Patents by Inventor Jad John Saliba
Jad John Saliba has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20240104085Abstract: Provided are a system and method for evaluating integrity of a parsed file system. The system includes a processor and a memory communicatively connected to the processor and storing computer-executable instructions that cause the system to read an allocation tracker, create an allocated blocks collection of each block identifier within the allocation tracker indicated to be currently allocated, create an initially empty reference anomaly blocks collection, for each block of each file system object referenced by the file system object, determine that the associated block identifier is present in the allocated blocks collection or not, respectively remove the block identifier from the allocated blocks collection or add the block identifier to the reference anomaly blocks collection, determine that the allocated blocks collection and the reference anomaly blocks collection are empty or not empty and respectively indicate a successful evaluation or an unsuccessful evaluation.Type: ApplicationFiled: September 21, 2023Publication date: March 28, 2024Inventors: Jad John Saliba, James David Schroering
-
Patent number: 11940982Abstract: A system and a method for locating application-specific data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data. The method includes accessing unidentified data from at least one data storage device; examining the unidentified data to detect at least one application-specific data pattern associated with at least one application; for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application; and if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.Type: GrantFiled: March 19, 2021Date of Patent: March 26, 2024Assignee: Magnet Forensics Investco Inc.Inventor: Jad John Saliba
-
Publication number: 20240013528Abstract: Provided is a computer system, method and storage medium for determining a platform type of a forensic image. The method includes storing in a memory a mapping data structure mapping at least one predetermined data marker type to at least one platform type and automatically determining the platform type by scanning the forensic image for the at least one predetermined data marker type. The method further includes, where at least one data marker is detected, mapping the at least one data marker to at least one platform type using the mapping data structure. The method further includes, where at least one data marker is not detected, examining the forensic image to identify a set of present data elements, determining, according to at least one encoded rule, a most likely platform type. The method further includes assigning the platform type or the most likely platform type as the determined platform type.Type: ApplicationFiled: May 10, 2023Publication date: January 11, 2024Inventors: Jad John Saliba, Samantha Mcilveen, Kieran Cunney, Emily Guglielmi, Mariel Cortez Martinez, Garrett Randall
-
Patent number: 11868212Abstract: The present embodiments relate generally to a computer device, system and method of identifying an application type of unknown data. The method may include: determining that the unknown data corresponds to database information, the database information comprising at least one table with at least one column; for a column of a table in the database information, determining if a column identifier of the column comprises a keyword associated with a particular application type; and if the column identifier comprises the keyword, identifying data stored in the database as belonging to an application that is of the particular application type.Type: GrantFiled: December 17, 2021Date of Patent: January 9, 2024Assignee: Magnet Forensics Investco Inc.Inventor: Jad John Saliba
-
Publication number: 20230297544Abstract: Systems and methods for predicting significant files for a digital forensic investigation are provided. A method of predicting files of interest during a digital forensic investigation of a target dataset stored on a target device includes tagging a plurality of significant files from a plurality of previous investigations to create at least one set of predictive criteria, storing the at least one set of predictive criteria in a memory of the investigator device, using a first set of predictive criteria to generate a first executable recommendation engine model, storing the recommendation engine model in the memory of an investigator device, automatically scanning the target dataset by a recommendation engine using the first recommendation engine model, and providing an output of any files of interest.Type: ApplicationFiled: March 20, 2023Publication date: September 21, 2023Inventors: Jad John Saliba, Matthew Moody, Mike Williamson, Tarah Melton, Harold C. Amick
-
Publication number: 20230281377Abstract: Methods and apparatus for examining digital forensic data using a viewer computer. Forensic data collections are provided to the viewer computer, which can format the data artifacts according to a variety of display types and presentation formats, to facilitate review and reporting by a user. The display types and presentation formats also enable the user to easily switch between a source location view and a related artifacts view.Type: ApplicationFiled: March 15, 2023Publication date: September 7, 2023Inventors: Jad John Saliba, Geoffrey Wendell MacGillivray, Diana Maureen Wiffen, Michael Charles Parkhill, Samantha Jo McIlveen, Tayfun Uzun, Jamie Robert Earl McQuaid, Paul Stephen Hendry
-
