IP Library Granted Patent US 12,363,134
Granted Patent B2
US 12,363,134 · App. 18/419,534 · Granted Jul 15, 2025

Method and system for forensic data tracking

Inventors: Steven V. Bacastow (Cumming, GA); Michael Royd Heuss (Alachua, FL)
Assignee: Quick Vault, Inc.
H04L63/1408G06F21/552H04L63/10H04L63/1433H04L63/20H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,134
App. No.
18/419,534
Granted
Jul 15, 2025
Kind
B2
Abstract

The present invention relates to a method and system for tracking the movement of data elements as they are shared and moved between authorized and unauthorized devices and among authorized and unauthorized users.

Claims (49)

1. A computing system comprising one or more network devices, the one or more network devices comprising one or more microprocessors and one or more memories that store executable instructions that, when executed by the one or more microprocessors, facilitate performance of operations, comprising:

receiving meta data associated with an endpoint, the meta data comprising:

an endpoint identifier that is indicative of the endpoint with which the meta data is associated, and

one or more of an electronic file name, a user identifier, and one or more data tags;

analyzing the meta data based on one or more of a configured setting and a policy;

determining, based on the analyzing of the meta data, a pattern of data activity that constitutes a deviation from normal behavior, wherein the deviation from normal behavior is determined based on a detected data activity that deviates from an average data activity for one or more of a user, a set of users, the endpoint, and a set of endpoints, wherein the detected data activity is determined by detecting that a significant volume of the meta data, relative to historical behavior, is associated with one or more of the user, the set of users, the endpoint, and the set of endpoints; and

in response to determining the deviation from normal behavior, performing one or more responsive actions.

2. The system of claim 1 , wherein the one or more data tags are capable of being used to determine a data classification associated with one or more of an electronic file and the endpoint.

3. The system of claim 1 , wherein the one or more data tags are indicative of a type of data included within or transmitted from the endpoint and wherein the deviation from normal behavior is based at least in part on the type of data included within an electronic file or transmitted from the endpoint.

4. The system of claim 1 , wherein the configured setting is stored in a settings database, and the configured setting relates to controlling user authorization to download data and user authorization to share data using the computing system.

5. The system of claim 1 , wherein the deviation from normal behavior is determined by the significant volume of the meta data exceeding a predetermined threshold relative to the historical behavior.

6. The system of claim 2 , wherein the data classification is usable to determine, based on the one or more of the configured setting and policy, whether data is unauthorized.

7. The system of claim 1 , wherein the policy comprises one or more of a standard policy, a customized policy, a data protection policy, a policy unique to an enterprise, and a foreign jurisdiction policy.

8. The system of claim 1 , wherein the one or more responsive actions comprises one or more of reporting, alerting, redacting, deleting, encrypting, and archiving.

9. The system of claim 1 , further comprising determining that the endpoint is unauthorized based on the one or more of the configured setting and policy.

10. The system of claim 9 , wherein the determining that the endpoint is unauthorized comprises determining that data associated with the endpoint is unauthorized.

11. The system of claim 10 , wherein the determining that data is unauthorized comprises determining that the data is unauthorized for downloading by a user.

12. The system of claim 10 , wherein the determining that the electronic file is unauthorized comprises determining that data is unauthorized for sharing by a user.

13. The system of claim 1 , wherein the detected data activity is based at least in part on a number of electronic files accessed by one or more of the user, the set of users, the endpoint, and the set of endpoints.

14. The system of claim 1 , wherein the detected data activity is based at least in part on a number of electronic files downloaded by one or more of the user, the set of users, the endpoint, and the set of endpoints.

15. The system of claim 1 , wherein the detected data activity is based at least in part on a number of electronic files shared by one or more of the user, the set of users, the endpoint, and the set of endpoints.

16. The system of claim 1 , wherein the deviation from normal behavior is related to a spike in activity for the user, the set of users, the endpoint, or the set of endpoints.

17. The system of claim 1 , wherein the one or more of the configured setting and the policy is associated with one or more of the user, the set of users, and the endpoint.

18. The system of claim 1 , wherein the endpoint identifier is one of an IP address, a URL, a software identifier and a computing device identifier.

