计算机应用 ›› 2005, Vol. 25 ›› Issue (06): 1290-1293.DOI: 10.3724/SP.J.1087.2005.1290

• 信息安全 • 上一篇    下一篇

分布式计算机动态取证模型

梁昌宇,吴强,曾庆凯   

  1. 南京大学计算机科学与技术系
  • 出版日期:2005-06-01 发布日期:2011-04-06
  • 基金资助:

    863计划项目(2004AA147070);;国家自然科学基金资助项目(60473053)

Distributed and dynamic computer forensic model

LIANG Chang-Yu ,WU Qiang,ZENG Qing-Kai   

  1. Department of Computer Science and Technology, Nanjing University, Nanjing Jiangsu 210093, China
  • Online:2005-06-01 Published:2011-04-06

摘要: 提出一个分布式计算机动态取证模型,在被保护系统中进行实时动态的证据采集,将证据及时、完整地存储到安全的证据中心,为证据分析和提取工作提供可信的原始证据数据。

关键词:  , 计算机取证, 动态取证, 证据完整性

Abstract: Along with the development of computer technology , traditional computer forensics model could not meet the requirements for safety. The new forensic model was proposed here. Camparing with traditional computer forensic model, the major differenced between these two models lies on the distributed structure and the mechanism of dynamical data gathering. With this two characteristics, forensics system based on the new model could gather real-time evidences dynamically in a distributed system, and save this evidences in a safe place in time. So unauthorised deletion ,change to evidences could be detected and prevented. Then the stored evidences could be used for further analysis and review.

Key words: computer forensics, dynamic forensics, integrality of evidence

中图分类号: