AUTOMATED ACQUISITION OF VOLATILE FORENSIC EVIDENCE FROM NETWORK DEVICES
First Claim
1. A method executed by an electronic forensic device comprising:
- detecting, with the electronic forensic device, a network device connected to one of a home or small-office communications network;
selecting an interrogation script for the detected network device; and
retrieving, with the electronic forensic device, forensic data from the network device using the interrogation script.
1 Assignment
0 Petitions
Accused Products
Abstract
Examples disclosed herein are directed to techniques for automatically retrieving and processing forensic data from network devices connected to a communications network without requiring device-specific knowledge or training. A mobile forensic device includes and extensible forensic analysis tool that allows on-scene forensic investigators to quickly and automatically acquire data from network devices without device-specific knowledge. The extensible forensic analysis tool is designed for use on handheld mobile computers, enabling on-scene investigators to quickly and easily acquire forensic data from network devices in the field without losing volatile data or shutting down the network.
-
Citations
34 Claims
-
1. A method executed by an electronic forensic device comprising:
-
detecting, with the electronic forensic device, a network device connected to one of a home or small-office communications network; selecting an interrogation script for the detected network device; and retrieving, with the electronic forensic device, forensic data from the network device using the interrogation script. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29)
-
-
30. A forensic device configured to automatically retrieve and process forensic data from a plurality of network devices connected to one of a home or small-office communications network, the device comprising:
-
an interrogation script storage database storing a plurality of different interrogation scripts, wherein each of the interrogation scripts conform to a common scripting language, and wherein each of the interrogation scripts corresponds to a different type of layer three network device; a device detection module configured to detect one or more network devices connected to the communications network; a device identification module configured to identify one or more of the detected network devices; a data acquisition module configured to automatically, and without user input, select a corresponding one of the interrogation scripts for each of the detected network devices based on its identity, retrieve raw data from each of the network devices using the interrogation script, and process the raw data retrieved from each of the network devices into forensic data; and a user interface module configured to present the forensic data to a user. - View Dependent Claims (31)
-
-
32. A system comprising:
-
a communications network; one or more network devices connected to the communications network; one or more non-network devices connected to the communications network; and a forensic device configured to connect to the communications network and detect the network devices, select an interrogation script for each of the detected network devices, and retrieve forensic data from each of the network devices using the respective interrogation scripts.
-
-
33. A computer-readable medium comprising instructions to cause a processor to:
-
detect a network device connected to one of a home or small-office communications network; select an interrogation script for the detected network device; and retrieve forensic data from the network device using the interrogation script.
-
-
34. A forensic device comprising:
-
means for detecting a network device connected to one of a home or small-office communications network; means for selecting an interrogation script for the detected network device; and means for retrieving forensic data from the network device using the interrogation script.
-
Specification