发明名称 Obtaining complete forensic images of electronic storage media
摘要 In a method of obtaining a complete forensic image of an electronic storage media containing electronic data, the storage media is part of a computer system. The method includes the steps of: (a) storing a data collection program on an external storage device; (b) sending the external storage device to a custodian of the electronic data, together with means for the custodian to easily return the external storage device; (c) requiring the custodian to connect the external storage device to a computer system containing the storage media; (d) requiring the custodian to use the data collection program to forensically collect the electronic data to create a complete forensic image of the storage media containing the electronic data; (e) authenticating the forensic image; and (f) preserving an exact copy of the forensic image without making changes to the forensic image.
申请公布号 US9087207(B2) 申请公布日期 2015.07.21
申请号 US201012726553 申请日期 2010.03.18
申请人 Ricoh Company, Ltd. 发明人 Greetham David A.
分类号 G06Q99/00;G06F21/62;G06F21/78;G06Q50/18;G06Q50/00;G06F3/06 主分类号 G06Q99/00
代理机构 Hickman Palermo Becker Bingham LLP 代理人 Hickman Palermo Becker Bingham LLP ;Becker Edward A.
主权项 1. A method of a first computer system obtaining a complete forensic image of an electronic storage media that is part of a second computer system containing electronic data, by collecting forensic data, the storage media being part of the second computer system which includes a display screen, the method comprising the steps of: a. using the first computer system to store a data collection program on a password-encrypted external storage device, the storage device having a USB 1.1 or greater interface, the storage device receiving all of its operating power via the USB interface, the first computer system modifying the data collection program, i. to select a desired level of encryption,ii. to require specific input of information from a custodian of the electronic data,iii. to select switches to capture RAM,iv. to select a drive to be imaged,v. to select data capturing switches, to be used during the process of capturing the forensic data, from the group of switches comprising: verification, chunked file sizes, logging options, and verification, andvi. to select audit switches, to be used to perform a system audit after termination of the imaging by the data collection program, from the group of audit switches comprising: operating system version, logged-on user name, hard drive size, and electronic serial numbers; b. sending the external storage device to the custodian of the electronic data, together with means for the custodian to easily return the external storage device; c. the custodian connecting the external storage device to the second computer system containing the storage media, once connected, the data collection program displaying a splash screen on the display screen; d. the data collection program, via the splash screen, using the second computer system to forensically collect the electronic data to create a complete forensic image, on the external storage device, of the storage media containing the electronic data; e. the data collection program encrypting the external storage device; f. the data collection program auditing the forensic image; and g. the data collection program preserving an exact copy of the forensic image onto the external storage device without making changes to the forensic image.
地址 Tokyo JP