Systems and methods for graphical exploration of forensic data
First Claim
Patent Images
1. A method of examining digital forensic data using a viewer computer comprising a memory and a processor, the digital forensic data extracted from at least one target device by a forensic data retrieval application, the method comprising:
- providing a forensic data investigation application to the viewer computer;
receiving, at the viewer computer, a data collection generated by the forensic data retrieval application, the data collection comprising a plurality of data items extracted from the at least one target device, wherein the data items correspond to textual data stored on the at least one target device;
scanning the data collection to identify a plurality of data artifacts, wherein at least one of the plurality of data artifacts is a structured representation of one or more of the plurality of data items that defines a subject-predicate relationship thereof;
for a first artifact in the plurality of artifacts, determining a first attribute associated with the first artifact, and creating a first ontological set associated with the first attribute;
displaying the first ontological set and the plurality of ontological sets in an ontological display in a graphical user interface, wherein each of the plurality of ontological sets are displayed respectively as nodes in a graph;
receiving a selection of the first ontological set in the forensic data investigation application;
determining that the first ontological set is related to the plurality of ontological sets; and
for each respective set in the plurality of ontological sets, determining a respective predicate relationship between the first ontological set and the respective set, and displaying a respective oriented edge connecting a first node representing the first ontological set and a respective node representing the respective set, wherein each respective oriented edge is oriented based on the respective predicate relationship between the first ontological set and the respective set.
6 Assignments
0 Petitions
Accused Products
Abstract
Methods and apparatus for examining digital forensic data using a viewer computer. Forensic data collections are provided to the viewer computer, which can format the data artifacts according to a variety of display types and presentation formats, to facilitate review and reporting by a user. A relation graph presentation format is provided for visual exploration of data relationships.
-
Citations
26 Claims
-
1. A method of examining digital forensic data using a viewer computer comprising a memory and a processor, the digital forensic data extracted from at least one target device by a forensic data retrieval application, the method comprising:
-
providing a forensic data investigation application to the viewer computer; receiving, at the viewer computer, a data collection generated by the forensic data retrieval application, the data collection comprising a plurality of data items extracted from the at least one target device, wherein the data items correspond to textual data stored on the at least one target device; scanning the data collection to identify a plurality of data artifacts, wherein at least one of the plurality of data artifacts is a structured representation of one or more of the plurality of data items that defines a subject-predicate relationship thereof; for a first artifact in the plurality of artifacts, determining a first attribute associated with the first artifact, and creating a first ontological set associated with the first attribute; displaying the first ontological set and the plurality of ontological sets in an ontological display in a graphical user interface, wherein each of the plurality of ontological sets are displayed respectively as nodes in a graph; receiving a selection of the first ontological set in the forensic data investigation application; determining that the first ontological set is related to the plurality of ontological sets; and for each respective set in the plurality of ontological sets, determining a respective predicate relationship between the first ontological set and the respective set, and displaying a respective oriented edge connecting a first node representing the first ontological set and a respective node representing the respective set, wherein each respective oriented edge is oriented based on the respective predicate relationship between the first ontological set and the respective set. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
Specification