Remote Forensic Analysis via iSCSI Read-Only Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer forensics methods are time-consuming and costly, requiring physical access to computing devices, which can disrupt business operations and pose risks to sensitive data, and often result in extensive efforts with minimal evidence found.

Innovation Solution

A system and method for remote forensic analysis using a non-proprietary communication protocol like iSCSI to establish a read-only connection between a subject computer and a forensic analysis server, allowing secure, remote access and analysis without altering the subject computer's data, enabling efficient and cost-effective digital forensics investigations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access to computing devices is taken for forensic analysis, then evidence collection can be performed, but business operations are disrupted and sensitive data is exposed

Engineering Contradiction:
Improveevidence integrityVSAvoidbusiness operations continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a remote forensic analysis system as an intermediary between the forensic practitioner and the subject computer. This intermediary enables evidence collection without physical access to the computer, allowing business operations to continue uninterrupted while maintaining evidence integrity through remote read-only access and cryptographic hashing verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy of the computer's storage devices through remote imaging capabilities. Instead of physically accessing the computer, the forensic analysis server creates a bit-by-bit copy of the storage devices over the network, allowing analysis of the copy while the original computer remains operational and unaffected.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive forensic analysis is performed on all computing devices, then evidence can be thoroughly collected, but time and cost increase significantly

Engineering Contradiction:
Improveevidence completenessVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements partial forensic analysis by allowing practitioners to target specific storage devices or partitions based on suspicion and investigative needs. Rather than analyzing all devices comprehensively, the system enables selective analysis of particular components, reducing time and cost while maintaining sufficient evidence collection for the specific investigation at hand.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary actions by creating remote images of storage devices before deeper analysis begins. This preliminary imaging allows practitioners to quickly assess the scope of evidence and determine which devices require full analysis, enabling more efficient resource allocation and reducing overall analysis time.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If write operations are performed on subject computer memory during analysis, then data can be modified for investigation, but evidence integrity is compromised

Engineering Contradiction:
Improveforensic analysis flexibilityVSAvoidevidence integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional forensic approach by using read-only remote access instead of write-based analysis. Instead of modifying data on the subject computer to examine it, the system reads data remotely and creates virtual copies for analysis, maintaining the original evidence's integrity while still enabling comprehensive forensic investigation through the inverted read-access model.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS8171108B2System and method for providing remote forensics capability
Publication Date: 2012.05.01 AGILE RISK MANAGEMENT LLC
  • US8171108B2 patent drawing
  • US8171108B2 patent drawing
  • US8171108B2 patent drawing

AI summary

A system and method for performing a forensic analysis of a subject computer having a non-volatile memory with a second computer is provided. In one embodiment, the method includes executing on the subject computer a first code segment configured to provide communications via a non-proprietary communication protocol such as the Internet Small Computer System Interface (iSCSI) protocol; establishing a connection between the second computer and the subject computer via the non-proprietary communication protocol. The non-proprietary communication protocol includes one or more write operations for writing data to a non-volatile memory in response to one or more write commands and the first code segment is configured to not write data to the non-volatile memory of the subject computer in response to receipt of the one or more write commands. The method may include performing a first forensic analysis of the subject computer via the connection. In addition, the method may further comprise establishing a secure connection, such via the Internet, between the second computer and a remote computer, wherein performing the first forensic analysis is initiated by the remote computer. A pre-defined forensic instruction set may be stored on the second computer and executed to perform the first forensic analysis.