IP Library Patent Application 13358782
Patent Application
App. No. 13/358,782

SYSTEMS, METHODS, APPARATUSES, AND COMPUTER PROGRAM PRODUCTS FOR FORENSIC MONITORING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/358,782
Abstract

Systems, methods, apparatuses, and computer program products are provided for forensic monitoring. A system may include a forensic analysis apparatus and one or more monitored apparatuses. A monitored apparatus may monitor activity on the monitored apparatus and extract forensic data based at least in part on monitored activity. The forensic data may be transferred from the monitored apparatus to the forensic analysis apparatus for processing and analysis.

Claims (51)

1 . A method for forensic monitoring comprising:

monitoring activity on a monitored apparatus;

extracting, by a processor, forensic data based at least in part on monitored activity; and

causing transfer of the extracted forensic data from the monitored apparatus to a forensic analysis apparatus configured to archive the forensic data for later analysis.

2 . The method of claim 1 , wherein extracting forensic data and causing transfer of the extracted forensic data are performed automatically on a scheduled basis.

3 . The method of claim 1 , wherein data integrity of the extracted forensic data and a chain of custody of the extracted forensic data is preserved during transfer of the extracted forensic through secure transfer of the forensic data from the monitored apparatus to the forensic analysis apparatus.

4 . The method of claim 1 , wherein extracting forensic data comprises extracting forensic data from one or more files containing evidence of activity on the monitored apparatus.

5 . The method of claim 4 , wherein extracting forensic data from one or more files comprises extracting forensic data from an operating system file.

6 . The method of claim 1 , wherein the forensic analysis apparatus is further configured to process the forensic data transferred to the forensic analysis apparatus and generate a report based at least in part on the processed forensic data.

7 . The method of claim 1 , wherein:

extracting forensic data and causing transfer of the extracted forensic data are performed automatically on a scheduled basis;

data integrity of the extracted forensic data and a chain of custody of the extracted forensic data is preserved during transfer of the extracted forensic through secure transfer of the forensic data from the monitored apparatus to the forensic analysis apparatus; and

the forensic analysis apparatus is further configured to process the forensic data transferred to the forensic analysis apparatus and generate a report based at least in part on the processed forensic data.

8 . An apparatus for forensic monitoring comprising at least one processor, the at least one processor configured to cause the apparatus to at least:

monitor activity on a monitored apparatus;

extract forensic data based at least in part on monitored activity; and

cause transfer of the extracted forensic data from the monitored apparatus to a forensic analysis apparatus configured to archive the forensic data for later analysis.

9 . The apparatus of claim 8 , wherein the at least one processor is further configured to cause the apparatus to extract forensic data and cause transfer of the extracted forensic data automatically on a scheduled basis.

10 . The apparatus of claim 8 , wherein the at least one processor is further configured to cause the apparatus to preserve data integrity of the extracted forensic data and a to preserve chain of custody of the extracted forensic data during transfer of the extracted forensic through secure transfer of the forensic data from the monitored apparatus to the forensic analysis apparatus.

11 . The apparatus of claim 8 , wherein the at least one processor is further configured to cause the apparatus to extract forensic data at least in part by extracting forensic data from one or more files containing evidence of activity on the monitored apparatus.

12 . The apparatus of claim 11 , wherein the at least one processor is further configured to cause the apparatus to extract forensic data from an operating system file.

13 . The apparatus of claim 8 , wherein the forensic analysis apparatus is further configured to process the forensic data transferred to the forensic analysis apparatus and generate a report based at least in part on the processed forensic data.

14 . A method for forensic analysis comprising:

receiving, at a forensic analysis apparatus, forensic data transferred from a monitored apparatus to the forensic analysis apparatus, the forensic data comprising forensic data extracted by the monitored apparatus based at least in part on monitored activity on the monitored apparatus; and

archiving the forensic data for later analysis, wherein archiving the received forensic data is performed under control of a processor.

15 . The method of claim 14 , wherein receiving the forensic data comprises receiving forensic data securely transferred from the monitored apparatus to the forensic analysis apparatus to preserve data integrity and a chain of custody of the forensic data.

16 . The method of claim 14 , further comprising:

processing the received forensic data to generate a processed set of forensic data;

wherein archiving the forensic data comprises archiving the processed set of forensic data.

17 . The method of claim 14 , further comprising:

analyzing the forensic data; and

generating a report based at least in part on the analysis of the forensic data.

18 . The method of claim 17 , further comprising:

determining one or more key risk indicator values relating to the monitored apparatus based at least in part on the analysis;

wherein generating the report comprises generating a report including the determined key risk indicator values.

19 . The method of claim 17 , wherein receiving the forensic data comprises receiving forensic data securely transferred from the monitored apparatus to the forensic analysis apparatus to preserve data integrity and a chain of custody of the forensic data, the method further comprising:

processing the received forensic data to generate a processed set of forensic data;

wherein archiving the forensic data comprises archiving the processed set of forensic data, wherein analyzing the forensic data comprises analyzing the processed set of forensic data.

20 . An apparatus for forensic analysis comprising at least one processor, the at least one processor configured to cause the apparatus to at least:

receive forensic data transferred from a monitored apparatus to the apparatus, the forensic data comprising forensic data extracted by the monitored apparatus based at least in part on monitored activity on the monitored apparatus; and

archive the forensic data for later analysis.

21 . The apparatus of claim 20 , wherein the at least one processor is further configured to cause the apparatus to receive the forensic data by receiving forensic data securely transferred from the monitored apparatus to the forensic analysis apparatus to preserve data integrity and a chain of custody of the forensic data.

22 . The apparatus of claim 20 , wherein the at least one processor is further configured to cause the apparatus to:

process the received forensic data to generate a processed set of forensic data; and

archive the forensic data at least in part by archiving the processed set of forensic data.

23 . The apparatus of claim 20 , wherein the at least one processor is further configured to cause the apparatus to:

analyze the forensic data; and

generate a report based at least in part on the analysis of the forensic data.

24 . The apparatus of claim 23 , wherein the at least one processor is further configured to cause the apparatus to:

determine one or more key risk indicator values relating to the monitored apparatus based at least in part on the analysis; and

generate the report at least in part by generating a report including the determined key risk indicator values.

Assignments (2)
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2022
From: COMERICA BANK
To: VIAFORENSICS, LLC
Reel/Frame 058860/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2012
From: HOOG, ANDREW W.
To: VIAFORENSICS, LLC
Reel/Frame 027599/0784 →