×

Method and apparatus for forensic analysis of information stored in computer-readable media

  • US 6,279,010 B1
  • Filed: 01/12/1999
  • Issued: 08/21/2001
  • Est. Priority Date: 07/20/1998
  • Status: Expired due to Fees
First Claim
Patent Images

1. A computer-implemented method of automatically extracting from a large ambient data file containing a mixture of textual data and binary data information that has a relatively high probability of corresponding to Internet-related activity of interest to an investigator, the method comprising:

  • providing an ambient data file including ambient data from one or more of the following sources, alone or in combination;

    unallocated storage space, file slack space at the end of one or more computer files, a windows swap, and one or more temporary system files;

    reading a portion of the ambient data file into random access memory;

    searching the portion of the ambient data to determine the presence of a first character or character group within a pre-specified proximity to a second character or character group to locate Internet-related identifiers of interest to the investigator;

    if internet-related identifiers are located, copying the internet-related identifiers to an output file, thereby providing an output file for the investigator to review that excludes non-textual data, is greatly reduced in size from the original ambient data file; and

    that includes most or all of the internet-related information of interest to an investigator in the ambient data file.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×