US 12,282,674 B2
Evidence collection guidance method and apparatus for file selection and computer-readable storage medium
Jung-Hoon Oh, Daejeon (KR); Hyun-Uk Hwang, Daejeon (KR); Seung-Yong Lee, Daejeon (KR); Jun-Su Kim, Daejeon (KR); Joong-Soo Han, Daejeon (KR); and Hye-Jin Jeong, Daejeon (KR)
Assigned to ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE, Daejeon (KR)
Filed by ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE, Daejeon (KR)
Filed on Jul. 13, 2022, as Appl. No. 17/863,634.
Prior Publication US 2024/0020039 A1, Jan. 18, 2024
Int. Cl. G06F 3/06 (2006.01)
CPC G06F 3/0643 (2013.01) [G06F 3/0604 (2013.01); G06F 3/0653 (2013.01); G06F 3/0673 (2013.01)] 13 Claims
OG exemplary drawing
 
1. An evidence collection guidance method, comprising:
generating preliminary analysis information by reading system volume and data volume from a collection target device, wherein the generated preliminary analysis information is separated into different pieces;
setting protocol levels of each piece of preliminary analysis information based on a predefined set of rules; and
generating and outputting notification information including summary description information which comprises information regarding reasons for the selected protocol level of the pieces of the preliminary analysis information and follow-up measure items comprising information on what type of analysis is to be used based on the selected protocol level of the pieces of preliminary analysis information,
wherein generating and outputting the notification information comprises:
checking the protocol level of corresponding preliminary analysis information;
when the protocol level of the corresponding preliminary analysis information is a caution level, generating summary description information and follow-up measure items corresponding to the caution level, and adding the summary description information and follow-up measure items to the notification information;
when the protocol level of the corresponding preliminary analysis information is a confirm level, generating summary description information and follow-up measure items corresponding to the confirm level, and adding the summary description information and the follow-up measure items to the notification information; and
outputting the notification information to which the summary description information and the follow-up measure items are added.