Metadata Extraction for Forensic Analysis of Stolen Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data centers face challenges in quickly identifying the content and potential impact of stolen hardware containing confidential data, as well as determining the owner of such data, due to the difficulty in monitoring physical theft and unauthorized access, which can lead to data exposure and compromise.

Innovation Solution

A system comprising a metadata generation component, security component, and metadata extractor component that generates and monitors metadata associated with a distributed file system, detects degradation events, and extracts relevant data items to generate reports and alerts, facilitating forensic analysis and notification of affected data owners.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical theft protection technology is implemented, then security against hardware theft is improved, but the ability to quickly identify stolen data content and notify owners deteriorates

Engineering Contradiction:
Improvesecurity against hardware theftVSAvoidtime to identify stolen data content
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating and storing metadata products containing data item information before any theft occurs. When a degradation event is detected, this pre-stored metadata enables immediate identification of stolen data content without requiring time-consuming analysis of the stolen hardware, thus resolving the contradiction between security protection and rapid response capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of essential data information in the form of metadata products that are stored separately from the actual data. These metadata copies contain identifiers and characteristics of data items, allowing rapid identification of stolen data through the metadata extractor component without needing to access or analyze the physical stolen hardware, thereby enabling quick response while maintaining security

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If data is stored without structured organization on hard drives, then storage flexibility is improved, but the ability to identify data owners and content deteriorates

Engineering Contradiction:
Improvestorage flexibilityVSAvoiddata owner identification capability
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system segments data identification information from the actual data storage by creating separate metadata products that contain data item information. This segmentation allows the main storage system to maintain flexibility in storing data without structured organization while the metadata layer provides organized tracking of data owners and content characteristics, resolving the contradiction between storage flexibility and identification capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The metadata product acts as an intermediary between the flexible unstructured storage system and the need for data owner identification. The metadata extractor component retrieves information from these intermediary metadata products, enabling owner identification and content characterization without requiring the main storage system to impose rigid structure on the stored data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10944782B2Forensic analysis through metadata extraction
Publication Date: 2021.03.09 EMC IP HLDG CO LLC
  • US10944782B2 patent drawing
  • US10944782B2 patent drawing
  • US10944782B2 patent drawing

AI summary

In one or more embodiments described herein, system, methods, and/or computer program products that forensic analysis through metadata extraction. According to an embodiment, a system can comprise a memory that stores computer executable components and a processor that executes the computer executable components stored in the memory. The computer executable components can comprise a metadata generation component that generates a metadata product comprising one or more data items associated with a distributed architecture of a file system, wherein the file system comprises one or more disks. The computer executable components can further comprise a security component that monitors the file system, wherein the security component generates an alert in response to detecting a degradation event associated with the one or more disks. The computer executable components can further comprise a metadata extractor component that extracts the one or more data items from the metadata product in response to receiving the alert from the security component.