×

System and Method for Entropy-Based Near-Match Analysis

  • US 20100235392A1
  • Filed: 03/11/2010
  • Published: 09/16/2010
  • Est. Priority Date: 03/16/2009
  • Status: Active Grant
First Claim
Patent Images

1. In a computer forensic investigation system including an examining machine coupled to one or more target machines over a data communications network, a method for identifying one or more files in the one or more target machines that are a near-match to a reference file, the method comprising:

  • computing or identifying an entropy of the reference file and outputting a first entropy value;

    identifying a second entropy value of a target file stored in the one or more target machines;

    determining a likeness of content in the target file to content in the reference file based on the first and second entropy values;

    identifying a tolerance threshold;

    determining a near-match between the target file and the reference file if the likeness of the target file to the reference file is within the tolerance threshold; and

    displaying on a display, information on the target file in response to the determining of a near-match.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×