摘要
由于目前计算机专业取证人员数量的不足,当前司法实践中对于现场中正处于运行状态的计算机大多采用"二步式"取证的方式来搜集数字证据,即先由侦查人员对涉案计算机实施关机分离和保全,尔后再移交专业机构进行数字证据司法鉴定。这种方式虽然保障了数字证据的原始性和证明力,但无形之中造成了存储在RAM中的"易挥发"数据以及其他形式的潜在数字证据的丢失。而计算机信息系统中的这些"易挥发数据"可以为案件的侦破提供重要线索和潜在的数字证据,因此通过对侦查人员的专业培训,实现"易挥发数据"的现场动态获取和合理保全对数字案件侦查取证意义重大。
Due to lack of computer forensics professionals, the "two-steps" approach is commonly adopted to gather digital evidence in the running computer at the crime scene, that is, unplugging the running computer and booking it into evidence facilities first, then submitting it to trained digital evidence experts for examination. Although this method protects the aboriginality and integrity of digital evidence, it leads to the loss of "volatile data" stored in RAM and in other forms. The "volatile data" can often provide crucial clues and evidence for crime investigation, so it is necessary to make live analysis on-scene to acquire them. It is recommended that investigators be given professional trainings and get the live analysis skill.
出处
《中国司法鉴定》
2008年第1期26-30,共5页
Chinese Journal of Forensic Sciences
关键词
计算机取证
现场动态分析
易挥发数据
收集
computer forensics
live analysis on-scene
volatile data
collection