×

Systems and methods for file clustering, multi-drive forensic analysis and data protection

  • US 9,792,289 B2
  • Filed: 11/07/2014
  • Issued: 10/17/2017
  • Est. Priority Date: 11/07/2014
  • Status: Active Grant
First Claim
Patent Images

1. A multi-drive forensic data analysis system comprising:

  • a plurality of memory devices having files stored thereon;

    at least one module configured to receive the files stored on the plurality of memory devices and extract characteristics of the files stored on the plurality of memory devices;

    a clustering module configured to;

    receive the extracted characteristics;

    identify similarities between the files stored on the plurality of memory devices, based on the extracted characteristics, using a two-stage algorithm wherein at least one stage of the two-stage algorithm includes content-based hashing;

    generate file clusters based on the identified similarities among the files stored on the plurality of memory devices; and

    generate a visual representation of the memory devices and connections therebetween based on the identified similarities among the files stored on the plurality of memory devices, the visual representation comprising;

    nodes that correspond to the memory devices; and

    lines connecting the nodes, each of the lines having a thickness representing the identified similarities; and

    a user interface module for displaying the visual representation.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×