Forensic Artifact Refining Module for Custom Data Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Forensic data investigation tools are limited in their ability to identify and extract custom artifacts, particularly those from new or proprietary software, as they are often pre-programmed for specific, widely-used types of data, and investigators may face challenges in specifying or sharing definitions due to security concerns.

Innovation Solution

The system allows users to create and apply custom artifact definitions, enabling extensibility of forensic data investigation tools without requiring new versions or developer involvement, by using refining modules that can be defined by end-users and stored in structured formats like XML or JSON.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If forensic data investigation tools are pre-programmed for specific, widely-used types of data, then the tools can reliably identify and extract common artifacts, but they cannot identify or extract custom artifacts from new or proprietary software

Engineering Contradiction:
Improveability to identify and extract common artifactsVSAvoidability to identify and extract custom artifacts
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transforms static, pre-programmed artifact definitions into dynamic, user-modifiable definitions. Investigators can now adapt the forensic tool by creating custom artifact definitions on-the-fly during investigations, allowing the system to evolve from rigid pre-programmed rules to flexible, dynamically configurable artifact identification capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables investigators to define their own custom artifacts without requiring developer intervention or new software versions. The tool serves itself by providing built-in mechanisms for users to create, modify, and manage artifact definitions independently, eliminating the need for external customization services.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If investigators specify custom artifact definitions, then the tools can identify diverse and proprietary artifacts, but investigators face challenges in sharing definitions due to security concerns

Engineering Contradiction:
Improveability to identify diverse and proprietary artifactsVSAvoidsecurity risks in sharing custom definitions
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary mechanism that allows secure sharing of custom artifact definitions. Instead of directly exposing sensitive definition data, the system uses structured formats (XML, JSON) that act as intermediaries, enabling safe transmission and exchange of artifact definitions while maintaining security controls and preventing unauthorized access to underlying investigative data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If forensic tools require new versions or developer involvement to add custom artifact types, then the core functionality remains stable and tested, but the tools lack extensibility and require significant time to adapt

Engineering Contradiction:
Improvestability of core functionalityVSAvoidtime and resources required to add new artifact types
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments artifact definition functionality from the core forensic tool executable. By separating custom artifact definitions into independent, configurable components (stored in structured formats), the system allows investigators to add new artifact types without modifying or re-releasing the core software, thereby maintaining stability while enabling extensibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal artifact definition framework that can accommodate multiple artifact types through a common structured format (XML/JSON). This multi-functional approach allows the same forensic tool to handle diverse artifact types—from traditional file system artifacts to custom proprietary formats—using a unified definition mechanism, eliminating the need for separate tool versions for each artifact type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12164573B2Systems and methods for collecting digital forensic evidence
Publication Date: 2024.12.10 MAGNET FORENSICS INVESTCO INC
  • US12164573B2 patent drawing
  • US12164573B2 patent drawing
  • US12164573B2 patent drawing

AI summary

Methods and apparatus for acquiring and analyzing digital forensic data using a computing device. Forensic data collections are retrieved by a computing device, and artifacts can be identified according to a variety of display types and presentation formats specified in an extensible format, to facilitate review and reporting by a user.