发明名称 COMPUTER FORENSICS, E-DISCOVERY AND INCIDENT RESPONSE METHODS AND SYSTEMS
摘要 Systems and methods for collection of volatile forensic data from active systems are described. In an embodiment of the methods, a selected set of forensics data items can be selected. Runtime code capable of launching data collection modules from a removable storage device with little or no user input is generated and stored on the device. The collection of forensic data can then be accomplished covertly using the removable storage device by a person with minimal training. In another embodiment, pre-deployed agents in communication with servers and controlled by console software can collect forensic data covertly according to schedule, immediately at the command of an analyst using a remote administrative console, or in response to a triggering event.
申请公布号 WO2009085239(A3) 申请公布日期 2009.10.08
申请号 WO2008US13955 申请日期 2008.12.22
申请人 E-FENSE, INC.;FAHEY, ANDREW L. 发明人 FAHEY, ANDREW L.
分类号 G06F15/16;G06F9/06;G06F9/30;G06F12/00 主分类号 G06F15/16
代理机构 代理人
主权项
地址
您可能感兴趣的专利