发明名称 Digital forensic analysis using empirical privilege profiling (EPP) for filtering collected data
摘要 A forensic device allows a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. The forensic device acquires the computer evidence from the target computing device and filters the computer evidence using an application-specific system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances executing throughout an enterprise. The forensic device presents a user interface through which the remote user views the filtered computer evidence acquired from the target computing device. In this manner, forensic device allows the user to filter the collected computer evidence to data that is likely to have forensic relevance.
申请公布号 US8458805(B2) 申请公布日期 2013.06.04
申请号 US20090469558 申请日期 2009.05.20
申请人 ADELSTEIN FRANK;MARCEAU CARLA;ARCHITECTURE TECHNOLOGY CORPORATION 发明人 ADELSTEIN FRANK;MARCEAU CARLA
分类号 G06F7/04 主分类号 G06F7/04
代理机构 代理人
主权项
地址