摘要
家用路由器是一种用于网络互联的设备,常用于当代家庭、公司、企业等小型场景。本文将探讨家用路由器电子数据取证方法,为传统案件和网络犯罪案件侦查提供线索。本文对家用路由器的定义、功能、厂商、硬件架构、软件以及在犯罪侦查中的作用进行了总结。在此基础上梳理了家用路由器的取证方法,包括动态取证和静态取证。动态取证介绍了运行状态下家用路由器的信息搜集、权限获取;静态取证介绍了被固定为证据的家用路由器的信息搜集、连接方式、数据提取和固件分析。
SOHO(small office/home office)router,a common network device,is universally used in the household,company,enterprise and other scenarios so that it can provide clues for both the detection of traditional cases and the investigation of cybercrime.This article summarizes the SOHO router about its definition,functions,vendors,hardware architecture,software and the role in criminal investigation.Furthermore,two forensic methods,dynamic and static,are sorted out for investigation of such kinds of router.The dynamic handling involves with the information collection and authority acquisition when the SOHO routers are running while the static deals with the information gathering,connection methods,data extraction and firmware analysis from the SOHO routers that are riveted as evidence.
作者
袁心宇
张璇
潘光诚
姜吉国
YUAN Xinyu;ZHANG Xuan;PAN Guangcheng;JIANG Jiguo(Jinan Public Security Bureau,Jinan 250099,China;Shandong Police College,Jinan 250200,China;Shandong Provincial Public Security Department,Jinan 250001,China)
出处
《刑事技术》
2020年第3期278-283,共6页
Forensic Science and Technology
关键词
刑事侦查学
家用路由器
网络犯罪侦查
电子数据
取证
criminal investigation
SOHO router
cybercrime investigation
electronic data
forensics