Forensic feature extraction and cross drive analysis
First Claim
Patent Images
1. A computer-based method for determining whether a second digital information storage medium accessible for forensic analysis relates to a social network with which a first digital information storage medium has previously been identified, the method comprising:
- accessing first and second respective digital images generated from digital information retrieved from or present on the first and second digital information storage media, respectively, the first and second digital images comprising first and second representations, respectively, of digital information from the first and second digital information storage media;
executing, on the first and second representations, a feature extractor function to extract occurrences, from within the representations of digital information from the first and second digital information storage media, respectively, of a selected feature, thereby to generate a feature extractor output;
detecting, based on the feature extractor output, pseudo-unique information from the first and second digital information storage media, respectively;
detecting a degree of commonality between pseudo-unique information from the first and second digital information storage media, respectively; and
,if a sufficient commonality of pseudo-unique information is detected, designating the second digital information storage medium as relating to the social network with which the first digital information storage medium has previously been identified.
5 Assignments
0 Petitions
Accused Products
Abstract
Computer-based systems and methods enable analysts to manage and explore the information that hard drives and other storage devices or sources of data may contain, and for extracting forensic features and performing cross drive analysis.
57 Citations
35 Claims
-
1. A computer-based method for determining whether a second digital information storage medium accessible for forensic analysis relates to a social network with which a first digital information storage medium has previously been identified, the method comprising:
-
accessing first and second respective digital images generated from digital information retrieved from or present on the first and second digital information storage media, respectively, the first and second digital images comprising first and second representations, respectively, of digital information from the first and second digital information storage media; executing, on the first and second representations, a feature extractor function to extract occurrences, from within the representations of digital information from the first and second digital information storage media, respectively, of a selected feature, thereby to generate a feature extractor output; detecting, based on the feature extractor output, pseudo-unique information from the first and second digital information storage media, respectively; detecting a degree of commonality between pseudo-unique information from the first and second digital information storage media, respectively; and
,if a sufficient commonality of pseudo-unique information is detected, designating the second digital information storage medium as relating to the social network with which the first digital information storage medium has previously been identified. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A computer-based method for discovering social networks with which ones of a plurality of digital information storage media accessible for forensic analysis may be identified, the method comprising:
-
accessing respective digital images generated from digital information retrieved from or present on the plurality of digital information storage media, respectively, the respective digital images comprising respective representations of digital information from corresponding ones of the plurality of digital information storage media; executing, on the representations, a feature extractor function to extract occurrences, from within the representations of digital information from respective ones of the digital information storage media, of a selected feature, thereby to generate a feature extractor output; detecting, based on the feature extractor output, pseudo-unique information from respective ones of the plurality of digital information storage media; detecting a degree of commonality between pseudo-unique information from respective ones of the plurality of digital information storage media; and
,if at least a selected degree of commonality of pseudo-unique information is detected, designating respective ones of the plurality of digital information storage media for which such commonality has been detected as relating to a potential social network, thereby to identify a potential social network. - View Dependent Claims (13)
-
-
14. A computer-based method of analyzing digital information present on or retrieved from a plurality of digital information storage media, the method comprising:
-
generating digital images representative of digital information from respective ones of the plurality of digital information storage media; applying a feature extractor function to extract features from the digital images or string files generated from the digital images, the feature extractor function comprising scanning for selected pseudo-unique identifiers to identify features for extraction, and storing extracted features for subsequent access or further analysis, whereby the feature extraction function extracts features from across at least a subset of the plurality of digital information storage media; applying a first order cross-media analysis, wherein the results of applying a feature extractor function are compared across multiple ones of the plurality of digital information storage media, to identify digital information storage media among the plurality of digital information storage media having a selected or maximal value or number of occurrences of a selected feature; applying a second order cross media analysis to generate correlations between ones of the plurality of digital information storage media, wherein the correlations are generated based on analysis of extracted features, to enable correlation of selected features across the plurality of digital information storage media and detection of a selected degree of commonality of features extracted from given digital information storage media within the plurality of digital information storage media; and whereby the method is operable to enable an operator to analyze and correlate information from across multiple ones of the plurality of digital information storage media. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26)
-
-
27. A computer-based method of analyzing digital information present on or retrieved from a plurality of digital information storage media, the method comprising:
-
generating digital images representative of digital information from respective ones of the plurality of digital information storage media; generating from the images an image file; extracting strings from the image file; applying a feature extractor function to extract features from the strings extracted from the digital images, the feature extractor function comprising scanning for selected pseudo-unique identifiers to identify features for extraction, wherein the feature extraction function extracts features from across at least a subset of the plurality of digital information storage media and writes the results to one or more feature files; applying a first order cross-media analysis, wherein the results of applying a feature extractor function are compared across multiple ones of the plurality of digital information storage media, to identify digital information storage media among the plurality of digital information storage media having a selected or maximal value or number of occurrences of a selected feature; and applying a second order cross media analysis to generate correlations between ones of the plurality of digital information storage media, wherein the correlations are generated based on analysis of extracted features, to enable correlation of selected features across the plurality of digital information storage media and detection of a selected degree of commonality of features extracted from given digital information storage media within the plurality of digital information storage media; whereby the method is operable to enable an operator to analyze and correlate information from across multiple ones of the plurality of digital information storage media. - View Dependent Claims (28, 29, 30, 31, 32, 33)
-
-
34. A computer-based system for determining whether a second digital information storage medium accessible for forensic analysis relates to a social network with which a first digital information storage medium has previously been identified, the system comprising:
-
means for accessing first and second respective digital images generated from digital information retrieved from or present on the first and second digital information storage media, respectively, the first and second digital images comprising first and second representations, respectively, of digital information from the first and second digital information storage media; means for executing, on the first and second representations, a feature extractor function to extract occurrences, from within the representations of digital information from the first and second digital information storage media, respectively, of a selected feature, thereby to generate a feature extractor output; means for detecting, based on the feature extractor output;
pseudo-unique information from the first and second digital information storage media, respectively;means for detecting a degree of commonality between pseudo-unique information from the first and second digital information storage media, respectively; and
,means for, if a sufficient commonality of pseudo-unique information is detected, designating the second digital information storage medium as relating to the social network with which the first digital information storage medium has previously been identified.
-
-
35. A computer program product operable within a computer, the computer program product being operable to enable the computer to determine whether a second digital information storage medium accessible for forensic analysis relates to a social network with which a first digital information storage medium has previously been identified, the computer program product comprising:
-
a non-transitory computer readable medium having computer-executable program code stored thereon, the computer-executable program code comprising program code executable by the computer to enable the computer to; access first and second respective digital images generated from digital information retrieved from or present on the first and second digital information storage media, respectively, the first and second digital images comprising first and second representations, respectively, of digital information from the first and second digital information storage media; execute, on the first and second representations, a feature extractor function to extract occurrences, from within the representations of digital information from the first and second digital information storage media, respectively, of a selected feature, thereby to generate a feature extractor output; detect, based on the feature extractor output, pseudo-unique information from the first and second digital information storage media, respectively; detect a degree of commonality between pseudo-unique information from the first and second digital information storage media, respectively; and
,if a sufficient commonality of pseudo-unique information is detected, designate the second digital information storage medium as relating to the social network with which the first digital information storage medium has previously been identified.
-
Specification