US2023342872A1PendingUtilityA1
System and method for collecting forensic data via a mobile device
Est. expiryFeb 28, 2033(~6.6 yrs left)· nominal 20-yr term from priority
Inventors:Shawn Mccreight
G06Q 50/26G06Q 10/06H04W 4/00H04W 4/38
75
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Embodiments of search systems that leverage the search or access activities of a core group of users to improve search functionality and performance of such search systems are disclosed. Specifically, embodiments may utilize users' search activity to generate clusters of users and associated labels for those clusters. These clusters can be leveraged during a search to generate suggestions for a user conducting the search.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system, comprising:
a processor; and a non-transitory computer readable medium comprising instructions for: obtaining a search parameter for a target device; and providing the search parameter to an investigation application executing on a device that is a separate device from the target device, wherein the investigation application on the device is for: accessing the target device based on a modification to a Basic Input Output System (BIOS) configuration of the target device, the accessing including:
searching files at the target device over a connection between the device and the target device to identify a set of files on the target device that satisfy the search parameter, without modification of a state of the target device; and
retrieving the identified set of files without modifying the state of the target device, wherein the searching and retrieving is done by the investigation application that is executing on an operating system on the device to search the target device over the connection between the device and the target device, without user involvement.
2 . The system of claim 1 , wherein the accessing further includes booting the target device over the connection between the device and the target device using the operating system stored in a memory at the device such that the operating system is executing from the memory of the device, and the forensic investigation application is executing on the operating system to search the target device.
3 . The system of claim 1 , wherein the search parameter is provided to the investigation application via a document used by military personnel to obtain data from the target device relating to a suspect.
4 . The system of claim 1 , wherein the search parameter is provided to the investigation application via a document used by a parole officer to obtain evidence from the target device relating to a parolee.
5 . The system of claim 1 , wherein the search parameter is provided to the investigation application via a document used by corporate security department personnel to perform an audit.
6 . The system of claim 1 , wherein the target device includes a mass storage device.
7 . The system of claim 1 , wherein the accessing includes storing the retrieved identified set of files in a memory of the device.
8 . A method, comprising:
obtaining a search parameter for a target device; and providing the search parameter to an investigation application executing on a device that is a separate device from the target device, wherein the investigation application on the device is for:
accessing the target device based on a modification to a Basic Input Output System (BIOS) configuration of the target device, the accessing including:
searching files at the target device over a connection between the device and the target device to identify a set of files on the target device that satisfy the search parameter, without modification of a state of the target device; and
retrieving the identified set of files without modifying the state of the target device, wherein the searching and retrieving is done by the investigation application that is executing on an operating system on the device to search the target device over the connection between the device and the target device, without user involvement.
9 . The method of claim 8 , wherein the accessing further includes booting the target device over the connection between the device and the target device using the operating system stored in a memory at the device such that the operating system is executing from the memory of the device, and the forensic investigation application is executing on the operating system to search the target device.
10 . The method of claim 8 , wherein the search parameter is provided to the investigation application via a document used by military personnel to obtain data from the target device relating to a suspect.
11 . The method of claim 8 , wherein the search parameter is provided to the investigation application via a document used by a parole officer to obtain evidence from the target device relating to a parolee.
12 . The method of claim 8 , wherein the search parameter is provided to the investigation application via a document used by corporate security department personnel to perform an audit.
13 . The method of claim 8 , wherein the target device includes a mass storage device.
14 . The method of claim 8 , wherein the accessing includes storing the retrieved identified set of files in a memory of the device.
15 . A non-transitory computer readable medium comprising instructions for:
obtaining a search parameter for a target device; and providing the search parameter to an investigation application executing on a device that is a separate device from the target device, wherein the investigation application on the device is for:
accessing the target device based on a modification to a Basic Input Output System (BIOS) configuration of the target device, the accessing including:
searching files at the target device over a connection between the device and the target device to identify a set of files on the target device that satisfy the search parameter, without modification of a state of the target device; and
retrieving the identified set of files without modifying the state of the target device, wherein the searching and retrieving is done by the investigation application that is executing on an operating system on the device to search the target device over the connection between the device and the target device, without user involvement.
16 . The non-transitory computer readable medium of claim 15 , wherein the accessing further includes booting the target device over the connection between the device and the target device using the operating system stored in a memory at the device such that the operating system is executing from the memory of the device, and the forensic investigation application is executing on the operating system to search the target device.
17 . The non-transitory computer readable medium of claim 15 , wherein the search parameter is provided to the investigation application via a document used by military personnel to obtain data from the target device relating to a suspect.
18 . The non-transitory computer readable medium of claim 15 , wherein the search parameter is provided to the investigation application via a document used by a parole officer to obtain evidence from the target device relating to a parolee.
19 . The non-transitory computer readable medium of claim 15 , wherein the search parameter is provided to the investigation application via a document used by corporate security department personnel to perform an audit.
20 . The non-transitory computer readable medium of claim 15 , wherein the target device includes a mass storage device.
21 . The non-transitory computer readable medium of claim 15 , wherein the accessing includes storing the retrieved identified set of files in a memory of the device.Join the waitlist — get patent alerts
Track US2023342872A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.