节点文献
基于协议分析的网络入侵动态取证系统设计
Design of Protocol Analysis Based IDS and Dynamic Computer Forensic System
【摘要】 计算机取证技术分为静态取证和动态取证两种。静态取证技术由于采用事后分析的方法提取证据,因而证据的采集不够全面,同时恢复的数据可能是已经被篡改的数据,因而法律效力低。文中将计算机取证技术与入侵检测技术结合,提出一种基于协议分析的网络入侵动态取证系统。该系统采用基于协议分析的入侵检测方法,提高了入侵检测效率及数据分析能力,有助于解决动态取证的实时性;同时系统采取了较全面的安全机制,确保收集的电子证据的真实性、有效性、不可篡改性,是动态计算机取证的一种较好解决方案。
【Abstract】 The computer forensic mainly consists of two techniques: the static forensic and dynamic forensic.The static computer forensic collects electronic evidences after the intrusion has happened,so it’s difficult to collect the evidences entirely and even the recovered files may has been modified,the collected electronic evidences are not so available in law.The paper provides a dynamic computer forensic system combined computer forensic technology and intrusion detection system based on protocol analysis.The system can improve the efficiency of intrusion detection and the ability of data analysis by using the protocol analysis method.It’s helpful to realize collecting electronic evidences dynamically in real-time.The system also uses several kinds of network safe mechanisms to ensure the accuracy,validity,immutability of the electronic evidences.It’s a good solution of dynamic computer forensic.
【Key words】 computer forensic; electronic evidence; intrusion detection; evidences collection;
- 【文献出处】 计算机技术与发展 ,Computer Technology and Development , 编辑部邮箱 ,2006年04期
- 【分类号】TP393.08
- 【被引频次】9
- 【下载频次】244