19. A method related to computing forensics, the method comprising:

transmitting machine-executable instructions to one or more network devices comprising one or more processors and one or more memories, wherein the machine-executable instructions are stored in the one or more memories, and wherein the machine-executable instructions when executed by the one or more processors enable the one or more network devices to:

receive meta data associated with an endpoint, the meta data comprising:

an endpoint identifier that is indicative of the endpoint with which the meta data is associated, and

one or more of an electronic file name, a user identifier and one or more data tags;

analyze the meta data based on one or more of a configured setting and a policy;

determine, based on analyzing the meta data, a pattern of data activity that constitutes a deviation from a normal pattern of data activity, wherein the deviation from the normal pattern of data activity is determined by a percentage change of data activity compared to data activity for one or more of a user, a set of users, the endpoint, and a set of endpoints, wherein the percentage change of data activity is determined by detecting that a significant volume of the meta data, relative to historical behavior, is associated with one or more of the user, the set of users, the endpoint, and the set of endpoints; and

perform one or more responsive actions related to determining the pattern of data activity that constitutes the deviation from the normal pattern of data activity.

20. The method of claim 19 , wherein a software agent is resident on the endpoint to facilitate a collection and transmission of the meta data to the one or more network devices.

21. The method of claim 19 , wherein the one or more data tags is used to determine a data classification associated with the endpoint.

22. The method of claim 19 , wherein the one or more data tags is indicative of a type of data associated with the endpoint.

23. The method of claim 19 , wherein the configured setting relates to user authorization to access data stored on the endpoint.

24. The method of claim 19 , wherein the configured setting relates to user authorization to download data from the endpoint.

25. The method of claim 19 , wherein the configured setting relates to user authorization to share data from the endpoint.

26. The method of claim 19 , wherein the one or more responsive actions comprises one or more of a redaction of data, a deletion of data, an encryption of data, and sending an alert regarding the deviation from normal behavior.

27. The method of claim 19 , wherein the one or more responsive actions comprises predicting data breaches based on changes in data topology associated with the endpoint, wherein the change in data topology reflects the deviation from normal behavior.

28. The method of claim 27 , wherein the changes in data topology reflect that data of a specific data classification associated with the endpoint.

29. The method of claim 19 , wherein the percentage change of data activity is based at least in part on one or more of a number of files transmitted to the endpoint, a number of files downloaded from the endpoint, a number of file access attempts, and a number of classified files associated with the endpoint.

30. The method of claim 26 , wherein the alert may be generated based on an anomaly wherein a user has sent or received a number of files that exceeds the average number of files sent or received by the user or exceeds a preestablished threshold of total files sent or received.

31. The method of claim 19 , wherein the deviation from the normal pattern of data activity is determined by the significant volume of the meta data exceeding a predetermined threshold relative to the historical behavior.

32. A computing system comprising one or more network devices, the one or more network devices comprising one or more microprocessors and one or more memories that store executable instructions that, when executed by the one or more microprocessors, facilitate performance of operations, comprising:

receiving meta data associated with an endpoint, the meta data comprising:

an endpoint identifier that is indicative of the endpoint with which the meta data is associated, and

one or more of an electronic file name, a user identifier, an IP address, a URL, a software identifier and a computing device identifier;