Publication number: 20230214752Abstract: A system and associated method for insider threat prediction. The system includes a forensic data source, a threat prediction module, and a data collection module, wherein the data collection module is configured to collect subject data of a subject from the forensic data source, and transmit the subject data to the threat prediction module, wherein the threat prediction module is configured to receive subject data from the data collection module and analyze subject data to generate an insider threat output characterizing the insider threat level of the subject.Type: ApplicationFiled: January 5, 2023Publication date: July 6, 2023Inventors: Jad John Saliba, Jamie McQuaid, Harold C. Amick, Dallas Jordan
-
Patent number: 11625526Abstract: Methods and apparatus for examining digital forensic data using a viewer computer. Forensic data collections are provided to the viewer computer, which can format the data artifacts according to a variety of display types and presentation formats, to facilitate review and reporting by a user. The display types and presentation formats also enable the user to easily switch between a source location view and a related artifacts view.Type: GrantFiled: March 13, 2017Date of Patent: April 11, 2023Assignee: Magnet Forensics Investco Inc.Inventors: Jad John Saliba, Geoffrey Wendell MacGillivray, Diana Maureen Wiffen, Michael Charles Parkhill, Samantha Jo McIlveen, Tayfun Uzun, Jamie Robert Earl McQuaid, Paul Stephen Hendry
-
Publication number: 20220158829Abstract: Systems, devices, and methods for securing sensitive data in the cloud are provided. The system includes a cloud server including a cloud service and a client device communicatively connected to the cloud server. The client device executes a client user interface (“UI”) module configured to: upon a first login of the first user to the cloud service, generate an asymmetric keypair including a public key and a private key, store the private key in a local storage on the client device, and send the public key to the cloud server; and, in response to a user command to upload case data to the cloud service, generate a symmetric case key, encrypt sensitive data of the case data using the symmetric case key, encrypt the symmetric case key using the public key, and send the case data, the encrypted sensitive data, and the encrypted symmetric case key to the cloud server.Type: ApplicationFiled: November 16, 2021Publication date: May 19, 2022Inventors: Mike Parkhill, Chris McKnight, Jad John Saliba
-
Publication number: 20220107868Abstract: The present embodiments relate generally to a computer device, system and method of identifying an application type of unknown data. The method may include: determining that the unknown data corresponds to database information, the database information comprising at least one table with at least one column; for a column of a table in the database information, determining if a column identifier of the column comprises a keyword associated with a particular application type; and if the column identifier comprises the keyword, identifying data stored in the database as belonging to an application that is of the particular application type.Type: ApplicationFiled: December 17, 2021Publication date: April 7, 2022Inventor: Jad John Saliba
-
Patent number: 11277480Abstract: A computer system, method, and device perform targeted acquisition of data. The system includes an examiner device having a processor and a memory, an agent in the form of an executable program for finding and transferring targeted data, and a target endpoint system. The examiner device is configured to deploy the agent to the target endpoint system. The agent is configured to establish a connection with the examiner device. The examiner device is configured to send a request for targeted data to the agent. The agent is configured to locate the targeted data on the target endpoint system. The agent is configured to transfer the targeted data to the examiner device.Type: GrantFiled: September 30, 2020Date of Patent: March 15, 2022Assignee: Magnet Forensics Investco Inc.Inventors: Jad John Saliba, Andrew Gordon Roberts, Nicholas Bruce Alexander Cosentino, Kevin Brightwell
-
Publication number: 20220043907Abstract: Systems and methods for conducting a cloud-based forensic investigation of electronically-stored information are provided. The system includes an investigation requestor device configured to request a forensic investigation including selecting search criteria for the investigation, at least one remote system of the target, wherein the at least one remote system comprises electronically-stored information; a cloud server for storing forensic artifacts collected from the at least one remote system, wherein the forensic artifacts are collected based on the search criteria; and a cloud-based evidence-processing service configured to analyze the forensic artifacts and generate an initial report.Type: ApplicationFiled: August 6, 2021Publication date: February 10, 2022Inventors: Jad John Saliba, Randy Shawn MacCarthy, Tayfun Uzun
-
Publication number: 20220027466Abstract: What is provided is a method of generating a minimal forensic image of a target dataset to reduce upload demand. The method includes storing a set of criteria in an investigator device, wherein the set of criteria determines target data files of the target dataset which are to be included in the minimal forensic image, and wherein the set of criteria includes a plurality of file types and at least a first upload format for each file type in the plurality of file types, locating the target data files of the plurality of file types in the target dataset using the set of criteria, storing a representation of each target data file in the minimal forensic image in an MFI upload format determined according to the set of criteria, and transferring the minimal forensic image to a cloud server.Type: ApplicationFiled: July 26, 2021Publication date: January 27, 2022Inventor: Jad John Saliba
