摘要
文章根据操作系统日志文件记录的信息,提出了使用事件查看器和日志分析工具对日志文件进行分析,提取已修改的计算机系统时间的事件,从而证实计算机系统时间被修改。
According to the information recorded in the log file of the operating system, this paper analyzes the log file with the event viewer and log analyzing tools,extracts the event which time of computer system has been modified ,thus proving the time of the computer system has been modified.
出处
《信息网络安全》
2013年第5期33-34,共2页
Netinfo Security
关键词
日志
修改
系统时间
提取方法
log
modify
system time
extraction method