System and method for collecting forensic data via a mobile device
First Claim
1. A method for conducting forensic investigations by investigators on an investigations field, the method comprising:
- receiving a digital search warrant, the digital search warrant including a search parameter for conducting a forensic investigation of a target device, wherein the digital search warrant is machine-readable and can be presented in a human-readable format;
notifying a mobile device of the digital search warrant;
receiving a user command to download the digital search warrant in response to the notifying;
downloading the digital search warrant to a forensic investigation application executing at the mobile device in response to the received user command;
booting, by the forensic investigation application at the mobile device, the target device over a data communication link between the mobile device and the target device using an operating system stored in a memory at the mobile device such that the target device is executing the operating system on the target device from a memory address in the memory of the mobile device over the data communication link and the execution of the operating system from the memory address of the memory of the mobile device on the target device causes the forensic investigation application executing at the mobile device to search the target device without user involvement;
parsing, by the forensic investigation application executing at the mobile device, the machine-readable instructions of the digital search warrant to identify the search parameter to use on the target device, the search parameter of the digital search warrant including a keyword and a file extension identifying a type of file;
searching, by the forensic investigation application executing at the mobile device, electronic documents at the target device over the data communications link between the mobile device and the target device to identify a set of electronic documents on the target device that include the keyword of the search parameter and are the type of file specified by the file extension in the digital search warrant, wherein the searching of the documents at the target device comprises only searching the files of the type of file identified by the file extension without modification of a state of the target device;
retrieving, from the target device, the set of documents that include the search parameter without modifying a state of the target device, wherein the retrieving is done by the forensic investigation application executing at the mobile device over the data communications link between the mobile device and the target device; and
storing the set of documents on the mobile device.
2 Assignments
0 Petitions
Accused Products
Abstract
A system and method for conducting forensic investigations by investigators on an investigations field using a mobile device. A digital search warrant is downloaded to the mobile device prior to conducting the forensic investigation. The digital search warrant defines the search parameters of the search to be conducted, including key terms, file types, and the like. The mobile device is coupled to a target device in the investigations field that is the subject of the forensic investigation. The mobile device parses the digital search warrant and automatically identifies and collects data from the target device based on the parsed digital search warrant. The automatically identifying and collecting of the data is done without modifying a state of the target device to retain forensic integrity during the investigation process.
-
Citations
11 Claims
-
1. A method for conducting forensic investigations by investigators on an investigations field, the method comprising:
-
receiving a digital search warrant, the digital search warrant including a search parameter for conducting a forensic investigation of a target device, wherein the digital search warrant is machine-readable and can be presented in a human-readable format; notifying a mobile device of the digital search warrant; receiving a user command to download the digital search warrant in response to the notifying; downloading the digital search warrant to a forensic investigation application executing at the mobile device in response to the received user command; booting, by the forensic investigation application at the mobile device, the target device over a data communication link between the mobile device and the target device using an operating system stored in a memory at the mobile device such that the target device is executing the operating system on the target device from a memory address in the memory of the mobile device over the data communication link and the execution of the operating system from the memory address of the memory of the mobile device on the target device causes the forensic investigation application executing at the mobile device to search the target device without user involvement; parsing, by the forensic investigation application executing at the mobile device, the machine-readable instructions of the digital search warrant to identify the search parameter to use on the target device, the search parameter of the digital search warrant including a keyword and a file extension identifying a type of file; searching, by the forensic investigation application executing at the mobile device, electronic documents at the target device over the data communications link between the mobile device and the target device to identify a set of electronic documents on the target device that include the keyword of the search parameter and are the type of file specified by the file extension in the digital search warrant, wherein the searching of the documents at the target device comprises only searching the files of the type of file identified by the file extension without modification of a state of the target device; retrieving, from the target device, the set of documents that include the search parameter without modifying a state of the target device, wherein the retrieving is done by the forensic investigation application executing at the mobile device over the data communications link between the mobile device and the target device; and storing the set of documents on the mobile device. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A server for conducting forensic investigations by investigators on an investigations field, the server comprising:
-
a processor; and a memory, wherein the memory stores instructions that, when executed by the processor, cause the processor to; receive, at a forensic investigation application on a mobile device, a user command to download a digital search warrant in response to a received notification that the digital search warrant is available, wherein the digital search warrant is machine-readable and can be presented in a human-readable format and the digital search warrant includes a search parameter for conducting a forensic investigation of a target device; download the digital search warrant to the forensic investigation application at the mobile device in response to the received user command; boot, by the forensic investigation application at the mobile device, the target device over a data communication link between the mobile device and the target device using an operating system stored in the memory at the mobile device such that the target device is executing the operating system on the target device from a memory address in the memory of the mobile device over the data communication link and the execution of the operating system from the memory address of the memory of the mobile device on the target device causes the forensic investigation application executing at the mobile device to search the target device without user involvement; parse, by the forensic investigation application at the mobile device, the machine-readable instructions of the digital search warrant to identify the search parameter to use on a target device, the search parameter of the digital search warrant including a keyword and a file extension identifying a type of file; search, by the forensic investigation application executing at the mobile device, electronic documents at the target device over the data communications link between the mobile device and the target device to identify a set of electronic documents on the target device that include the keyword of the search parameter and are the type of file specified by the file extension in the digital search warrant, wherein the searching of the documents at the target device comprises only searching the files of the type of file identified by the file extension without modification of a state of the target device; retrieve from the target device the set of documents that include the search parameter without modifying a state of the target device, wherein the retrieving is done by the forensic investigation application executing at the mobile device over the data communications link between the mobile device and the target device; and store the set of documents on the mobile device. - View Dependent Claims (8, 9, 10, 11)
-
Specification