Inventors:
Thomas Clay Shields - Washington DC, US
Ophir Frieder - Chicago IL, US
Marcus A. Maloof - Bethesda MD, US
Assignee:
Georgetown University - Washington DC
International Classification:
G06F 7/00
US Classification:
707742, 707781, 713180, 713186, 705 50, 705 51, 705 64, 705 75, 705 76
Abstract:
Methods and systems are provided for a proactive approach for computer forensic investigations. The invention allows organizations anticipating the need for forensic analysis to prepare in advance. Digital representations are generated proactively for a specified target. A digital representation is a digest of the content of the target. Digital representations of a collection of targets indexed and organized in a data structure, such as an inverted index. The searching and comparison of digital representations of a collection of targets allows quick and accurate identification of targets having identical or similar content. Computational and storage costs are expended in advance, which allows more efficient computer forensic investigations. The present invention can be applied to numerous applications, such as computer forensic evidence gathering, misuse detection, network intrusion detection, and unauthorized network traffic detection and prevention.