通信学报 ›› 2012, Vol. 33 ›› Issue (Z2): 125-134.doi: 10.3969/j.issn.1000-436x.2012.z2.016

• 学术论文 • 上一篇    下一篇

基于Windows日志的电子证据获取与分析方法研究

董晓梅1,刘旭东1,李晓华1,费雅洁2   

  1. 1 东北大学 信息科学与工程学院,辽宁 沈阳 110004
    2 沈阳工程学院 信息工程系,辽宁 沈阳 110136
  • 出版日期:2012-11-25 发布日期:2017-08-03
  • 基金资助:
    教育部中央高校基本科研业务费基金资助项目

Study on electronic evidence acquisition and analysis method over Windows logs

Xiao-mei DONG1,Xu-dong LIU1,Xiao-hua LI1,Ya-jie FEI2   

  1. 1 College of Information Science and Engineering,Northeastern University,Shenyang 110004,China
    2 Department of Information Engineering,Shenyang Institute of Engineering,Shenyang 110136,China
  • Online:2012-11-25 Published:2017-08-03
  • Supported by:
    The Fundamental Research Funds for the Central Universities

摘要:

为解决Windows日志的实时获取问题,针对2种日志文件格式,分别提出了相应的日志实时获取方法。在实时获取日志的基础上,提出了将日志文件与原子攻击功能关联的方法,将对日志文件的分析转换成对原子攻击功能的分析,大大减少了日志文件分析的时间。提出了一种基于时间的日志关联分析和事件重构方法,实现对计算机犯罪场景的还原。实验结果表明,提出的方法可以有效获取日志证据,重构犯罪过程。

关键词: 计算机取证, Windows日志, 获取, 分析, 事件重构

Abstract:

In order to collect logs in real time,two methods to acquire Windows logs in real time were proposed respectively according to the two types of log file formats.Based on acquiring logs,an approach for correlating log files with atomic attack functions was proposed.After the correlation,atomic attack functions can be analyzed instead of log files,which can greatly decrease the time of analysis.A time based log correlation and event reconstruction method was proposed to reconstruct the computer criminal scenarios.Experimental results show that log evidences can be acquired and the crime process can be reconstructed effectively.

Key words: computer forensics, Windows logs, acquisition, analysis, event reconstruction

No Suggested Reading articles found!