DDCFS: A Distributed Dynamic Computer Forensic System Based on Network

被引:2
作者
Hu, Liang [1 ]
Tang, Kuo [1 ]
Shi, Guangkun [1 ]
Nurbol [1 ]
Zhao, Kuo [1 ]
机构
[1] Jilin Univ, Dept Comp Sci & Technol, Changchun 130012, Peoples R China
来源
ICICTA: 2009 SECOND INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION, VOL IV, PROCEEDINGS | 2009年
关键词
computer forensic; electronic evidence; dynamic forensic;
D O I
10.1109/ICICTA.2009.729
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increasing development of information technology, the computer crime problem is getting even serious. However traditional computer forensic that employs the static investigation after security events has inherent limitations. The authenticity, effectiveness and timeliness of the evidence are difficult to meet real needs. In order to solve the existing problems which static forensics technology has, this paper presents the design and implementation of DDCFS: a distributed dynamic computer forensics system based on network. Comparing with the traditional tools of the forensic system, it employs the work of gathering evidences of criminal actions before they occur or just they are ongoing, which avoid the evidence chain lose caused by traditional static forensic. It can improve the efficiency of the work of gathering evidences; enhance data integrity and timeliness of evidences. This paper describes the architecture, function and forensic procedure of DDCFS, and the implementation of the core module.
引用
收藏
页码:53 / 56
页数:4
相关论文
共 8 条
[1]  
Andrew MW, 2007, INT WORK SYS APPR D, P16
[2]  
Ding Li-Ping, 2005, Journal of Software, V16, P260, DOI 10.1360/jos160260
[3]  
Franke K, 2008, LECT NOTES COMPUT SC, V5158, P1
[4]   Backtracking intrusions [J].
King, ST ;
Chen, PM .
ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2005, 23 (01) :51-76
[5]  
PEISERT S, 2008, ACM SIGOPS OPERATING, V42, P112
[6]  
Schneier B., 1999, ACM Trans. Inf. Syst. Secur., V2, P159
[7]  
Wang Ling, 2003, Journal of Software, V14, P1635
[8]  
Whitcomb C.M., 2002, International Journal of Digital Evidence, V1, P7