidence examination easeVSAvoiddata fidelity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The virtual machine file set is created as an exact bit-stream copy of the forensic image, preserving all original data, timestamps, and file structures. This copy enables customers to examine evidence in a familiar virtualized environment without risking alteration of the original forensic data, maintaining information fidelity while improving operational ease

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8656095B2Digital forensic acquisition kit and methods of use thereof
Publication Date: 2014.02.18 CYLANCE INC
  • US8656095B2 patent drawing
  • US8656095B2 patent drawing
  • US8656095B2 patent drawing

AI summary

Disclosed are compositions, methods, and kits, for issuing and conducting automated imaging and preservation for obtaining digital forensic data from active (i.e., powered-on) and non-active (i.e., powered-off) computer systems. In certain embodiments, the invention further encompasses providing a customer base a preliminary report of data. In other embodiments, the invention encompasses the option to receive a virtual machine file set of the acquired information for additional viewing and examination by the customer. The invention further encompasses methods and systems for implementing the embodiments of the invention. The invention also encompasses methods, apparatuses, and systems for secure forensic investigation of a target machine.