×

Forensic software investigation

  • US 9,887,886 B2
  • Filed: 07/15/2014
  • Issued: 02/06/2018
  • Est. Priority Date: 07/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer system including instructions recorded on a non-transitory computer-readable medium and executable by at least one processor, the system comprising:

  • a server configured to cause the at least one processor to manage forensic investigations of client assets associated with a client based on a forensic service agreement between the client and a cloud service provider in a cloud environment, the server including;

    a forensic service interface configured to establish the forensic service agreement between the client and the cloud service provider for servicing the forensic investigations of the client assets associated with the client, the forensic service interface providing multiple modes for the forensic service agreement, the multiple modes including at least;

    (i) a first mode where the server is configured to manage the forensic investigations in real time on an ongoing basis;

    (ii) a second mode where the server is configured to manage the forensic investigations for an event during a time period specified by the client; and

    (iii) a third mode where the server is configured to manage the forensic investigations on a just-in-time basis in response to an investigation request from the client;

    a forensic data handler configured to acquire forensic data related to each client asset associated with the client, wherein the forensic data handler acquires the forensic data in real time on an ongoing basis when the forensic service agreement specifies the first mode, wherein the forensic data handler acquires the forensic data for the event during the time period when the forensic service agreement specifies the second mode, and wherein the forensic data handler acquires the forensic data on a just-in-time basis when the forensic service agreement specifies the third mode, and generate one or more client inventory records for each client asset based on the forensic data related to each client asset; and

    a forensic engine configured to generate one or more client evidence records for each client asset based on each client inventory record generated for each client asset;

    wherein the forensic service agreement includes a subscription for Forensics as a Service (FaaS), and under the FaaS subscription, the cloud service provider is configured to expose one or more forensic functionalities related to one or more of on-demand investigation, troubleshooting, auditing, and logging of forensic data related to the client assets associated with the client.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×