摘要
针对目前基于Docker容器的取证技术缺陷,提出一种基于Docker主机的调查取证模型,并根据该取证模型中Docker主机所处不同状态给出有针对性的数据取证方法.实验结果表明,利用该模型取证能更有针对性地获取相关电子证据.
Aiming at the shortcomings of forensic technology based on Docker container,we proposed an investigation and forensics model based on Docker host,and gave a targeted data forensics method according to the different states of the Docker host in the forensic model.The experimental results show that the forensics can obtain relevant electronic evidence more specifically by using the model.
作者
李鹏超
周凯
LI Pengchao;ZHOU Kai(Department of Information Security,Chongqing Police College,Chongqing 401331,China;College of Computer and Information Science,Southwest University,Chongqing 400715,China)
出处
《吉林大学学报(理学版)》
CAS
北大核心
2019年第6期1485-1490,共6页
Journal of Jilin University:Science Edition
基金
重庆市教委科学技术研究项目(批准号:KJQN201801703)