摘要
手机取证过程中的多种动态性因素都会导致前后两次内存镜像不一致,从而影响获取证据的真实性和可采性。分析了手机内存中的数据变化规律,引入细粒度完整性检验方法对手机内存镜像中的数据对象按照细粒度分别进行完整性检验。结合各种案例选取不同数据对象作为证据的需求,将手机内存镜像数据划分为不同粒度的数据对象。该方法可以有效地隔离不同数据对象,使得在内存镜像变化难以避免的情况下,验证了取证镜像过程的可靠性,证明目标数据对象的完整性,从而保证作为证据的数据对象能够被法庭接受。
A variety of the dynamic factors in mobile phone forensics process can lead to inconsistencies in the back-to-back memory image, thus affecting the authenticity and admissibility of the evidence. The data variation in the phone memory is analyzed, according with the introduction of fine-grained method and the integrity of the data in the phone memory image objects is tested separately by fine-grained. Combining with different cases, select different data objects as evidence demand, and divide the phone memory image data into data objects of different size. This method can effectively isolate the different data objects, in the case of inevitable changes in memory image, verify the reliability of forensic image process and prove the integrity of the target data objects, thus ensuring data objects as evidence can be accepted by courts.
出处
《计算机工程与设计》
CSCD
北大核心
2012年第11期4091-4094,4148,共5页
Computer Engineering and Design
基金
重庆市教委科学技术研究基金项目(KJ110505)
重庆市科技攻关计划基金项目(CSTC
2011AC2155)