Hive Database Query System for Computer Investigations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional query languages for computer investigations are complex and difficult for non-programmers to understand and use, making it challenging to generate effective machine-readable search queries.
Innovation Solution
A system and method that utilize a structured database, referred to as a 'hive', which stores data as unique facts or links, and an enterprise query language (EQL) that allows for simple, human-readable search queries, enabling non-programmers to conduct computer investigations efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional query languages are used for computer investigations, then machine-readable search queries can be generated, but the queries become complex and difficult for non-programmers to understand and use
Solution Approach 1:
The patent introduces an intermediary layer between the user and the traditional query language. This intermediary automatically translates natural language or simplified queries into the complex traditional query language, shielding non-programmers from complexity while maintaining query accuracy. The system acts as a mediator that handles the translation and complexity management.
Solution Approach 2:
The patent creates a simplified copy or alternative representation of the query language that is easier to understand and use. Instead of requiring users to learn complex traditional query languages, the system provides a simplified interface that copies the essential functionality while using familiar, non-technical language that non-programmers can understand.
2Adaptability or versatility
If traditional query languages with multiple Boolean expressions and parenthesis are used, then comprehensive search capabilities are achieved, but the queries become hard for humans with little or no programming experience to interpret and understand
Solution Approach 1:
The patent segments the complex query language into simpler, more manageable components. By breaking down complex Boolean expressions with multiple levels of parenthesis into smaller, organized segments or modules, the system maintains comprehensive search capabilities while reducing the perceived complexity for users. Each segment can be understood and manipulated independently.
Solution Approach 2:
The patent changes the parameters of the query language interface by introducing new syntax rules or formatting standards that simplify the representation of complex queries. This might include changing how Boolean operations are expressed, how parenthesis are used, or introducing visual aids that make the query structure more interpretable for non-programmers.
Data Source
AI summary
A computer investigation system and method organize information in a hive. Information in a target device is parsed by a processor, and facts and links are extracted from the data. The processor identifies the fact type for each identified fact, and further generates a fact ID for the fact. The information for the fact is stored in the hive in a fact table associated with the fact type. The processor also identifies the link type for each identified link, and further generates a link ID for the link. The information for the link ID is stored in the hive in a link table associated with the identified link type. A query language that is adapted to work with the hive allows querying of data stored in the hive.


