电信科学 ›› 2010, Vol. 26 ›› Issue (12): 72-78.doi: 10.3969/j.issn.1000-0801.2010.12.021

• 研究与开发 • 上一篇    下一篇

基于用户行为关联分析的电子取证系统研究

苏红1,2,万国根3   

  1. 1 四川大学数学学院 成都610065
    2 公安部第三研究所 上海200031
    3 清华大学网络行为研究所 北京100084
  • 出版日期:2010-12-15 发布日期:2010-12-15
  • 基金资助:
    国家发改委信息安全基金资助专项“面向主动防御的电子取证系统”

Electronic Forensics System Based on User Behaviors Correlation Analysis

Hong Su1,2,Guogen Wan3   

  1. 1 College of Math,Sichuan Univ.,Chengdu 610065,China
    2 The Third Research Institute of Ministry of Public Security,Shanghai 200031,China
    3 Inst.of Network Behaviors,Tsinghua Univ.,Beijing 100084,China
  • Online:2010-12-15 Published:2010-12-15

摘要:

针对目前电子取证缺乏全程监督的问题提出了一种基于用户行为关联分析的电子取证系统。该系统根据业务活动主体、行为和客体约束关系建立用户行为知识库,基于电子证据属性相似度,对原始电子证据进行过滤和融合,在WINEPI算法的基础上,实现电子证据的用户行为关联。使用实际数据测试表明,该系统能够对用户网络活动过程进行全程监督,并可以把取证过程的监督数据作为呈堂的证据。

关键词: 电子取证, 关联分析, 用户行为

Abstract:

Aimed at the problem of which the electronic forensics lack of full supervision,the electronic forensics system based on user behaviors correlation analysis was presented.The system according to the main business activities,behavior,and object constraints of application established knowledge of user behavior,based on the similarity properties of electronic evidence, electronic evidence of the original filter and integration,in WINEPI algorithm based on the realization of user behavior associated with electronic evidence.Tested using actual data show that the system can monitor the whole process of network activity and can show the supervised data as evidence in court.

Key words: electronic evidence, user behavior, correlation

No Suggested Reading articles found!