Remote Forensic Agent for Non-Invasive Evidence Acquisition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer forensic techniques are invasive and burdensome, particularly when dealing with critical network servers, and often result in the loss of volatile evidence, as they require physical access and can alert perpetrators, leading to potential data deletion.
Innovation Solution
A user-configurable forensic investigative tool that allows remote acquisition of data from target computing devices over an enterprise network, using a framework with a common user interface and reporting structure, enabling the invocation of multiple forensic tools and utilities, and a remote agent for temporary execution on the target device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical seizure or on-site inspection is performed on target computing devices, then forensic evidence can be acquired, but the investigation becomes burdensome on network users and may cause loss of volatile evidence
Solution Approach 1:
The patent introduces a remote agent as an intermediary component that executes forensic tools on target computing devices without requiring physical presence. The remote agent communicates with the investigator's system over a network, enabling evidence acquisition while the target device remains operational and unaffected by physical seizure or on-site inspection activities.
Solution Approach 2:
The patent replaces physical mechanical systems (physical seizure, on-site inspection) with a remote execution system. Forensic tools are deployed remotely via network communication, and the remote agent executes these tools on the target device, substituting the need for physical interaction and eliminating the burden on network users while preserving volatile evidence.
2Reliability
If invasive forensic techniques are used to acquire evidence, then evidence can be collected, but the perpetrator may be alerted and delete data
Solution Approach 1:
The remote agent acts as an intermediary that executes forensic tools without requiring physical access or alerting the user. The agent communicates results back to the investigator's system, enabling covert evidence collection that does not alert the perpetrator to delete data.
Solution Approach 2:
The target computing device performs self-examination through the remotely executed forensic tools without external intervention or user knowledge. The device autonomously provides forensic data while maintaining normal operation, preventing the perpetrator from detecting or responding to the investigation.
3Adaptability or versatility
If a comprehensive forensic examination framework is implemented, then multiple forensic tools can be invoked, but the system complexity increases
Solution Approach 1:
The patent creates a universal framework where a single remote agent can execute multiple different forensic tools on various target computing devices. The framework provides a common user interface and reporting structure that handles diverse forensic operations uniformly, enabling comprehensive examination capabilities without requiring separate specialized systems for each tool.
Solution Approach 2:
The patent merges multiple forensic tools and operations into a unified remote execution framework. The remote agent consolidates the execution of various forensic tools, and the framework combines their results through a common reporting structure, reducing the complexity of managing multiple separate systems while maintaining comprehensive examination capabilities.
Data Source
AI summary
This disclosure provides example techniques to invoke one or more forensic tools, with a forensic investigative tool. The forensic investigative tool provides a common framework that allows investigators to invoke their own trusted forensic tools or third-party generated forensic tools. The forensic investigative tool described herein seamlessly and transparently invokes the forensic tools in accordance with an investigative profile created by the investigator.


