Remote Forensic Evidence Acquisition via Network Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer forensic techniques require physical access to target computers, which can be burdensome and invasive, especially for critical network devices, and often disrupt the system, making it difficult to collect evidence without detection.

Innovation Solution

A remote computer forensic system that allows investigators to acquire and analyze computer evidence from target devices via a network connection, using a forensic device that can communicate with devices on the same subnet, perform acquisition operations in a specific order to minimize disruption, and normalize and authenticate data for integrity and admissibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If physical connection or on-site inspection is used to acquire computer evidence, then evidence collection completeness is improved, but system disruption and operational burden increase

Engineering Contradiction:
Improveevidence collection completenessVSAvoidsystem disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a forensic device as an intermediary component that connects to the target computer through a network interface card (NIC) without requiring physical seizure of the target system. This intermediary device captures forensic evidence remotely, eliminating the need for investigators to physically connect analysis devices to the target computer, thereby maintaining system operation while enabling complete evidence collection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the forensic investigation function from the target computer system by using a separate forensic device with its own processing capabilities. The forensic device contains its own analysis software and processing unit, allowing it to independently acquire and analyze evidence without burdening the target system's resources, thus preventing system disruption while ensuring complete evidence collection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical seizure or shutdown of target device is performed, then evidence acquisition reliability is improved, but operational continuity deteriorates

Engineering Contradiction:
Improveevidence acquisition reliabilityVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables continuous operation of the target computer during forensic evidence acquisition. The forensic device monitors and captures evidence in real-time while the target system continues to operate normally, eliminating the need to shut down or seize the target device. This ensures both reliable evidence acquisition and uninterrupted operational continuity of the target system.

Inventive Principle:
Principle #20Continuity of useful action

3Difficulty of detecting and measuring

If invasive forensic techniques are used, then evidence detection capability is improved, but detectability by perpetrator increases

Engineering Contradiction:
Improveevidence detection capabilityVSAvoiddetectability by perpetrator
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-generated harmful factors

Solution Approach 1:

The forensic device operates as a hidden intermediary on the network, capturing evidence remotely without the target user's knowledge. By using network-based communication rather than direct physical connection, the forensic investigation remains undetected by the perpetrator while maintaining high evidence detection capability through comprehensive data capture.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If remote network-based forensic acquisition is used, then operational burden on network users is reduced, but technical complexity of the system increases

Engineering Contradiction:
Improveoperational burden on network usersVSAvoidtechnical complexity of forensic system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines multiple forensic functions (evidence capture, data analysis, and storage) into a single integrated forensic device. This consolidation simplifies the overall system architecture and reduces operational complexity compared to using multiple separate tools, while still providing remote network-based acquisition that minimizes burden on network users.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7496959B2Remote collection of computer forensic evidence
Publication Date: 2009.02.24 WATCHGUARD
  • US7496959B2 patent drawing
  • US7496959B2 patent drawing
  • US7496959B2 patent drawing

AI summary

The invention is directed to techniques for allowing a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. A forensic device receives input from a remote user that identifies computer evidence to acquire from the target computing device. The forensic device acquires the computer evidence from the target computing device and presents a user interface for the forensic device through which the remote user views the computer evidence acquired from the target computing device. In this manner, forensic device allows the user to interrogate the target computing device to acquire the computer evidence without seizing or otherwise “shutting down” the target device.