IP Library Granted Patent US 8,438,174
Granted Patent B2
US 8,438,174 · App. 12/822,722 · Granted May 7, 2013

Automated forensic document signatures

Inventors: Thomas Clay Shields (Washington, DC); Ophir Frieder (Chicago, IL); Marcus A. Maloof (Washington, DC)
Assignee: Georgetown University
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,174
App. No.
12/822,722
Granted
May 7, 2013
Kind
B2
Abstract

Methods and systems are provided for a proactive approach for computer forensic investigations. The invention allows organizations anticipating the need for forensic analysis to prepare in advance. Forensic signatures are created including a digital fingerprint and other information associated with a file. In one aspect, informational signatures are created, which may assist in determining what information is included in a file. In another aspect, the digital fingerprint may represent contents of the file and is resistant to minor modification of the file. In another aspect, fingerprints can be compared in parallel on different computers.

Claims (53)

1. A method of generating forensic evidence of a digital file, comprising:

selecting a token indicating an informational object;

generating a digital fingerprint of the digital file using the selected token; and

creating the signature that includes the digital fingerprint and meta data of the digital file,

wherein the informational object has semantic meanings, represents specific contents of the digital file and represents more information than a collection of computer-generated symbols, and

wherein the signature is proactively generated for computer forensic evidence of the digital file and configured to allow a forensic analysis with the computer forensic evidence, and

wherein a computer operation that changes the informational object causes proactive updating of the signature.

2. A method of generating forensic evidence of a video, comprising

detecting scene changes of the video;

segmenting the video into a plurality of segments corresponding to each scene change;

extracting a representation from each segment

forming a digital fingerprint based on the representations; and

creating a signature by combining the digital fingerprint with predetermined metadata of the video,

wherein the signature is proactively generated for computer forensic evidence of the video and configured to allow a forensic analysis with the computer forensic evidence, and

wherein a computer operation the video causes proactive updating of the signature.

3. A method of claim 2 , wherein the representation includes one or more frames of each segment.

4. A method of claim 2 , wherein the representation includes length information of each segment.

5. A method of claim 2 , wherein the representation includes a subtitle and caption text of each segment.

6. A method of generating forensic evidence for an audio file, comprising:

determining whether the audio includes music or speech;

generating, if the audio includes speech, a transcript of the speech;

extracting a representation from the transcript;

forming a digital fingerprint based on the representation; and

creating a signature by combining the digital fingerprint with predetermined metadata of the audio,

wherein the signature is proactively generated for computer forensic evidence of the audio and configured to allow a forensic analysis with the computer forensic evidence, and

wherein a computer operation that changes the audio file causes proactive updating of the signature.

7. A method of claim 1 , further comprising:

extracting a plurality of tokens from the digital file according to the selected token; and

inserting the extracted plurality of tokens into a data structure that probabilistically determines whether a token was previously inserted.

8. The method of claim 1 , wherein the selected token includes a token selected from the group consisting essentially of: an email address, a name, an account number, and a social security number.

9. A computer-readable non-transitory storage medium storing an executable program, when executed, causing a computer system to execute a method of generating forensic evidence of a digital file, comprising :

selecting a token indicating an informational object;

generating a digital fingerprint of the digital file using the selected token; and

creating the signature that includes the digital fingerprint and meta data of the digital file,

wherein the informational object has semantic meanings, represents specific contents of the digital file and represents more information than a collection of computer-generated symbols, and

wherein the signature is proactively for computer forensic evidence of the digital file and configured to allow a forensic analysis with the computer forensic evidence,

a computer operation that charges the informational object causes proactive updating of the signature.

10. A computer-readable non-transitory storage medium storing an executable program, when executed, causing a computer system to execute a method of generating forensic evidence of a video, comprising:

detecting scene changes of the video;

segmenting the video into a plurality of segments corresponding to each scene change;

extracting a representation from each segment;

forming a digital fingerprint based on the representation; and

creating a signature by combining the digital fingerprint with predetermined metadata of the video,

wherein the signature is proactively generated for computer forensic evidence of the video and configured to allow a forensic analysis with the computer forensic evidence, and

a computer operation that changes the video causes proactive updating of the signature.

11. A computer-read-able non-transitory storage medium storing an executable program, when executed, causing a computer system to execute a method of generating forensic evidence for an audio file, comprising:

determining whether the audio includes music or speech;

generating, if the audio includes speech, a transcript of the speech;

extracting a representation from the transcript;

forming a digital fingerprint based on the representation; and

creating a signature by combining the digital fingerprint with predetermined metadata of the audio,

wherein the signature is proactively generated for computer forensic evidence of the audio and configured to allow a forensic analysis with the computer forensic evidence,

a computer operation that changes the audio file causes proactive updating of the signature.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2010
From: SHIELDS, THOMAS CLAY; FRIEDER, OPHIR; MALOOF, MARCUS A.
To: GEORGETOWN UNIVERSITY
Reel/Frame 024719/0846 →
Continuity (3)
Continuation In Part 11963186 · Dec 21, 2007
Continuation In Part 12118942 · May 12, 2008
Related Publication 20100287196A1 · Nov 11, 2010