作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 117-119,. doi: 10.3969/j.issn.1000-3428.2007.16.040

• 安全技术 • 上一篇    下一篇

基于远程控制技术的动态取证系统

史伟奇1,3,张波云2,谢冬青1   

  1. (1. 湖南大学软件学院,长沙 410082;2. 国防科技大学计算机学院,长沙410073;3. 湖南公安高等专科学校计算机系,长沙 410006)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

System of Dynamic Computer Forensic Based on Remote Control Technology

SHI Wei-qi1, 3, ZHANG Bo-yun2, XIE Dong-qing1   

  1. (1. School of Software, Hunan University, Changsha 410082; 2. School of Computer, National University of Defense Technology, Changsha 410073; 3. Computer Department, Hunan Public Security Academy, Changsha 410006)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要: 设计了一种新的基于远程控制技术的计算机取证系统,提供了3种不同取证方法动态获取控制目标的电子证据,研究了文件隐藏、进程隐藏、注册表修改隐藏、端口反弹、数据加密等关键技术。实验表明,该系统能动态获取网上不同监控对象的电子证据,是当前取证技术的一种新思路。

关键词: 计算机取证, 远程控制, 电子证据, 动态获取

Abstract: A novel computer forensics system based on remote control technology is present. By using three different ways of evidence-obtaining and evidence-controlling for different subjects, the system can realize objective of dynamic obtaining electronic evidence of the monitored subjects, including the research on the key technologies of process hiding and file hiding, register modifying and hiding, ports back-bouncing, and data encrypting about the system as well. Experimental result shows that the system realizes the active obtaining evidence to the monitored subjects on the network by different applications, and it demonstrates that this is a new technical thinking in the current computer forensics technology.

Key words: computer forensics, remote control, electronic evidences, dynamic obtaining

中图分类号: