摘要
针对多台目标机和一台取证服务器,可同时在线收集多台计算机的关键证据,并提供案件管理、智能分析等功能,实现证据获取。服务器端主要通过网络通信来获取多台目标机内的证据,并采取知识推理和数据挖掘技术,从大量的电子证据中分析、推理出有效的鉴定结论,改变了目前只能人工对计算机活证据进行分析的现状,提高了工作效率和准确度,具有很大的价值。
For multi target machines and one evidence server, the system enables to collect the key evidences on multi computers at the same time, and provides case management, intelligence analysis and other functions, to achieve evidences accessing. On the serverside, it mainly obtains the evidences from multi target machines via network, and introduced knowledge reasoning and data mining technologies. It analyzes and inferences identification conclusions effectively from a large number of electronic evidences, which changed the current situation that can only analyzing human to computer live evidences, and improved the efficiency and accuracy, it has great value.
出处
《计算机工程与设计》
CSCD
北大核心
2010年第2期266-269,共4页
Computer Engineering and Design
基金
山东省自然科学基金项目(Y2008G35)
关键词
在线取证
离线取证
客户端/服务端
网络版
电子证据
on-line evidence
offline evidence
client/server
network version
electronic evidence