摘要
针对司法取证的要求,结合网络数据的特点,提出了基于网络的动态电子取证模型,描述了总体结构和相关规则.为保证取证网络会话的完整性,设计了基于二维链表的多队列高速网络数据缓存算法,并验证了该算法的有效性,解决了取证模型的关键技术.最后利用插件技术实现了可扩展的取证系统.
Considering on judicial forensic requirements and the characteristic of network packets,a network dynamic forensic model is proposed,which architecture and related rules are described.An algorithm based two-dimensional linked list and multi-queue which is used to cache network data in high speed network is designed.The effectiveness of the algorithm is analyzed and tested.The algorithm resolves key problem in the above model and ensures the integrality of network session which is saved.Finally,a network forensic system is designed by plug-in,which is extensible and support second development.
出处
《电子学报》
EI
CAS
CSCD
北大核心
2010年第11期2529-2534,共6页
Acta Electronica Sinica
基金
河南省科技攻关计划(No.082102210082,No.082102210092)
关键词
取证模型
二维链表
高速缓存算法
插件技术
forensic model
two-dimensional linked list
caching algorithm
plug-in