IP Library Granted Patent US 11,036,714
Granted Patent B2
US 11,036,714 · App. 14/928,013 · Granted Jun 15, 2021

Systems and methods for locating application specific data

Inventor: Jad John Saliba (Puslinch, CA)
Assignee: Magnet Forensics Investco Inc.
G06F16/2365G06F16/245G06F16/9535G06F21/57G06F21/64G06F21/78G06Q10/10G06Q50/01H04L63/308
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,036,714
App. No.
14/928,013
Granted
Jun 15, 2021
Kind
B2
Abstract

A system and a method for locating application-specific data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data. The method includes accessing unidentified data from at least one data storage device; examining the unidentified data to detect at least one application-specific data pattern associated with at least one application; for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application; and if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.

Claims (41)

1. A system for locating application-specific data comprising:

at least one data storage device, having unidentified data stored therein;

at least one processor operatively coupled to the at least one data storage device, the at least one processor configured to:

provide a user-definable strictness level indicative of a tolerable amount of unacceptable characters;

access unidentified data from at least one data storage device, wherein the unidentified data is data stored in sectors or addresses of the at least one data storage device that are marked as unallocated;

examine the unidentified data to detect a plurality of application-specific data patterns, each of the application-specific data patterns indicative of respective applications in a plurality of software applications;

for each application-specific data pattern detected in the unidentified data, determine that said application-specific data pattern is associated with two or more applications and, in response to determining that said application-specific data pattern is associated with two or more applications, execute an application validation process specific for each of said associated two or more applications, wherein the at least one processor is further configured to execute each application-specific validation process by:

determining an amount of unacceptable characters present in a portion of the unidentified data, the unacceptable characters being indicative of data that is not associated with any desired application; and

determining that the portion of the unidentified data passes the application-specific validation process based upon the amount of unacceptable characters and the user-definable strictness level; and

in response to determining that the unidentified data passes the application-specific validation process corresponding to the associated application, recover relevant data from the portion of data and associate said relevant data with the corresponding application.

2. The system of claim 1 , wherein the unidentified data includes data that has been previously deleted.

3. The system of claim 1 , wherein the at least one processor is configured to output the valid data to a second data storage device such that the valid data do not overwrite the unidentified data in the data storage device.

4. The system of claim 1 , wherein the application-specific data pattern includes at least one user identifier for the at least one application, the user identifier being associated with at least one user of the data storage device.

5. The system of claim 1 , wherein the at least one processor is further configured to execute the application-specific validation process by: determining whether data stored by the application is stored at address off-sets based on the location of the application-specific pattern.

6. The system of claim 1 , wherein the unacceptable characters are null characters with a hexadecimal value of 0x00.

7. The system of claim 6 , wherein determining whether the portion of the unidentified data is valid based upon the amount of unacceptable characters and the user-definable strictness level comprises determining whether a percentage of the unidentified data that is null characters is acceptable as determined by the user-definable strictness level.

8. The system of claim 1 , wherein the at least one processor is further configured to provide a number of user-selectable options to select one or more applications to search and determine the search locations based upon the options selected.

9. The system of claim 1 , further comprising a second data storage device configured to removably connect with the at least one processor and provide computer-executable instructions to configure the at least one processor.

10. A method of locating application-specific data, the method comprising:

providing a user-definable strictness level indicative of a tolerable amount of unacceptable characters;

accessing unidentified data from at least one data storage device, wherein the unidentified data is data stored in sectors or addresses of the at least one data storage device that are marked as unallocated;

examining the unidentified data to detect a plurality of application-specific data patterns, each of the application-specific data patterns indicative of respective applications in a plurality of software applications;

for each application-specific data pattern detected in the unidentified data, determining that said application-specific data pattern is associated with two or more applications and, in response to determining that said application-specific data pattern is associated with two or more applications, executing an application validation process specific for each of said associated two or more applications, wherein each application-specific validation process comprises:

determining an amount of unacceptable characters present in the portion of the unidentified data, the unacceptable characters being indicative of data that is not associated with any desired application; and

determining that the portion of the unidentified data passes the application-specific validation process based upon the amount of unacceptable characters and the user-definable strictness level; and

in response to determining that the unidentified data passes the application-specific validation process corresponding to the associated application, recovering relevant data from the portion of data and associating said relevant data with the corresponding application.

11. The method of claim 10 , wherein the unidentified data includes data that has been previously deleted.

12. The method of claim 10 , wherein the application-specific data pattern includes at least one user identifier for the at least one application, the user identifier being associated with at least one user of the data storage device.

13. The method of claim 10 , wherein the at least one user identifier is obtained by searching the data storage device at specific locations, the locations being known to store user identifiers associated with the at least one application.

14. The method of claim 10 , wherein the application-specific validation process includes determining whether data stored by the application is stored at address offsets based on the location of the application-specific pattern.

15. The method of claim 10 , wherein the unacceptable characters are null characters with a hexadecimal value of 0x00.

16. The method of claim 15 , wherein determining whether the portion of the unidentified data is valid based upon the amount of unacceptable characters and the user-definable strictness level comprises determining whether a percentage of the unidentified data that is null characters is acceptable as determined by the user-definable strictness level.

17. The method of claim 10 , wherein the method further comprises providing a number of user-selectable options to select one or more applications to search, and the search locations are determined based upon the options selected.

18. A non-transitory computer-readable storage medium comprising instructions which when executed on a computer cause the computer to execute a method of locating application-specific data, the method comprising:

providing a user-definable strictness level indicative of a tolerable amount of unacceptable characters;

accessing unidentified data from at least one data storage device, wherein the unidentified data is data stored in sectors or addresses of the at least one data storage device that are marked as unallocated;

examining the unidentified data to detect a plurality of application-specific data patterns, each of the application-specific data patterns indicative of respective applications in a plurality of software applications;

for each application-specific data pattern detected in the unidentified data, determining that said application-specific data pattern is associated with two or more applications and, in response to determining that said application-specific data pattern is associated with two or more applications, executing an application validation process specific for each of said associated two or more applications, wherein each application-specific validation process comprises:

determining an amount of unacceptable characters present in the portion of the unidentified data, the unacceptable characters being indicative of data that is not associated with any desired application; and

determining that the portion of the unidentified data passes the application-specific validation process based upon the amount of unacceptable characters and the user-definable strictness level; and

in response to determining that the unidentified data passes the application-specific validation process corresponding to the associated application, recovering relevant data from the portion of data and associating said relevant data with the corresponding application.

Assignments (6)
SECURITY INTEREST Recorded Apr 6, 2023
From: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
To: OWL ROCK TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 063248/0122 →
RELEASE OF SECURITY INTEREST Recorded Apr 5, 2023
From: ROYAL BANK OF CANADA
To: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
Reel/Frame 063231/0372 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 057797 FRAME: 0493. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 1, 2021
From: MAGNET FORENSICS INVESTCO, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 058037/0964 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2021
From: MAGNET FORENSICS INVESTCO, INC.
To: ROYAL BANK OF CANADA
Reel/Frame 057797/0493 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2021
From: MAGNET FORENSICS INC.
To: MAGNET FORENSICS INVESTCO INC.
Reel/Frame 054951/0873 →
NUNC PRO TUNC ASSIGNMENT Recorded Nov 16, 2015
From: SALIBA, JAD
To: MAGNET FORENSICS INC.
Reel/Frame 037050/0039 →
Continuity (3)
Continuation 13711902 · Dec 12, 2012
Provisional Application 61579325 · Dec 22, 2011
Related Publication 20160048555A1 · Feb 18, 2016