Remote Forensic Analysis via iSCSI Read-Only Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer forensics methods are time-consuming and costly, requiring physical access to computing devices, which can disrupt business operations and pose risks to sensitive data, and often result in extensive efforts with minimal evidence found.
Innovation Solution
A system and method for remote forensic analysis using a non-proprietary communication protocol like iSCSI to establish a read-only connection between a subject computer and a forensic analysis server, allowing secure, remote access and analysis without altering the subject computer's data, enabling efficient and cost-effective digital forensics investigations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical access to computing devices is taken for forensic analysis, then evidence collection can be performed, but business operations are disrupted and sensitive data is exposed
Solution Approach 1:
The patent introduces a remote forensic analysis system as an intermediary between the forensic practitioner and the subject computer. This intermediary enables evidence collection without physical access to the computer, allowing business operations to continue uninterrupted while maintaining evidence integrity through remote read-only access and cryptographic hashing verification.
Solution Approach 2:
The system creates a virtual copy of the computer's storage devices through remote imaging capabilities. Instead of physically accessing the computer, the forensic analysis server creates a bit-by-bit copy of the storage devices over the network, allowing analysis of the copy while the original computer remains operational and unaffected.
2Reliability
If comprehensive forensic analysis is performed on all computing devices, then evidence can be thoroughly collected, but time and cost increase significantly
Solution Approach 1:
The patent implements partial forensic analysis by allowing practitioners to target specific storage devices or partitions based on suspicion and investigative needs. Rather than analyzing all devices comprehensively, the system enables selective analysis of particular components, reducing time and cost while maintaining sufficient evidence collection for the specific investigation at hand.
Solution Approach 2:
The system performs preliminary actions by creating remote images of storage devices before deeper analysis begins. This preliminary imaging allows practitioners to quickly assess the scope of evidence and determine which devices require full analysis, enabling more efficient resource allocation and reducing overall analysis time.
3Ease of operation
If write operations are performed on subject computer memory during analysis, then data can be modified for investigation, but evidence integrity is compromised
Solution Approach 1:
The patent inverts the traditional forensic approach by using read-only remote access instead of write-based analysis. Instead of modifying data on the subject computer to examine it, the system reads data remotely and creates virtual copies for analysis, maintaining the original evidence's integrity while still enabling comprehensive forensic investigation through the inverted read-access model.
Data Source
AI summary
A system and method for performing a forensic analysis of a subject computer having a non-volatile memory with a second computer is provided. In one embodiment, the method includes executing on the subject computer a first code segment configured to provide communications via a non-proprietary communication protocol such as the Internet Small Computer System Interface (iSCSI) protocol; establishing a connection between the second computer and the subject computer via the non-proprietary communication protocol. The non-proprietary communication protocol includes one or more write operations for writing data to a non-volatile memory in response to one or more write commands and the first code segment is configured to not write data to the non-volatile memory of the subject computer in response to receipt of the one or more write commands. The method may include performing a first forensic analysis of the subject computer via the connection. In addition, the method may further comprise establishing a secure connection, such via the Internet, between the second computer and a remote computer, wherein performing the first forensic analysis is initiated by the remote computer. A pre-defined forensic instruction set may be stored on the second computer and executed to perform the first forensic analysis.


