作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (11): 14-16. doi: 10.3969/j.issn.1000-3428.2012.11.005

所属专题: 云计算专题

• 云计算专题 • 上一篇    下一篇

云取证模型的构建与分析

公 伟1,2,刘培玉1,2,迟学芝3,贾 娴1,2   

  1. (1. 山东师范大学信息科学与工程学院,济南 2. 山东省分布式计算机软件新技术重点实验室,济南 250014; 3. 山东警察学院公共基础部,济南 250014)
  • 收稿日期:2011-08-11 出版日期:2012-06-05 发布日期:2012-06-05
  • 作者简介:公 伟(1987-),男,硕士研究生,主研方向:网络信 息安全,网络安全;刘培玉,教授、博士生导师;迟学芝,讲师;贾 娴,硕士研究生
  • 基金资助:
    国家自然科学基金资助项目(60873247);山东省教育厅 科技计划基金资助项目(J09LG52)

Construction and Analysis of Cloud Forensics Model

GONG Wei 1,2, LIU Pei-yu 1,2, CHI Xue-zhi 3, JIA Xian 1,2   

  1. 1. School of Information Science and Engineering, Shandong Normal University, Jinan 250014, China; 2. Shandong Provincial Key Laboratory for Distributed Computer Software Novel Technology, Jinan 250014, China; 3. Department of General Foundation, Shandong Police College, Jinan 250014, China)
  • Received:2011-08-11 Online:2012-06-05 Published:2012-06-05

摘要: 计算机取证存在证据获取困难及日志处理量大的问题。为此,将云计算思想引入计算机取证中,提出一种云取证模型。该模型利用Agent技术获取证据,增强证据获取的自主性、智能性,利用云计算中的虚拟化技术和协作技术,提高取证效率及计算机证据的安全性,引入反馈技术,完善取证体制。实验结果验证了该模型的有效性。

关键词: 计算机取证, 云计算, 云取证模型, 智能体, 虚拟化技术

Abstract: There exist the problems of difficulties in evidence obtaining and numerous logs to be dealt with in computer forensics. Aiming at these problems, this paper introduces the cloud computing into computer forensics, proposes a Cloud Forensics Model(CFM). CFM obtains evidence by making use of Agent technology, which can increase autonomy and intelligence of evidence acquisition. It improves the forensics efficiency and the safety of computer evidence by using the virtualization technology and collaboration technology. It introduces the feedback technology, which can consummate the evidence collection system. Experimental results prove the validity of the model.

Key words: computer forensics, cloud computing, Cloud Forensics Model(CFM), Agent, virtualization technology

中图分类号: