期刊文献+

基于移动介质的免拆机取证技术 被引量:1

Disassemble-free Forensic Technology Based on Removable Media
下载PDF
导出
摘要 鉴于实际取证工作中存在的不允许拆卸计算机硬盘的情况,基于移动介质的免拆机取证技术应运而生。然而目前使用的免拆机取证技术存在着种种缺陷,本文就如何提高硬盘复制速度、提高取证效率、保证证据的司法有效性、增强无痕取证等问题,提出相应的解决方案,让取证工作更快速、更准确。 Because of difficulties of taking out hard drives from desktop or notebook computers of the suspect during forensic practice, disassemble-free forensic technology based on removable media came into being, but current solution still had lots of deficiencies. This paper describes solutions on how to improve the duplication speed of hard drive to make digital evidence processing more efficient and forensically sound, and how to enhance the capability of live forensics without trace. These solutions will make evidence processing faster and more accurate during the process of digital investigations.
作者 陈明金
出处 《信息网络安全》 2010年第11期27-30,共4页 Netinfo Security
关键词 移动介质 免拆机 WINPE Computer Forensic Disassemble-free Windows PE
  • 相关文献

参考文献8

二级参考文献17

  • 1丁丽萍,王永吉.计算机取证的相关法律技术问题研究[J].软件学报,2005,16(2):260-275. 被引量:84
  • 2徐爱钧,万天军,李家绪.一种U盘数据采集系统的设计[J].长江大学学报(自科版)(上旬),2006,3(3):79-81. 被引量:4
  • 3于波,涂敏.计算机取证分析[J].计算机与现代化,2006(12):4-6. 被引量:10
  • 4张有东,王建东,朱梧槚.反计算机取证技术研究[J].河海大学学报(自然科学版),2007,35(1):104-107. 被引量:13
  • 5grugq.Defeating forensic analysis on Unix. Phrack #59 article6.http://www.phrack.org/show.phpp=59a=6,2002.
  • 6Farmer D.What are MACtimes Dr. Dobb''s Journal.http://www.ddj.com/documents/s=880/ddj0010f/0010f.htm,2000,10.
  • 7Farmer D Venema W.The coroner''''s toolkit (TCT). Dan Farmer Wietse Venema.http://www.fish.com/tct/,2002.
  • 8grugq scut.Armouring the ELF: Binary encryption on the UNIX platform. Phrack #58 article5.http://www.phrack.org/show.phpp=58a=5,2001.
  • 9Oseles L.Computer forensics: The key to solving the crime.http://facuity.ed.umuc.edu/-meinkej/inss690/oseles_2.pdf,2001.
  • 10ParraM.Computer forensics.http://www.giac.org/practical/Moroni_Parra_GSEC.doc,2002.

共引文献205

同被引文献7

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部