INTERACTIVE CASE MANAGEMENT PLATFORM
Embodiments of the present disclosure are directed to a method for processing computer readable electronic files in an investigation in a computer system including a processor coupled to a display and an electronic storage device coupled to the processor. The method includes the processor accessing the electronic files and related data from a data source. The accessed files and related data are culled by the processor based on predetermined filter criteria. The processor stores the remaining files and related data in a third-party data repository and maps a set of electronic files and related data stored in the third-party data repository into a predetermined database schema. The mapped files and related data are analyzed by the processor, which applies a status decision on them. The analyzed electronic files and related data are submitted to a third-party e-discovery processing application based on the applied status decision.
1 . A method of mapping computer readable electronic files to a schema allowing investigation in a computer system including at least one processor, at least one electronic storage device coupled to the at least one processor and at least one display coupled to the at least one processor comprising:
the at least one processor accessing the electronic files and data related to the electronic files from a data source;
the at least one processor culling at least one of the accessed files and related data based on predetermined filter criteria:
the at least one processor storing the remaining files and related data in a third-party data repository:
the at least one processor mapping a set of electronic files and related data stored in the third-party data repository into a predetermined database schema;
the at least one processor obtaining the mapped files and related data from the predetermined database schema and analyzing the mapped files and related data obtained from the predetermined database schema;
the at least one processor applying a status decision on the analyzed files and related data; and
the at least one processor submitting at least one analyzed electronic file and related data to a third-party e-discovery processing application based on the applied status decision.
2 . The method of claim 1 wherein the culling further comprises:
the at least one processor determining a hash value of each electronic file;
the at least one processor receiving search criterion including one or more of file system date range, file type, file path, or whether the hash value can be found in a list of hash values for electronic files known to be irrelevant to the investigation;
the at least one processor comparing each electronic file and/or the associated file system information to the received search criterion to determine the files that meet the search
criterion as a positive result;
the at least one processor, when the hash value is selected as one of the search criterion, determining whether the hash value is not on the list of hash values as a positive result; and
the at least one processor providing the electronic files with positive results to an e-discovery application provided on the computer system and populating an electronic file with identifying information concerning those electronic files not resulting in a positive result.
3 . The method of claim 2 wherein the culling further comprises:
the at least one processor receiving the list of hash values for electronic files known to be irrelevant;
at least one processor storing in the at least one storage device all hash values with predetermined digits in common with other hash values in the list of hash values in tables, wherein the number of predetermined digits is between one and less than all of the digits in the hash values;
the at least one processor receiving the hash value of each electronic file;
at least one processor identifying the table including the hash values having the predetermined digits in common with the received hash value;
at least one processor searching for the received hash value in the identified table stored in the at least one electronic storage device;
the at least one processor determining a positive result when the received hash value is not in the identified table; and
the at least one processor not indicating a positive result when the at least one processor determines that the received hash value is in the identified table.
4 . The method of claim 1 further comprising:
the at least one processor storing computer readable electronic files of the communications in the at least one electronic storage device;
the at least one processor mapping a plurality of communication addresses associated with a plurality of communicators to a single communication party; and
the at least one processor reporting or graphically displaying on the at least one display the communications wherein all communications involving the plurality of communication addresses are treated as involving the single communication party.
5 . The method of claim 1 wherein the analyzing further comprises:
the at least one processor storing computer readable electronic files and associated data corresponding to communications associated with the investigation from a group of custodians in the at least one storage device;
the at least one processor identifying source and destination address data included in the electronic files and associated data for the communications;
the at least one processor using the electronic files and related data to determine the number and direction of the communications among the source and destination addresses;
the at least one processor graphically representing communications by establishing a node for each of the source and destination addresses and extending lines between the nodes
to represent a number and direction of communications between addresses associated with the nodes; and
the at least one processor indicating on the graphical representation custodians not included in the group of custodians from whom electronic files and associated data should be considered in the investigation.
