IP Library Granted Patent US 11,500,938
Granted Patent B2
US 11,500,938 · App. 15/487,168 · Granted Nov 15, 2022

Systems and methods for collecting digital forensic evidence

Inventors: Nicholas Bruce Alexander Cosentino (Waterloo, CA); Christine McGarry (Waterloo, CA); Matthew Moody (Waterloo, CA); Christopher Sippel (Waterloo, CA)
Assignee: Magnet Forensics Investco Inc.
G06F16/90344G06F16/9032G06Q10/00G06Q50/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,500,938
App. No.
15/487,168
Granted
Nov 15, 2022
Kind
B2
Abstract

Methods and apparatus for acquiring and analyzing digital forensic data using a computing device. Forensic data collections are retrieved by a computing device, and artifacts can be identified according to a variety of display types and presentation formats specified in an extensible format, to facilitate review and reporting by a user.

Claims (23)

1. A method of retrieving digital forensic data from at least one target device using a computing device comprising a memory and a processor, the method comprising:

receiving an artifact definition and a mapping definition, the artifact definition comprising a database-type artifact definition defining at least a first pattern to be matched and a fragment-type artifact definition defining at least a second pattern to be matched, wherein the first pattern comprises comprising at least one database parsing definition comprising a database query and the second pattern comprises at least one carving definition;

adding the artifact definition to a plurality of artifact definitions in the memory;

acquiring data from the at least one target device, the data stored on a data storage device of the at least one target device, the data comprising file metadata and file contents;

loading the artifact definition from the memory;

scanning the data first based upon the fragment-type artifact definition, and subsequently based upon the database-type artifact definition to identify a data subset that matches the first and second patterns;

when the first and second patterns are identified, extracting the data subset from the data based on the at least one carving definition and the at least one database parsing definition, the data subset selected from the group consisting of a database artifact that matches the database-type artifact definition, a fragment artifact that matches the fragment-type artifact definition, and both the database artifact and the fragment artifact; and

according to the mapping definition, generating a data fragment record in a forensic database based on the data subset, wherein the mapping definition maps elements of the data subset, as extracted based on the at least one carving definition and the at least one database parsing definition, to the data fragment record.

2. The method of claim 1 , wherein the plurality of patterns comprises a source definition.

3. The method of claim 2 , wherein the source definition comprises a filename.

4. The method of claim 2 , wherein the source definition comprises a partial filename.

5. The method of claim 2 , wherein the source definition comprises a regular expression.

6. The method of claim 1 , wherein the at least one database parsing definition comprises a database table name.

7. The method of claim 1 , wherein the at least one carving definition comprises a header data pattern.

8. The method of claim 7 , wherein the header data pattern is a byte array.

9. The method of claim 7 , wherein the header data pattern is a regular expression.

10. The method of claim 7 , wherein the header data pattern further comprises a byte offset.

11. The method of claim 7 , wherein the at least one carving definition comprises at least one of a footer data pattern and a length expression.

12. The method of claim 1 , wherein the mapping definition comprises at least one of a source database column name, a forensic database column name, a data type and a category.

13. The method of claim 1 , wherein the artifact definition is stored in a file.

14. The method of claim 13 , wherein the file is editable by a user of the computing device.

15. A non-transitory computer-readable medium storing computer-executable instructions, the instructions when executed by a computer processor for causing the computer processor to carry out the method of claim 1 .

16. A computing device comprising a memory and a processor, the processor configured to carry out the method of claim 1 .

Assignments (3)
SECURITY INTEREST Recorded Apr 6, 2023
From: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
To: OWL ROCK TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 063248/0122 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2022
From: COSENTINO, NICHOLAS BRUCE ALEXANDER; MCGARRY, CHRISTINE; MOODY, MATTHEW; SIPPEL, CHRISTOPHER
To: MAGNET FORENSICS INC.
Reel/Frame 059506/0087 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2021
From: MAGNET FORENSICS INC.
To: MAGNET FORENSICS INVESTCO INC.
Reel/Frame 055019/0151 →
Continuity (2)
Provisional Application 62321869 · Apr 13, 2016
Related Publication 20170300594A1 · Oct 19, 2017