首页> 外国专利> Digital forensic analysis using empirical privilege profiling (EPP) for filtering collected data

Digital forensic analysis using empirical privilege profiling (EPP) for filtering collected data

机译:使用经验特权概要分析(EPP)进行数字取证分析以过滤收集的数据

摘要

A forensic device allows a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. The forensic device acquires the computer evidence from the target computing device and filters the computer evidence using an application-specific system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances executing throughout an enterprise. The forensic device presents a user interface through which the remote user views the filtered computer evidence acquired from the target computing device. In this manner, forensic device allows the user to filter the collected computer evidence to data that is likely to have forensic relevance.
机译:法医设备允许用户远程询问目标计算设备,以便收集和分析可能存储在目标计算设备上的计算机证据。取证设备从目标计算设备获取计算机证据,并使用特定于应用程序的系统级特权配置文件过滤计算机证据,该配置文件描述了在整个企业中执行的多个软件应用程序实例对系统级特权的汇总行使。取证设备呈现用户界面,远程用户可通过该用户界面查看从目标计算设备获取的已过滤计算机证据。以这种方式,取证设备允许用户将收集到的计算机证据过滤为可能具有取证相关性的数据。

著录项

  • 公开/公告号US8458805B2

    专利类型

  • 公开/公告日2013-06-04

    原文格式PDF

  • 申请/专利权人 FRANK ADELSTEIN;CARLA MARCEAU;

    申请/专利号US20090469558

  • 发明设计人 FRANK ADELSTEIN;CARLA MARCEAU;

    申请日2009-05-20

  • 分类号G06F7/04;

  • 国家 US

  • 入库时间 2022-08-21 16:43:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号