6 . The method of claim 1 wherein the analyzing further comprises:
the at least one processor receiving at least one facet for the basis of the selecting and at least one value associated with each facet, the at least one facet including custodians of the electronic files, dates associated with the electronic files, e-mail domains associated with e-mails represented by the electronic files, file types of the electronic files, terms included within the electronic files, or current states of the electronic files or any combination thereof;
the at least one processor filtering for computer readable electronic files stored in the at least one electronic storage device meeting the at least one value associated with the at least one facet received by the at least one processor;
the at least one processor displaying on the at least one display metadata associated with the electronic files identified in the filtering;
the at least one processor causing contents of an electronic file selected based on the metadata to be displayed on the at least one display; and
the at least one processor recording an indication from a user as to whether or not an electronic file is responsive to an investigation.
7 . The method of claim 1 wherein the analyzing further comprises:
the at least one processor identifying all electronic files stored in the at least one electronic storage device obtained from one or more specified custodians of electronic files;
the at least one processor determining a date associated with each of the identified electronic files;
the at least one processor determining a number of electronic files associated with the specified custodians in each of a series of time segments over a period of time;
the at least one processor causing at least one display coupled to the at least one processor to display the number of electronic files in each of the series of time segments; and
the at least one processor causing the at least one display to illustrate those time segments with large and/or small numbers compared to other time segments.
8 . The method of claim 1 wherein the analyzing further comprises:
the at least one processor receiving a plurality of search terms and/or electronic file metadata elements to be searched;
the at least one processor conducting a search in the electronic files for each search term and/or metadata element;
the at least one processor determining a number of electronic files including each search term and/or metadata element and a number of electronic files including each search term and/or metadata element and no other of the search terms or metadata elements; and
the at least one processor causing the numbers to be displayed on the at least one display.
9 . The method of claim 1 further comprising for each new electronic file to be added to the collection:
the at least one processor determining a hash value of the new electronic record;
the at least one processor determining whether the hash value of the new electronic file matches a hash value of an electronic file already in the collection;
when the hash value of the new electronic file does not match the hash value of any electronic file already in the collection, the at least one processor adding the new electronic file and its hash value to the collection stored in the at least one storage device; and
when the hash value of the new electronic file matches the hash value of an electronic file already in the collection, the at least one processor linking an identity of the new electronic
file to the electronic file already in the collection with the matching hash value without storing the new electronic file in the collection.
10 . A computer system for mapping computer readable electronic files to a schema allowing investigation comprising:
at least one processor;
at least one electronic storage device coupled to the at least one processor; and at least one display coupled to the at least one processor, wherein:
the at least one processor access the computer readable electronic files and related data from a data source;
the at least one processor culls at least one of the accessed files and related data based on predetermined filtered criteria:
the at least one processor stores remaining files and related data in a third-party data repository;
the at least one processor maps a set of electronic files and related data stored in a third-party data repository into a predetermined database schema;
the at least one processor obtains the mapped files and related data from the predetermined database schema and analyzes the mapped files and related data obtained from the predetermined database schema;
the at least one processor applies a status decision on the analyzed electronic files and related data; and
the at least one processor submits at least one analyzed electronic file and related data to an e-discovery reviewing application based on the applied status decision.
11 . The computer system of claim 10 wherein the culling further comprises:
the at least one processor determining a hash value of each electronic file,
the at least one processor receiving search criterion including one or more of file system date range, file type, file path, or whether the hash value can be found in a list of hash values for electronic files know to be irrelevant to the investigation,
the at least one processor comparing each electronic file and/or the associated file system information to the received search criterion to determine the files that meet the search criterion as a positive result,
at least one processor, when the hash value is selected as one of the search criterion, determining whether the hash value is not on the list of hash values as a positive result, and
at least one processor providing the electronic files with positive results to an e-discovery application provided on the computer system and populating an electronic file with
identifying information concerning those electronic files not resulting in a positive result.
