×

Forensic software investigation

  • US 10,476,759 B2
  • Filed: 01/03/2018
  • Issued: 11/12/2019
  • Est. Priority Date: 07/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer system including instructions recorded on a non-transitory computer-readable medium and executable by at least one processor, the computer system comprising:

  • a server configured to at least manage forensic investigations of client assets associated with a client based on a forensic service agreement between the client and a cloud service provider in a cloud environment, wherein the forensic investigations include technical evidence generation for each client asset associated with the client, wherein the technical evidence generation comprises contextual reporting, and wherein the contextual reporting comprises separating audit data with respect to tenants of a multi-tenant environment and correlating the audit data with respect to a reported incident, the server including;

    a forensic service interface configured to at least establish the forensic service agreement between the client and the cloud service provider for servicing the forensic investigations of the client assets associated with the client, the forensic service interface providing multiple modes for the forensic service agreement, wherein the forensic service agreement includes a forensics as a service subscription, and under the forensics as a service subscription, the cloud service provider is configured to expose one or more forensic functionalities related to one or more of on-demand investigation, troubleshooting, auditing, or logging of forensic data related to the client assets associated with the client;

    a forensic data handler configured to at least acquire forensic data related to each client asset associated with the client, and generate one or more client inventory records for each client asset based on the forensic data related to each client asset, wherein the forensic data handler acquires the forensic data according to a selected mode of the multiple modes for the forensic service agreement; and

    a forensic engine configured to at least generate one or more client evidence records for each client asset based on each client inventory record generated for each client asset.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×