determining, based on analyzing the meta data, a pattern of activity that constitutes a deviation from normal behavior, wherein the deviation from normal behavior is determined by detecting that a significant volume of the meta data, relative to historical behavior, is associated with one or more of a user, a set of users, the endpoint, a set of endpoints, the IP address, the URL, the software identifier, and the computing device identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2025
From: BACASTOW, STEVEN V.; HEUSS, MICHAEL ROYD
To: QUICKVAULT, INC.
Reel/Frame 070735/0322 →
Continuity (10)
Continuation 18305563 · Apr 24, 2023
Continuation 17244505 · Apr 29, 2021
Continuation 16695949 · Nov 26, 2019
Continuation 15965625 · Apr 27, 2018
Continuation 15406746 · Jan 15, 2017
Continuation 14853464 · Sep 14, 2015
Provisional Application 62186530 · Jun 30, 2015
Provisional Application 62082258 · Nov 20, 2014
Provisional Application 62049514 · Sep 12, 2014
Related Publication 20240171592A1 · May 23, 2024
References Cited (116)
US 5331136A · Koench et al. · 1994 [cited by applicant]
US 5566339A · Perholtz et al. · 1996 [cited by applicant]
US 5592618A · Micka et al. · 1997 [cited by applicant]
US 5659595A · Chanu et al. · 1997 [cited by applicant]
US 5696909A · Wallner · 1997 [cited by applicant]
US 5790074A · Rangedahl et al. · 1998 [cited by applicant]
US 5844776A · Yamaguchi et al. · 1998 [cited by applicant]
US 5903646A · Rackman · 1999 [cited by applicant]
US 5956733A · Nakano et al. · 1999 [cited by applicant]
US 5979753A · Rosia · 1999 [cited by applicant]
US 6003008A · Postrel et al. · 1999 [cited by applicant]
US 6062478A · Izaquirre et al. · 2000 [cited by applicant]
US 6166688A · Cromer et al. · 2000 [cited by applicant]
US 6170060B1 · Mott et al. · 2001 [cited by applicant]
US 6442682B1 · Pothapragada et al. · 2002 [cited by applicant]
US 6553348B1 · Hashimoto · 2003 [cited by applicant]
US 6574716B2 · Dovi · 2003 [cited by applicant]
US 6546441B1 · Lum · 2003 [cited by applicant]
US 6614349B1 · Proctor et al. · 2003 [cited by applicant]
US 6640217B1 · Scanlan et al. · 2003 [cited by applicant]
US 6704885B1 · Salas-Meza et al. · 2004 [cited by applicant]
US 6901511B1 · Ofsuka · 2005 [cited by applicant]
US 6950949B1 · Gilchrist · 2005 [cited by applicant]
US 7103684B2 · Chen et al. · 2006 [cited by applicant]
US 7143289B2 · Denning et al. · 2006 [cited by applicant]
US 7165154B2 · Coombs et al. · 2007 [cited by applicant]
US 7225208B2 · Midgley · 2007 [cited by applicant]
US 7229016B2 · Bravo · 2007 [cited by applicant]
US 7263190B1 · Moritz · 2007 [cited by applicant]
US 7269732B2 · Killian-Kehr · 2007 [cited by applicant]
US 7356510B2 · Durand et al. · 2008 [cited by applicant]
US 7356703B2 · Chebolu et al. · 2008 [cited by applicant]
US 7403743B2 · Welch · 2008 [cited by applicant]
US 7404088B2 · Giobbi · 2008 [cited by applicant]
US 7421516B2 · Minogue et al. · 2008 [cited by applicant]
US 7543053B2 · Goodman · 2009 [cited by applicant]
US 7561691B2 · Blight et al. · 2009 [cited by applicant]
US 7702922B2 · Hetzler · 2010 [cited by applicant]
US 7739402B2 · Roese et al. · 2010 [cited by applicant]
US 7818608B2 · DeMaio et al. · 2010 [cited by applicant]
US 8041677B2 · Sumner et al. · 2011 [cited by applicant]
US 8086688B1 · Bacastow · 2011 [cited by applicant]
US 8180735B2 · Ansari et al. · 2012 [cited by applicant]
US 8316102B2 · Matsuzaki et al. · 2012 [cited by applicant]
US 8862687B1 · Bacastow · 2014 [cited by applicant]
US 8868683B1 · Bacastow · 2014 [cited by applicant]
US 9166993B1 · Liu · 2015 [cited by applicant]
US 10498745B2 · Bacastow · 2019 [cited by applicant]
US 10999300B2 · Bacastow · 2021 [cited by applicant]
US 11637840B2 · Bacastow · 2023 [cited by applicant]
US 11895125B2 · Bacastow · 2024 [cited by examiner]
US 20020082925A1 · Herwig · 2002 [cited by applicant]
US 20020188856A1 · Worby · 2002 [cited by applicant]
US 20020193157A1 · Yamada et al. · 2002 [cited by applicant]
US 20030005193A1 · Seroussi et al. · 2003 [cited by applicant]
US 20030046034A1 · Kitamoto et al. · 2003 [cited by applicant]
US 20030050940A1 · Robinson · 2003 [cited by applicant]
US 20030055792A1 · Kinoshita et al. · 2003 [cited by applicant]
US 20030074575A1 · Hoberock et al. · 2003 [cited by applicant]
US 20030110371A1 · Yang et al. · 2003 [cited by applicant]