12 . The computer system of claim 11 wherein the culling further comprises:
at least one processor receiving the list of values for electronic files known to be irrelevant to the investigation;
the at least one processor storing in at least one electronic storage device all hash values with predetermined digits in common with other hash values in the list of hash values in tables, wherein the number of predetermined digits is between one and less than all of the digits in the hash values;
the at least one processor receiving a hash value of an electronic file;
the at least one processor identifying the table including the hash values having the predetermined digits in common with the received hash values;
the at least one processor searching for the received hash value in the identified table stored in the at least one electronic storage device;
the at least one processor determining a positive result when the received hash value is not in the identified table; and
the at least one processor does not indicate a positive result when the at least one processor determining that the received hash value is in the identified table.
13 . The computer system of claim 10 wherein:
the at least one processor stores computer readable electronic files of the communications in the at least one electronic storage device;
the at least one processor maps a plurality of communication addresses associated with a plurality of communicators to a single communication party; and
the at least one processor reports or graphically displays the communications on the at least one display wherein all communications involving the plurality of communication
addresses are treated as involving the single communication party.
14 . The computer system of claim 10 wherein the at least one processor performs the analyzing by:
the at least one processor storing computer readable electronic files and associated data corresponding to communications associated with the investigation from a group of custodians in the at least one storage device;
the at least one processor identifying source and destination address data included in the electronic files and associated data for the communications;
the at least one processor using the electronic files and related data to determine the number and direction of the communications among the source and destination addresses;
the at least one processor graphically representing communications on the display by establishing a node for each of the source and destination addresses and extending lines between the nodes to represent a number and direction of communications between the addresses associated with the nodes; and
the at least one display displaying the graphical representation to identify custodians not included in the group of custodians from whom electronic files and associated data.
15 . The computer system of claim 10 wherein the at least one processor performs the analyzing by:
the at least one processor receiving at least one facet for the basis of the selecting and at least one value associated with each facet, the at least one facet including domains of the electronic files, dates associated with the electronic files, e-mail domains associated with e-mails represented by the electronic files, file types of the electronic files, terms included within the electronic files, or current states of the electronic files, or any combination thereof:
the at least one processor filtering for computer readable electronic files stored in the at least one storage device meeting the at least one value associated with the at least one facet received by the at least one processor;
the at least one processor displaying on the at least one display metadata associated with the electronic files identified in the filtering;
the at least one processor causing contents of an electronic file selected based on the metadata to be displayed on the at least one display; and
the at least one processor recording an indication from a user as to whether or not an electronic file is responsive to an investigation.
16 . The computer system of claim 10 wherein the at least one processor performs the analyzing by:
the at least one processor identifying all electronic files stored in the at least one storage device obtained from one or more specified custodians of electronic files;
the at least one processor determining a date associated with each of the identified electronic files;
the at least one process determining a number of electronic files associated with the specified custodians in each of a series of time segments over a period of time;
the at least one processor causing the at least one display to display the number of electronic files in each of the series of time segments; and
the at least one processor causing the at least one display to illustrate those time segments with large and/or small numbers compared to other time segments.
17 . The computer system of claim 10 wherein the at least one processor performs the analyzing by:
the at least one processor receiving a plurality of search terms and/or electronic metadata elements to be searched;
the at least one processor conducting a search in the electronic files stored in the at least one storage device for each search term and/or metadata element;
the at least one processor determining a number of electronic files including each search term and/or metadata element and a number of electronic files including each search term and/or metadata element and no other of the search terms or metadata elements; and
the at least one processor causing the numbers to be displayed on the at least one display.
18 . The computer system of claim 10 wherein:
the at least one processor determines a hash value of each new electronic record to be added to the collection;
the at least one processor determines whether the hash value of the new electronic file matches a hash value of an electronic file already in the collection;
when the hash value of the new electronic file does not match the hash value of any electronic file already in the collection, the at least one processor adds the new electronic file and its hash value to the collection stored in the at least one electronic storage device; and
when the hash value of the new electronic file matches the hash value of an electronic file already in the collection, the at least one processor links an identify of the new electronic file to the electronic file already in the collection with the matching hash value without storing the new electronic file in the collection.