Journal on Communications ›› 2012, Vol. 33 ›› Issue (Z2): 125-134.doi: 10.3969/j.issn.1000-436x.2012.z2.016

• Papers • Previous Articles     Next Articles

Study on electronic evidence acquisition and analysis method over Windows logs

Xiao-mei DONG1,Xu-dong LIU1,Xiao-hua LI1,Ya-jie FEI2   

  1. 1 College of Information Science and Engineering,Northeastern University,Shenyang 110004,China
    2 Department of Information Engineering,Shenyang Institute of Engineering,Shenyang 110136,China
  • Online:2012-11-25 Published:2017-08-03
  • Supported by:
    The Fundamental Research Funds for the Central Universities

Abstract:

In order to collect logs in real time,two methods to acquire Windows logs in real time were proposed respectively according to the two types of log file formats.Based on acquiring logs,an approach for correlating log files with atomic attack functions was proposed.After the correlation,atomic attack functions can be analyzed instead of log files,which can greatly decrease the time of analysis.A time based log correlation and event reconstruction method was proposed to reconstruct the computer criminal scenarios.Experimental results show that log evidences can be acquired and the crime process can be reconstructed effectively.

Key words: computer forensics, Windows logs, acquisition, analysis, event reconstruction

No Suggested Reading articles found!