J4

• 计算机科学 • Previous Articles     Next Articles

Design and Implementation of Dynamic Computer Forensics System Based on Network

YU Zhihong1, LIU Zhe2, ZHAO Kuo1, Nuerbuli1, SHI Guangkun1, HU Liang1   

  1. 1. College of Computer Science and Technology, Jilin University, Changchun 130012, China;2. Jilin Province Economics and Management Cadres College, Changchun 130012, China
  • Received:2008-01-24 Revised:1900-01-01 Online:2008-07-26 Published:2008-07-26
  • Contact: HU Liang

Abstract: In order to solve the problems existed in static forensics technology, this paper presents the design and implementation of a dynamic computer forensics system based on network. Compared with the traditional tools of the system, it performs the work of gathering evidence in advance before criminal action has occurred or in the process of crime so as to avoid the evidence chain lost caused by evidence not scout timely. It can improve the efficiency of the work of gathering evidence; enhance data integrity and timeliness of evidence. This paper describes the architecture, function and work flow, and the implementation of main functions of the core module technology.

Key words: computer forensics, electronic evidence, log, protocol analysis

CLC Number: 

  • TP309