Electronic discovery system and method
First Claim
1. A computer-implemented method for conducting investigations of one or more target machines in a data communications network via an examining machine, the method comprising:
- defining, under control of the examining machine, a set of investigation criteria;
automatically generating by the examining machine, a unique identifier for the set of investigation criteria;
automatically investigating the one or more target machines based on the set of investigation criteria and outputting results of the investigation;
preserving the results of the investigation in an evidence data store; and
storing the unique identifier in the evidence data store in association with the preserved results for tracing the results to the set of investigation criteria.
7 Assignments
0 Petitions
Accused Products
Abstract
A computer investigation system and method that conducts electronic discovery of desired files across a live network in a forensically sound manner. The investigation entails an examining machine electronically identifying, collecting, and preserving evidence from target machines that is responsive to a set of investigation criteria. The set of investigation criteria is associated with an investigation subject that is identified by a global unique identifier (GUID). As the investigation subject is applied to the various files, the responsive files are stamped with the GUID and preserved in a container file referred to as a logical evidence file (LEF). The GUID allows the results of an investigation to be easily and reliably traced to the particular investigation subject that was applied.
150 Citations
20 Claims
-
1. A computer-implemented method for conducting investigations of one or more target machines in a data communications network via an examining machine, the method comprising:
-
defining, under control of the examining machine, a set of investigation criteria;
automatically generating by the examining machine, a unique identifier for the set of investigation criteria;
automatically investigating the one or more target machines based on the set of investigation criteria and outputting results of the investigation;
preserving the results of the investigation in an evidence data store; and
storing the unique identifier in the evidence data store in association with the preserved results for tracing the results to the set of investigation criteria. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. An examining machine conducting investigations of one or more target machines in a data communications network, the examining machine comprising:
-
a processor;
a memory operably coupled to the processor storing program instructions therein, the processor being operable to execute the program instructions, the program instructions including;
defining a set of investigation criteria;
automatically generating a unique identifier for the set of investigation criteria;
automatically investigating the one or more target machines based on the set of investigation criteria and outputting results of the investigation;
preserving the results of the investigation in an evidence data store; and
storing the unique identifier in the evidence data store in association with the preserved results for tracing the results to the set of investigation criteria. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification