Patent · US Active

Methods, systems, and computer readable media for efficient computer forensic analysis and data access control

US9721089B2 · kind B2 · utility

3Cited by
2References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 7, 2012
Grant dateAug 1, 2017
Priority date
Expiry dateSep 21, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/53
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

According to one aspect, the subject matter described herein includes a method for efficient computer forensic analysis and data access control. The method includes steps occurring from within a virtualization layer separate from a guest operating system. The steps include monitoring disk accesses by the guest operating system to a region of interest on a disk from which data is copied into memory. The steps also include tracking subsequent accesses to the memory resident data where the memory resident data is copied from its initial location to other memory locations or over a network. The steps further include linking operations made by the guest operating system associated with the disk accesses with operations made by the guest operating system associated with the memory accessed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.