US 20030135418A1 · Shekhar et al. · 2003 [cited by applicant]
US 20030174167A1 · Poo et al. · 2003 [cited by applicant]
US 20030225971A1 · Oishi et al. · 2003 [cited by applicant]
US 20030233501A1 · Ma et al. · 2003 [cited by applicant]
US 20040001088A1 · Stancil et al. · 2004 [cited by applicant]
US 20040019742A1 · Wei et al. · 2004 [cited by applicant]
US 20040038592A1 · Yang · 2004 [cited by applicant]
US 20040039575A1 · Bum · 2004 [cited by applicant]
US 20040039851A1 · Tang et al. · 2004 [cited by applicant]
US 20040039854A1 · Estakhri et al. · 2004 [cited by applicant]
US 20040095382A1 · Fisher et al. · 2004 [cited by applicant]
US 20040187012A1 · Kohiyama et al. · 2004 [cited by applicant]
US 20050010768A1 · Light et al. · 2005 [cited by applicant]
US 20050010835A1 · Childs et al. · 2005 [cited by applicant]
US 20050081198A1 · Cho et al. · 2005 [cited by applicant]
US 20050125513A1 · Lam et al. · 2005 [cited by applicant]
US 20050138390A1 · Adams et al. · 2005 [cited by applicant]
US 20050144443A1 · Cromer et al. · 2005 [cited by applicant]
US 20050149394A1 · Postrel · 2005 [cited by applicant]
US 20050149684A1 · Sankaran et al. · 2005 [cited by applicant]
US 20050149745A1 · Ishidoshiro · 2005 [cited by applicant]
US 20050216466A1 · Miyamoto et al. · 2005 [cited by applicant]
US 20060010328A1 · Liu et al. · 2006 [cited by applicant]
US 20060041934A1 · Hetzler · 2006 [cited by applicant]
US 20060206720A1 · Harada et al. · 2006 [cited by applicant]
US 20060209337A1 · Atobe et al. · 2006 [cited by applicant]
US 20060253620A1 · Kang · 2006 [cited by applicant]
US 20070028304A1 · Brennan · 2007 [cited by applicant]
US 20070038681A1 · Pierce · 2007 [cited by applicant]
US 20070081508A1 · Madhaven et al. · 2007 [cited by applicant]
US 20070118847A1 · Sugimoto et al. · 2007 [cited by applicant]
US 20070143529A1 · Bacastow · 2007 [cited by applicant]
US 20070174911A1 · Kronenberg · 2007 [cited by applicant]
US 20070214047A1 · Antonello et al. · 2007 [cited by applicant]
US 20070245158A1 · Giobbi et al. · 2007 [cited by applicant]
US 20080022003A1 · Alve · 2008 [cited by applicant]
US 20080082813A1 · Chow et al. · 2008 [cited by applicant]
US 20080177755A1 · Stern et al. · 2008 [cited by applicant]
US 20110040641A1 · Bacastow et al. · 2011 [cited by applicant]
US 20120066759A1 · Chen et al. · 2012 [cited by applicant]
US 20130191355A1 · Bone et al. · 2013 [cited by applicant]
US 20130247185A1 · Viscuso et al. · 2013 [cited by applicant]
US 20140325609A1 · Bacastow · 2014 [cited by applicant]
CN 103700195A1 · 2014 [cited by applicant]
WO 03009620 · 2003 [cited by applicant]
International Searching Authority, International Search Report and Written Opinion, Jan. 14, 2016, Moscow, Russia, PCT/US/2015/049979. [cited by applicant]
Iomega Automatic Backup Manual Table of Contents (hereafter “IAB” archived on Dec. 22, 2002 at: http://web.archive.org/web/20021222172018/http://www.iomega.com/support/manuals/ioauto/main.html (linking to 22 pages—herea… [cited by applicant]
http://web.archive.org/web/20021030183837/www.iomega.com/support/manuals/ioauto/qs_setup.html (hereafter “IAB1”) (archived in 2002). [cited by applicant]
http://web.archive.org/web/20021223082620/www.iomega.com/support/manuals/ioauto/qs_schedule.html (hereafter “IAB11”) (archived in 2002). [cited by applicant]
http://web.archive.org/web/20021223081144/www.iomega.com/support/manuals/ioauto/qs_cache.html (hereafter “IAB12”) (archived in 2002). [cited by applicant]
http://web.archive.org/web/20021223075646/www.iomega.com/support/manuals/ioauto/qs_nomonitor.html (hereafter “IAB13”) (archived in 2002). [cited by applicant]
http://web.archive.org/web20021223081714/www.iomega.com/support/manuals/ioauto/qs_restore.html (hereafter “IAB15”) (archived in 2002). [cited by applicant]
Blaze, Matt. “A cryptographic file system for UNIX.” Proceedings of the 1st ACM conference on Computer and communications security. ACM, 1993. [cited by applicant]
Extended European Search Report for European Patent Application No. 15840841.9, issued Jan. 16. [cited by applicant]
Tan, Yu Shyang et al., “Tracking of Data Leaving the Cloud”, Jun. 25, 2012. [cited by applicant]
Oberheide, Jonathan Clarke et al., “Leveraging the Cloud for Software Security Services”, Jan. 1, 2012. [cited by applicant]