Automated Forensic Data Collection System for Selective Evidence Acquisition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Historically, collecting forensic data from a target computer requires capturing the entire hard drive, leading to substantial storage capacity demands, especially when data needs to be acquired frequently, resulting in significant growth and space requirements.

Innovation Solution

A system and method for automated collection of user-specified forensic data, which includes providing a user interface to select a target computer, specify data types, create subfolders for storage, connect to the target computer, scan for the Operating System, and collect specified data, thereby reducing storage needs and administrative work.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the entire hard drive is captured for forensic data collection, then complete forensic evidence is obtained, but storage capacity requirements become substantial

Engineering Contradiction:
Improvecompleteness of forensic evidenceVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the relevant forensic data from the target computer system rather than capturing the entire hard drive. The software module allows users to selectively specify and collect only the types of forensic data needed for the investigation, separating necessary evidence from unnecessary data and significantly reducing storage requirements while maintaining evidentiary completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the forensic data collection process into selectable categories and types. Users can choose specific data types to collect from different user profiles on the target computer, dividing the monolithic approach of full hard drive capture into modular, manageable segments that can be stored and processed efficiently.

Inventive Principle:
Principle #1Segmentation

2Productivity

If full hard drive data is collected frequently, then comprehensive forensic analysis is enabled, but administrative burden increases significantly

Engineering Contradiction:
Improvefrequency of data acquisitionVSAvoidadministrative work
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the software module automatically manages the forensic data collection process. Once users specify the types of data needed and select target computers, the system automatically connects, scans, identifies the operating system, collects the specified forensic data, and saves it to appropriate locations without requiring manual administrative intervention for each collection task.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal software module that handles multiple functions within a single automated process: user interface management, target computer selection, data type specification, automatic connection establishment, OS detection, data collection, and file saving. This multi-functional approach consolidates numerous administrative tasks into one unified tool.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9680844B2Automation of collection of forensic evidence
Publication Date: 2017.06.13 BANK OF AMERICA CORP
  • US9680844B2 patent drawing
  • US9680844B2 patent drawing
  • US9680844B2 patent drawing

AI summary

Embodiments of the invention are directed to systems, methods and computer program products for automated collection of user-specified forensic data from a target computer associated with a case. In particular, embodiments herein disclosed provide for a system that is configured to provide a user interface to allow a user to select a target computer within a network, select one or more user profiles associated with the target computer, and specify one or more types of forensic data to be collected from the target computer. The system is also configured to create a subfolder in a folder linked to the case and one or more files in the subfolder for storing the user-specified data; connect the computer apparatus to the target computer; and collect the specified data and save the collected data to the files.