IP Library Granted Patent US 11,847,204
Granted Patent B2
US 11,847,204 · App. 16/990,561 · Granted Dec 19, 2023

Systems and methods for cloud-based management of digital forensic evidence

Inventors: Martin Barrow (Sheffield, GB); William Lindsay (Kitchener, CA); Gayathiri Thananjagen (Waterloo, CA)
Assignee: Magnet Forensics Inc.
G06F21/53G06F9/45558G06F21/57G06F2009/4557G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,847,204
App. No.
16/990,561
Granted
Dec 19, 2023
Kind
B2
Abstract

Systems and methods for cloud-based management of digital forensic evidence and, in particular, to systems and methods for enabling cloud-based digital forensic investigations.

Claims (39)

1. A forensic investigation system for conducting distributed digital forensic processing of a target device, the system comprising:

one or more agent computing devices comprising:

at least one data-collecting agent device operable to collect digital forensic data from the target device using a remote data acquisition software application installed on the at least one data-collecting agent device; and

at least one processing agent device operable to conduct at least a portion of the distributed digital forensic processing on the collected digital forensic data according to an investigation workflow including a digital forensic analysis routine comprising one or more processing tasks, the one or more processing tasks including refining the collected digital forensic data to identify or extract one or more data artifacts;

a central computing device for managing operation of the one or more agent computing devices for conducting the distributed digital forensic processing, the central computing device operable to communicate with the one or more agent computing devices via at least one data communication network to remotely deploy the remote data acquisition software application to the at least one data-collecting agent device for collecting the digital forensic data from the target device and refining the collected digital forensic data to identify or extract the one or more data artifacts, the central computing device further operable to assign each processing agent device to at least one of the one or more processing tasks, wherein the central computing device triggers each stage of the investigation workflow to occur in a distributed or localized manner based on available processing agent devices; and

a data storage device for storing the digital forensic data collected by the at least one data-collecting agent device from the target device.

2. The system of claim 1 , wherein the central computing device is operable to allocate the one or more agent computing devices based on a priority status of a forensic investigation associated with the collected digital forensic data.

3. The system of claim 1 , wherein the at least one data-collecting agent device is preconfigured to collect the digital forensic data from the target device.

4. The system of claim 1 , wherein the at least one data-collecting agent device is the target device.

5. The system of claim 1 , wherein the at least one data-collecting agent device is remotely provisioned to be operable to collect the digital forensic data.

6. The system of claim 5 , wherein, following remote provisioning, the central computing device is operable to transmit one or more commands to the at least one data-collecting agent device to collect the digital forensic data.

7. The system of claim 6 , wherein, in response to receiving the one or more commands, the at least one data-collecting agent device is operable to collect the digital forensic data and transmit the digital forensic data.

8. The system of claim 7 , wherein the at least one data-collecting agent device transmits the digital forensic data to the central computing device.

9. The system of claim 7 , wherein the at least one data-collecting agent device transmits the digital forensic data to the data storage device.

10. The system of claim 1 , wherein the one or more agent computing devices further comprise at least one virtual computing device.

11. The system of claim 10 , wherein the at least one virtual computing device is accessible by the central computing device via a virtual private network.

12. A method of conducting distributed digital forensic processing of a target device, the method comprising:

providing one or more agent computing devices including at least one data-collecting agent device and at least one processing agent device;

providing a central computing device, the central computing device operable to communicate with the one or more agent computing devices via at least one data communication network, the central computing device further operable to assign each processing agent device to one or more processing tasks, wherein the central computing device triggers each stage of an investigation workflow to occur in a distributed or localized manner based on available processing agent devices;

remotely deploying a remote data acquisition software application from the central computing device to the at least one data-collecting agent device for collecting digital forensic data from the target device and refining the collected digital forensic data to identify or extract one or more data artifacts;

collecting the digital forensic data via the at least one data-collecting agent device using the remote data acquisition software application installed on the at least one data-collecting agent device;

storing the digital forensic data collected by the at least one data-collecting agent device from the target device; and

conducting at least a portion of the distributed digital forensic processing on the collected digital forensic data at the least one processing agent device according to the investigation workflow including a digital forensic analysis routine comprising the one or more processing tasks, the one or more processing tasks including refining the collected digital forensic data to identify or extract the one or more data artifacts.

