WO2007075813A2

Systems and methods for enterprise-wide data identification, sharing and management, and methods for searching forensic data

Abstract

A system and method of automatically identifying relevant or suspect data during a digital forensic investigation. Input raw data are extracted from various digital data sources. The system determines to which one or more identification modules the unknown raw data should be delivered to for processing. This determination is based on the type of data in the extracted raw data coming into the application. Suspect or relevant data that are identified includes that data that are identical to or similar to the extracted unknown raw data. If there are suspect data, the system transmits a message or alert to interested parties or stores the findings/report on a storage device. In this manner, the suspect data are identified automatically, without intervention by a human being. Identification modules are invoked in a search markup language interpreter and the one or more identification modules are expressed in a search markup language specifically for digital forensics and receives parameters from the search language for processing. Furthermore, a component for conducting digital forensic searches is described. The component has a header; one or more search markup language programs, and a data features section. The component, also referred to as a search pack, enables a first entity, such as an investigation agency, to share its suspect and sensitive data with a second entity, such as another investigative agency, in a manner that allows the second agency to utilize the suspect data while not revealing the actual content of the sensitive data to the second agency. The second agency can perform comparisons and other operations on the sensitive data without having to know the actual content of the data. The search pack allows an investigative agency to define an investigative strategy for a particular case via the search markup language programs and by the data features that it includes in the search pack. Thus, by sharing search packs among agencies, an agency can share or inform others of that agency's theory of the case and investigative goal. Search packs can also be updated automatically as new information is learned about a particular case. A search pack is updated is determined by the agency that created it and manages it.

WO2007075813A2, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

7 claims: 3 independent, 4 dependent

  1. 1
    CLAIMS We claim:1. A digital forensic search software component embodied in a computer-readable storage medium, the software component comprising: a header;a search markup language program;a data features section containing features of data, wherein the software component enables a first entity to share the suspect data with a second entity in a manner that enables utilization of the suspect data by the second entity while not revealing the actual content of the sensitive data to the second entity;and whereby the first entity is able to define an investigative strategy for a particular case.
  2. 4
    A computer software component as recited in claim wherein the search markup language section and the data features section enable the first entity to share the investigative strategy for the particular case with the second entity.
  3. 5
    A method of automatically identifying relevant data during a digital forensic investigation, the method comprising:extracting raw data from one or more digital data sources, thereby producing extracted unknown raw data;determining which ones of a plurality of one or more identification modules, the unknown raw data should be delivered to for processing wherein the determination is based on categories of data comprising the extracted unknown raw data;within the determined ones of the identification modules, any relevant data in the extracted unknown raw data, wherein relevant data are one of data identical to and similar to the extracted unknown raw data;and transmitting a signal if there is any suspect data, whereby relevant data are identified are automatically, without intervention by a human being.