×

Method and system for forensic investigation of data access

  • US 9,535,994 B1
  • Filed: 03/28/2011
  • Issued: 01/03/2017
  • Est. Priority Date: 03/26/2010
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus to differentiate among various forms of accessing data which is stored in an information system, said differentiation being based on a time of access for said data during a finite time period, said finite time period having a beginning time and an ending time;

  • wherein said data includes a plurality of datum, the apparatus comprising;

    a non-transitory machine-readable medium; and

    a plurality of instructions in the machine-readable medium which, when executed by a processing machine, enable the processing machine to perform operations comprising;

    obtaining and storing in an array a time of access for at least a plurality of said datum in said data;

    iterating through said array and making at least one determination selected from the group of determinations consisting of determining an earliest of said stored times of access and determining for each of said stored times of access whether said time of access falls within said finite time period;

    when the selected determination includes determining for each of said stored times of access whether said time of access falls within said finite time period performing a comparison between said stored times of access and at least one predetermined invariant;

    transforming said times of access into a conclusion as to said form of access that has occurred based at least in part on a result of said comparison between said times of access and said at least one predetermined invariant; and

    ,when the selected determination includes determining an earliest of said stored times of access based at least in part on said determination, transforming said times of access into a conclusion as to which of said various forms of access has occurred.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×