Remote Forensic Evidence Acquisition via Network Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer forensic techniques require physical access to target computers, which can be burdensome and invasive, especially for critical network devices, and often disrupt the system, making it difficult to collect evidence without detection.
Innovation Solution
A remote computer forensic system that allows investigators to acquire and analyze computer evidence from target devices via a network connection, using a forensic device that can communicate with devices on the same subnet, perform acquisition operations in a specific order to minimize disruption, and normalize and authenticate data for integrity and admissibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If physical connection or on-site inspection is used to acquire computer evidence, then evidence collection completeness is improved, but system disruption and operational burden increase
Solution Approach 1:
The patent introduces a forensic device as an intermediary component that connects to the target computer through a network interface card (NIC) without requiring physical seizure of the target system. This intermediary device captures forensic evidence remotely, eliminating the need for investigators to physically connect analysis devices to the target computer, thereby maintaining system operation while enabling complete evidence collection.
Solution Approach 2:
The patent segments the forensic investigation function from the target computer system by using a separate forensic device with its own processing capabilities. The forensic device contains its own analysis software and processing unit, allowing it to independently acquire and analyze evidence without burdening the target system's resources, thus preventing system disruption while ensuring complete evidence collection.
2Reliability
If physical seizure or shutdown of target device is performed, then evidence acquisition reliability is improved, but operational continuity deteriorates
Solution Approach 1:
The patent enables continuous operation of the target computer during forensic evidence acquisition. The forensic device monitors and captures evidence in real-time while the target system continues to operate normally, eliminating the need to shut down or seize the target device. This ensures both reliable evidence acquisition and uninterrupted operational continuity of the target system.
3Difficulty of detecting and measuring
If invasive forensic techniques are used, then evidence detection capability is improved, but detectability by perpetrator increases
Solution Approach 1:
The forensic device operates as a hidden intermediary on the network, capturing evidence remotely without the target user's knowledge. By using network-based communication rather than direct physical connection, the forensic investigation remains undetected by the perpetrator while maintaining high evidence detection capability through comprehensive data capture.
4Ease of operation
If remote network-based forensic acquisition is used, then operational burden on network users is reduced, but technical complexity of the system increases
Solution Approach 1:
The patent combines multiple forensic functions (evidence capture, data analysis, and storage) into a single integrated forensic device. This consolidation simplifies the overall system architecture and reduces operational complexity compared to using multiple separate tools, while still providing remote network-based acquisition that minimizes burden on network users.
Data Source
AI summary
The invention is directed to techniques for allowing a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. A forensic device receives input from a remote user that identifies computer evidence to acquire from the target computing device. The forensic device acquires the computer evidence from the target computing device and presents a user interface for the forensic device through which the remote user views the computer evidence acquired from the target computing device. In this manner, forensic device allows the user to interrogate the target computing device to acquire the computer evidence without seizing or otherwise “shutting down” the target device.


