摘要
随着计算机犯罪的不断增加 ,电子数据取证技术 (DigitalForensicTechnologies)越来越受到人们的重视 .目前对计算机取证技术的研究主要集中于证据提取及证据分析等方面 ,而对取证机制本身的安全没有考虑 ,这使得电子数据证据的完整性得不到充分的保障 .在对相关研究工作进行分析的基础上 ,文中提出安全隔离环境是用于保护电子数据取证机制的有效方法 ,并设计和实现一个安全保护机制———I LOMAC ,验证了以上方法是符合实际并有效的 .
Research regarding Digital Forensic Technologies has become more active with the recent increases in illegal accesses to computer system. Many researchers focus only on the techniques or mechanisms for evidence detecting and evidence analyzing, without considering the security of forensic mechanisms themselves, and the digital evidence can't be protected completely. Based on the analysis of relative researches, secure area is proposed to protect forensic mechanisms from attacking. A mechanism called I-LOMAC has been designed and implemented to evaluate this method. The results demonstrate the advantage in protecting the forensic mechanisms.
出处
《电子学报》
EI
CAS
CSCD
北大核心
2004年第8期1374-1380,共7页
Acta Electronica Sinica
基金
国家自然科学基金 (No .60 0 730 2 2 )
国家 863高科技项目基金 (No .863 30 6 ZD1 2 1 4 2 )
中国科学院知识创新工程基金 (No.KGCX1 0 9)
关键词
电子数据取证
电子数据证据收集系统
访问控制
完整性
真实性
Client server computer systems
Computer crime
Computer networks
Network protocols
Numerical analysis
Security of data