IP Library Granted Patent US 9,183,416
Granted Patent B2
US 9,183,416 · App. 13/077,235 · Granted Nov 10, 2015

System for performing parallel forensic analysis of electronic data and method therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,183,416
App. No.
13/077,235
Granted
Nov 10, 2015
Kind
B2
Abstract

System and method for conducting a forensic analysis of electronic data having files and information indicative of a location of each of the files. The system has processors and a controller. The controller is configured to characterize the electronic data based, at least in part, on the files and the information indicative of the location of each of the files to obtain a characterization and distribute segments of the electronic data to the processors based, at least in part, on the characterization, each of the processors corresponding to at least one of the segments and each of the segments corresponding to at least one of the processors. Each one of the processors is configured to process each corresponding one of the segments to identify at least one characteristic of each corresponding one of the segments.

Claims (39)

1. A system for conducting a forensic analysis of electronic data duplicated from an electronic storage device, the electronic data comprising a plurality of files and information indicative of a location of each of the plurality of files in the electronic storage device, the system comprising:

a controller operatively coupled to a plurality of processors, wherein the controller is configured to:

characterize the electronic data based, at least in part, on the plurality of files and the information indicative of the location of each of the plurality of files to obtain a characterization; and

distribute a plurality of segments of the electronic data, at least some of the plurality of segments being approximately equal in size, to the plurality of processors based, at least in part, on the characterization, each of the plurality of processors corresponding to at least one of the plurality of segments and each of the plurality of segments corresponding to at least one of the plurality of processors; and

wherein each one of the plurality of processors is configured to process each corresponding one of the plurality of segments to identify at least one characteristic of each corresponding one of the plurality of segments, wherein the plurality of processors are configured to process in parallel, and wherein each of the plurality of processors are configured to communicate with at least one other one of the plurality of processors.

2. The system of claim 1 , wherein the controller is further configured to create a work process for the plurality of segments of the electronic data based, at least in part, on the characterization; and

wherein the controller is further configured to distribute the plurality of segments of the electronic data to the plurality of processors based, at least in part, on the work process.

3. The system of claim 1 , wherein the plurality of segments account for all of the electronic data.

4. The system of claim 3 , wherein the plurality of segments is a distribution plurality of segments;

wherein the electronic data is initially divided into an initial plurality of segments, each individual one of the initial plurality of segments comprising at least a portion of at least one of said plurality of files;

wherein the controller is further configured to characterize the electronic data to obtain the characterization by identifying, for at least some of the plurality of files, segments of the initial plurality of segments to which each one of the at least some of the plurality of files corresponds; and

wherein the controller is further configured to cause the electronic data to be divided into the distribution plurality of segments based, at least in part, on the characterization, at least some of the distribution plurality of segments being of different size than a size of ones of the initial plurality of segments and comprising at least a portion of at least one of the plurality of files.

5. The system of claim 4 , wherein the controller is further configured to distribute the second plurality of segments so that each individual one of the plurality of files is wholly contained in at least one of the second plurality of segments.

6. The system of claim 3 , wherein the characteristic identified for each corresponding one of the plurality of segments comprises information pertaining to at least one of the plurality of files corresponding to the corresponding one of the plurality of segments.

7. The system of claim 6 , wherein the information comprises contents of the at least one of the plurality of files.

8. The system of claim 3 , wherein the information indicative of the location of each of the plurality of files is file system data.

9. The system of claim 4 , wherein each of the plurality of files has a file start; and

wherein the controller is further configured to cause the electronic data to be divided into the distribution plurality of segments based, at least in part, on a location in one of the initial plurality of segments of each file start of the plurality of files.

10. The system of claim 4 , wherein each individual one of the plurality of files has a correspondence in primary part to one of the initial plurality of segments; and wherein the controller is further configured to cause the electronic data to be divided into the distribution plurality of segments based, at least in part, on the correspondence in primary part of each individual one of the plurality of files.

11. A method for conducting a forensic analysis of electronic data from an electronic storage device, the electronic data comprising a plurality of files and information indicative of a location of each of the plurality of files in the electronic storage device, comprising the steps of:

characterizing the electronic data based, at least in part, on the plurality of files and the information indicative of the location of each of the plurality of files to obtain a characterization;

distributing a plurality of segments of the electronic data, at least some of the plurality of segments being approximately equal in size, to the plurality of processors based, at least in part, on the characterization, each of the plurality of processors corresponding to at least one of the plurality of segments and each of the plurality of segments corresponding to at least one of the plurality of processors; and

causing processing with the plurality of processors of each corresponding one of the plurality of segments to identify at least one characteristic of each corresponding one of the plurality of segments, wherein the plurality of processors are configured to process in parallel, and wherein each of the plurality of processors are configured to communicate with at least one other one of the plurality of processors.

12. The method of claim 11 , further comprising the steps of:

creating a work process for each of the plurality of segments of the electronic data based, at least in part, on the characterization; and

wherein the distributing step is further configured to distribute the plurality of segments of the electronic data to the plurality of processors based, at least in part, on the work process.

13. The method of claim 11 wherein the dividing steps further comprises dividing all of the electronic data into the plurality of segments.

14. The method of claim 13 wherein the plurality of segments is a distribution plurality of segments, and further comprising the steps of:

initially dividing the electronic data into an initial plurality of segments, each individual one of the initial plurality of segments and comprising at least a portion of at least one of said plurality of files;

characterizing the electronic data to obtain the characterization by identifying, for at least some of the plurality of files, segments of the initial plurality of segments to which each one of the at least some of the plurality of files corresponds; and

causing the electronic data to be divided into the distribution plurality of segments based, at least in part, on the characterization, at least some of the distribution plurality of segments being of different size than a size of ones of the initial plurality of segments and comprising at least a portion of at least one of the plurality of files.

15. The method of claim 14 wherein the distributing step further comprises distributing the electronic data so that each individual one of the plurality of files is wholly contained in at least one of the second plurality of segments.

16. The method of claim 13 wherein the characteristic identified for each corresponding one of the plurality of segments comprises information pertaining to at least one of the plurality of files corresponding to the corresponding one of the plurality of segments.

17. The method of claim 16 wherein the information comprises contents of the at least one of the plurality of files.

18. The method of claim 13 wherein information indicative of a location of each of the plurality of files is file system data.

19. The method of claim 18 wherein each of the plurality of files has a file start; and

wherein the causing the electronic data to be divided step further comprises causing the electronic data to be divided into the distribution plurality of segments based, at least in part, on a location in one of the initial plurality of segments of each file start of the plurality of files.

20. The method of claim 18 wherein each individual one of the plurality of files has a correspondence in primary part to one of the initial plurality of segments; and

wherein the causing the electronic data to be divided step further comprises causing the electronic data to be divided into the distribution plurality of segments based, at least in part, on the correspondence in primary part of each individual one of the plurality of files.

Assignments (4)
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2016
From: LIGHTBOX TECHNOLOGIES, INC.
To: STROZ FRIEDBERG, LLC
Reel/Frame 038067/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2011
From: STEWART, JON; BLACK, GEOFFREY N.
To: LIGHTBOX TECHNOLOGIES, INC.
Reel/Frame 026062/0401 →