发明名称 Frequent data set captures for volume forensics
摘要 Techniques, including systems and methods, take frequent captures of data sets for the purpose of forensic analysis. The data set captures are taken at the block level in various embodiments. Data set captures are used to instantiate forensic storage volumes that are attached to computing instances. The computing instances can access data in the forensic storage volumes at a state corresponding to a specified capture time. A user can select different capture times to re-instantiate the forensic storage volume to see how the forensic storage volume changed between captures.
申请公布号 US9189343(B2) 申请公布日期 2015.11.17
申请号 US201414574247 申请日期 2014.12.17
申请人 Amazon Technologies, Inc. 发明人 Brandwine Eric Jason
分类号 G06F17/30;G06F11/14;G06F7/04 主分类号 G06F17/30
代理机构 Hogan Lovells US LLP 代理人 Hogan Lovells US LLP
主权项 1. A computer-implemented method for providing access to different states of a data set, comprising: under the control of one or more computer systems configured with executable instructions, storing a data set among a plurality of data blocks of a storage volume; performing write operations that change at least a subset of the plurality of data blocks; generating block-level captures of the data set, each block-level capture having a corresponding capture time and each block-level capture representing a state of the plurality of data blocks of the storage volume at the corresponding capture time; for a particular capture time corresponding to a particular state of the plurality of blocks and to a particular capture of the data set, using the particular capture to configure a forensic storage volume in a state corresponding to the particular state, the forensic storage volume hosted by a provider of a computer resource, a customer using an application programming interface (API) to specify information related to the particular capture time; providing, to a user, access to a computing device in a manner allowing the user to select a different capture time, the different capture time corresponding to a different capture and to a different state of the plurality of data blocks; and providing, to the user, access to the computing device, the computing device having access to the changed forensic storage volume.
地址 Reno NV US