-
Publication number: 20210357364Abstract: Computer systems and computer-implemented methods for forensically investigating a target dataset including a target file by comparing the target file to a source file are provided. The method includes performing a preliminary matching operation. The preliminary matching operation includes performing at least one of a file size matching operation, in which a target file size is compared to a source file size, and a sub-hash matching operation, in which a target file sub-hash is compared to a source file sub-hash. A sub-hash is a hash value calculated using a subset of data from the file. The method further includes performing a full hash matching operation if the preliminary matching operation identifies a preliminary match. The full hash matching operation includes generating a target file full hash value and comparing the target file full hash value to a source file full hash value.Type: ApplicationFiled: May 13, 2021Publication date: November 18, 2021Inventors: Jad John Saliba, John Wiley Singleton
-
Publication number: 20210311927Abstract: A system and a method for locating application-specific data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data. The method includes accessing unidentified data from at least one data storage device; examining the unidentified data to detect at least one application-specific data pattern associated with at least one application; for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application; and if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.Type: ApplicationFiled: March 19, 2021Publication date: October 7, 2021Applicant: Magnet Forensics Investco Inc.Inventor: Jad John Saliba
-
Patent number: 11036714Abstract: A system and a method for locating application-specific data that has been previously deleted and located in an address of the data storage device marked as being available for storing new data. The method includes accessing unidentified data from at least one data storage device; examining the unidentified data to detect at least one application-specific data pattern associated with at least one application; for each detected application-specific data pattern, executing an application-specific validation process to determine whether the unidentified data includes valid data associated with a corresponding application; and if it is determined that the unidentified data includes valid data associated with the corresponding application, then recovering the valid data.Type: GrantFiled: October 30, 2015Date of Patent: June 15, 2021Assignee: Magnet Forensics Investco Inc.Inventor: Jad John Saliba
-
Publication number: 20210133904Abstract: A computer system and method for infield collection of digital evidence is provided. The computer system includes a communication interface for connecting the computer system to an evidence provider device and a processor configured to transfer digital evidence from the evidence provider device to the computer system by pulling media files from the evidence provider device onto the computer system, filtering the media files according to filtering criterion data, displaying thumbnails the filtered media files, receiving selection data indicating which of the displayed filtered media files is selected to be transferred, and copying the selected media files and media file metadata for the selected media files to the computer system. The computer system also includes a user input device which receives the filtering criterion data and selection data from a user and a display communicatively connected to the processor and which displays at least one output of the processor.Type: ApplicationFiled: September 22, 2020Publication date: May 6, 2021Inventors: Jad John Saliba, Tayfun Uzun
-
Publication number: 20210099528Abstract: A computer system, method, and device perform targeted acquisition of data. The system includes an examiner device having a processor and a memory, an agent in the form of an executable program for finding and transferring targeted data, and a target endpoint system. The examiner device is configured to deploy the agent to the target endpoint system. The agent is configured to establish a connection with the examiner device. The examiner device is configured to send a request for targeted data to the agent. The agent is configured to locate the targeted data on the target endpoint system. The agent is configured to transfer the targeted data to the examiner device.Type: ApplicationFiled: September 30, 2020Publication date: April 1, 2021Inventors: Jad John Saliba, Andrew Gordon Roberts, Nicholas Bruce Alexander Cosentino, Kevin Brightwell
-
Patent number: D823860Type: GrantFiled: March 11, 2016Date of Patent: July 24, 2018Assignee: Magnet Forensics Inc.Inventors: Diana Maureen Wiffen, Jad John Saliba, Geoffrey Wendell MacGillivray, Michael Charles Parkhill, Samantha Jo McIlveen, Tayfun Uzun, Jamie Robert Earl McQuaid, Paul Stephen Hendry
-
Patent number: D912068Type: GrantFiled: July 23, 2018Date of Patent: March 2, 2021Assignee: MAGNET FORENSICS INVESTCO INC.Inventors: Diana Maureen Wiffen, Jad John Saliba, Geoffrey Wendell MacGillivray, Michael Charles Parkhill, Samantha Jo McIlveen, Tayfun Uzun, Jamie Robert Earl McQuaid, Paul Stephen Hendry