13. The method of claim 12 , further comprising the central computing device allocating the one or more agent computing devices based on a priority status of a forensic investigation associated with the collected digital forensic data.

14. The method of claim 12 , further comprising preconfiguring the at least one data-collecting agent device to collect the digital forensic data from the target device.

15. The method of claim 12 , wherein the at least one data-collecting agent device is the target device.

16. The method of claim 12 , further comprising remotely provisioning the at least one data-collecting agent device to collect the digital forensic data.

17. The method of claim 16 , wherein, following remote provisioning, the central computing device is operable to transmit one or more commands to the at least one data-collecting agent device to collect the digital forensic data.

18. The method of claim 17 , wherein the at least one data-collecting agent device collects the digital forensic data and transmits the digital forensic data in response to receiving the one or more commands.

19. The method of claim 18 , wherein the at least one data-collecting agent device transmits the digital forensic data to the central computing device.

20. The method of claim 18 , wherein the at least one data-collecting agent device transmits the digital forensic data to the data storage device.

21. The method of claim 12 , wherein the one or more agent computing devices further comprise at least one virtual computing device.

22. A non-transitory computer readable medium storing computer program instructions executable by at least one computer processor, which when executed by the at least one computer processor, cause the at least one computer processor to carry out a method of conducting distributed digital forensic processing of a target device, the method comprising:

providing one or more agent computing devices including at least one data-collecting agent device and at least one processing agent device;

providing a central computing device, the central computing device operable to communicate with the one or more agent computing devices via at least one data communication network, the central computing device further operable to assign each processing agent device to one or more processing tasks, wherein the central computing device triggers each stage of an investigation workflow to occur in a distributed or localized manner based on available processing agent devices;

remotely deploying a remote data acquisition software application from the central computing device to the at least one data-collecting agent device for collecting digital forensic data from the target device and refining the collected digital forensic data to identify or extract one or more data artifacts;

collecting the digital forensic data via the at least one data-collecting agent device using the remote data acquisition software application installed on the at least one data-collecting agent device;

storing the digital forensic data collected by the at least one data-collecting agent device from the target device; and

conducting at least a portion of the distributed digital forensic processing on the collected digital forensic data at the least one processing agent device according to the investigation workflow including a digital forensic analysis routine comprising the one or more processing tasks, the one or more processing tasks including refining the collected digital forensic data to identify or extract the one or more data artifacts.

Assignments (5)
SECURITY INTEREST Recorded Apr 6, 2023
From: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
To: OWL ROCK TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 063248/0122 →
RELEASE OF SECURITY INTEREST Recorded Apr 5, 2023
From: ROYAL BANK OF CANADA
To: MAGNET FORENSICS INC.; MAGNET FORENSICS INVESTCO, INC.
Reel/Frame 063231/0372 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONYANCE PREVIOUSLY RECORDED AT REEL: 057797 FRAME: 0479. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Nov 1, 2021
From: MAGNET FORENSICS INC.
To: ROYAL BANK OF CANADA
Reel/Frame 058082/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2021
From: MAGNET FORENSICS INC.
To: ROYAL BANK OF CANADA
Reel/Frame 057797/0479 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: BARROW, MARTIN; LINDSAY, WILLIAM; THANANJAGEN, GAYATHIRI
To: MAGNET FORENSICS INC.
Reel/Frame 053460/0410 →
Continuity (2)
Provisional Application 62885588 · Aug 12, 2019
Related Publication 20210049264A1 · Feb 18, 2021