发明名称 Systems and methods for digital forensic triage
摘要 In one embodiment, a method for forensic triage may include coupling, communicatively, a computer and a mobile device. The computer can be booted with machine readable instructions stored on the one or more mobile memory modules of the mobile device. A search data set can be received with one or more mobile processors of the mobile device. One or more processors of the computer, the one or more mobile processors, or both, can execute, automatically, the machine readable instructions stored on the one or more mobile memory modules of the mobile device to search one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set. The triage data can be transmitted via one or more communication modules of the mobile device.
申请公布号 US9621597(B2) 申请公布日期 2017.04.11
申请号 US201514730260 申请日期 2015.06.04
申请人 Aces and Eights Corporation 发明人 Frecks, Jr. Austin P.;Curry Anthony W.;Lynn, Jr. Donald Gene;Bland Christopher J.
分类号 H04M1/66;H04L29/06;H04W4/00;G06F21/57;G06F9/44;G06F17/30;H04L9/32;H04W12/12 主分类号 H04M1/66
代理机构 Dinsmore & Shohl, LLP 代理人 Dinsmore & Shohl, LLP ;Jaensson, Esq. Monika L'Orsa
主权项 1. A system for forensic triage comprising: a mobile device comprising one or more mobile processors conductively coupled to one or more mobile memory modules and one or more communication modules; a cloud computing device communicatively coupled to the one or more communication modules of the mobile device, the cloud computing device comprising one or more cloud processors conductively coupled to one or more cloud memory modules; a search data set stored on the one or more mobile memory modules of the mobile device, the one or more cloud memory modules, or both; and machine readable instructions stored on the one or more mobile memory modules of the mobile device, the one or more cloud memory modules, or both, wherein when the one or more communication modules of the mobile device is communicatively coupled to a computer comprising one or more processors conductively coupled to one or more memory modules, the one or more processors, the one or more mobile processors, or both are configured to execute the machine readable instructions to: boot the computer according to the machine readable instructions;search the one or memory modules of the computer in a read only mode for triage data that corresponds to the search data set; and the one or more cloud processors, the one or more mobile processors, or both are configured to execute the machine readable instructions to: compare the triage data, the search data set, or both to a data archive that is protected by a firewall;allow the receipt of data indicative of a match between the triage data and the data archive, the search data set and the data archive, or both; anddeny the receipt of predefined segments of the data archive.
地址 Shinnston WV US