IP Library Granted Patent US 9,177,011
Granted Patent B2
US 9,177,011 · App. 13/711,902 · Granted Nov 3, 2015

Systems and methods for locating application specific data

Inventor: Jad John Saliba (Puslinch, CA)
Assignee: Magnet Forensics Inc.
G06F17/30371G06F21/57G06F21/64G06F21/78G06Q10/10G06Q50/01H04L63/308
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,177,011
App. No.
13/711,902
Granted
Nov 3, 2015
Kind
B2
Abstract

A system and a method for locating application-specific data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data. The method includes accessing unidentified data from at least one data storage device; examining the unidentified data to detect at least one application-specific data pattern associated with at least one application; for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application; and if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.

Claims (41)

1. A system for locating for application-specific data comprising:

(a) at least one data storage device, having unidentified data stored therein;

(b) at least one processor operatively coupled to the at least one data storage device, the at least one processor configured to:

provide a user-definable strictness level indicative of a tolerable amount of unacceptable characters

access unidentified data from at least one data storage device;

examine the unidentified data to detect at least one application-specific data pattern associated with at least one application;

for each detected application-specific data pattern, execute an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application, wherein the application-specific validation process comprises:

determining an amount of unacceptable characters present in a portion of the unidentified data, the unacceptable characters being indicative of data that is not associated with any desired application, wherein the unacceptable characters are null characters, and wherein the amount of unacceptable characters is determined based on a percentage of null characters present in the portion of the unidentified data; and

determining whether the portion of the unidentified data is valid based upon the amount of unacceptable characters and the strictness level; and

if it is determined that the unidentified data includes valid data associated with the corresponding application, then recover the valid data.

2. The system of claim 1 , wherein the unidentified data includes data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data.

3. The system of claim 1 , wherein the application-specific data pattern includes at least one user identifier for the at least one application, the user identifier being associated with at least one user of the data storage device.

4. The system of claim 3 , wherein the at least one processor is configured to obtain the at least one user identifier by searching that data storage device at specific locations that are known to store user identifiers associated with the at least one application.

5. The system of claim 1 , wherein the at least one processor is further configured to execute the application-specific validation process by:

(a) determining a date associated with a portion of the unidentified data located near that application-specific data pattern; and

(b) comparing the date against provided date ranges to filter out invalid data.

6. The system of claim 1 , wherein the at least one processor is further configured to execute the application-specific validation process by determining whether expected data for the application is stored at expected locations for the application.

7. The system of claim 6 , wherein the at least one processor is further configured to check whether the data stored in the expected locations includes non-readable characters to determine whether the portion of the unidentified data is valid.

8. The system of claim 1 , wherein the at least one processor is further configured to execute the application-specific validation process by checking data surrounding the portion of the unidentified data to determine that that portion of data is not associated with another application.

9. The system of claim 1 , wherein the at least one processor is further configured to limit the search to selected locations on the data storage device for application-specific data.

10. The system of claim 9 , wherein the at least one processor is further configured to:

(a) provide a number of user-selectable options to select one or more applications to search; and

(b) determine the search locations based upon the options selected.

11. The system of claim 1 , wherein the at least one processor is further configured to execute the application-specific validation process by conducting semantic error checking.

12. The system of claim 1 , further comprising a second data storage device configured to removably connect with the at least one processor and provide computer-executable instructions to configure the at least one processor.

13. The system of claim 1 , further comprising a third data storage device configured to removably connect with the at least one processor, wherein the at least one processor is configured to output the valid data to the third data storage device such that the valid data do not overwrite the unidentified data in the data storage device.

14. A computer-implemented method for locating application-specific data, the method comprising:

providing a user-definable strictness level indicative of a tolerable amount of unacceptable characters;

accessing unidentified data from at least one data storage device;

examining the unidentified data to detect at least one application-specific data pattern associated with at least one application;

for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application, wherein the application-specific validation process comprises:

determining an amount of unacceptable characters present in a portion of the unidentified data, the unacceptable characters being indicative of data that is not associated with any desired application, wherein the unacceptable characters are null characters, and wherein the amount of unacceptable characters is determined based on a percentage of null characters present in the portion of the unidentified data; and

determining whether the portion of the unidentified data is valid based upon the amount of unacceptable characters and the strictness level; and

if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.

15. The method of claim 14 , wherein the application-specific validation process comprises:

(a) determining a date associated with a portion of the unidentified data located near that application-specific data pattern; and

(b) comparing the date against provided date ranges to filter out invalid data.

16. The method of claim 14 , further comprising:

(a) providing a number of user-selectable options to select one or more applications to search;

(b) determining search locations based upon the options selected; and

(c) limiting the search to the determined search locations on the data storage device for application-specific data.

Assignments (6)
SECURITY INTEREST Recorded Apr 6, 2023
From: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
To: OWL ROCK TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 063248/0122 →
RELEASE OF SECURITY INTEREST Recorded Apr 5, 2023
From: ROYAL BANK OF CANADA
To: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
Reel/Frame 063231/0372 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 057797 FRAME: 0493. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 1, 2021
From: MAGNET FORENSICS INVESTCO, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 058037/0964 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2021
From: MAGNET FORENSICS INVESTCO, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 057797/0493 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2021
From: MAGNET FORENSICS INC.
To: MAGNET FORENSICS INVESTCO INC.
Reel/Frame 054951/0604 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2012
From: SALIBA, JAD JOHN
To: MAGNET FORENSICS INC.
Reel/Frame 029463/0954 →
Continuity (2)
Provisional Application 61579325 · Dec 22, 2011
Related Publication 20130166517A1 · Jun 27, 2013