摘要
针对目前取证系统的时效性不足和通信瓶颈等问题,提出了一种分布式自治型计算机取证系统。该系统利用自治取证节点对所有可能的入侵行为进行实时动态取证,并采用了安全有效的方式对证据及时保存。由于取证节点具有自治取证能力,系统的整体性能得到了优化。实验表明:该系统能实时取到真实有效的电子证据,并具有很强的容错能力。
Currently, most of computer forensics systems are not real-time, and often cause communicational bottleneck. In order to overcome the shortages, a distributed and autonomous computer forensics system was presented. By using the autonomous forensics node, the system could obtain real-time evidence dynamically as soon as network intrusions took place, in which the evidence could be saved in a safe way in time. This way of autonomous forensics could optimize system performance. Experimental result shows that the system can capture the authentic and valid electronic evidence, and has high capability of fault tolerance.
出处
《计算机应用》
CSCD
北大核心
2008年第10期2485-2487,共3页
journal of Computer Applications
基金
国家自然科学基金资助项目(60473031)
公安部应用创新计划项目(2006YYCXHNST024)
关键词
计算机取证
分布式
自治型
computer forensics
distributed
autonomous model