Remote Digital Forensics via Virtual SCSI Emulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current forensic services face challenges in efficiently and cost-effectively conducting remote digital forensics and eDiscovery over public and private networks, requiring physical access to computing devices and involving extensive time and resources, especially when dealing with large enterprises and sensitive data.

Innovation Solution

A method and system that enables forensically sound remote examination of geographically dispersed computers by emulating non-transitory computer-readable media as read-only SCSI devices over networks, using protocols like NBD and cloud computing to facilitate secure, remote access and analysis without altering original data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access to subject computers is required for forensic examination, then data integrity and chain of custody are maintained, but time and cost of forensic operations increase significantly

Engineering Contradiction:
Improvedata integrityVSAvoidtime for forensic examination
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual copy of the physical storage device by establishing a network block device connection. This virtual representation allows forensic examiners to access and analyze data remotely without physically handling the original media, thereby maintaining data integrity at the source while eliminating travel time and physical access requirements. The virtual device acts as a faithful replica that can be examined without affecting the original.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The network block device serves as an intermediary between the forensic examiner and the physical storage media. It translates remote access requests into local storage operations, enabling forensic examinations to be conducted over networks while preserving the integrity of the original physical devices. This intermediary layer eliminates the need for physical presence while maintaining forensic soundness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical access to subject computers is required for forensic examination, then direct control over evidence is achieved, but resource requirements and operational costs increase

Engineering Contradiction:
Improveevidence controlVSAvoidcost-effectiveness of forensic operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By creating a virtual block device that replicates the physical storage media over a network connection, the system enables forensic examiners to maintain direct control and access to evidence data without incurring the costs associated with physical transport, secure storage facilities, and on-site personnel. The virtual copy provides the same level of evidentiary control as physical possession but eliminates associated operational costs.

Inventive Principle:
Principle #26Copying

3Loss of time

If remote access to computing devices is implemented, then time and cost of forensic operations are reduced, but data security and access control challenges arise

Engineering Contradiction:
Improvetime for forensic examinationVSAvoiddata security risks
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The network block device acts as a secure intermediary that implements authentication, authorization, and access control mechanisms. It manages the connection between remote forensic tools and local storage devices, ensuring that only authorized personnel can access evidence data while maintaining security protocols. This intermediary layer protects against unauthorized access while enabling efficient remote forensic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9037630B2Systems and methods for provisioning digital forensics services remotely over public and private networks
Publication Date: 2015.05.19 SHANNON MATTHEW MARTIN
  • US9037630B2 patent drawing
  • US9037630B2 patent drawing
  • US9037630B2 patent drawing

AI summary

Provided are systems and methods for remote collection, preservation, and analysis of computer-based evidence in the course of conducting a network-based forensics or electronic discovery service. The challenge is to collect and analyze Electronically Stored Information (ESI) in a forensically sound manner over public and private networks. This is achieved via network-based forensics that may be conducted via an end user computer communicating directly with one or more subject computers across public or private networks, or it may be achieved via a “cloud computing” model whereupon the end user obtains, from the Internet, temporary use of shared resources, software, and information for the purpose of conducting digital forensics and eDiscovery upon subject computers.