论文部分内容阅读
在分析数字证据特点的基础上,提出并建立了网络取证中数字证据信息处理过程模型。针对其中的关键性问题,包括证据信息完整性问题、证据信息存贮问题和证据信息分析问题等提出新的相应的解决方案。证据信息从多数据源收集后,通过数据结构转换和完整性处理实现证据信息的标准结构存贮以及建立证据信息间的相关性,并存入数据仓库。采用正向推断和逆向推断相结合的方法对数据仓库内证据信息进行分析。
On the basis of analyzing the characteristics of digital evidence, this paper proposes and establishes a model of digital evidence information processing in network forensics. In view of the key problems among them, including the integrity of evidence information, the storage of evidence information and the analysis of evidence information, a new solution is proposed. After the evidence information is collected from multiple data sources, the standard structure of evidence information storage and the correlation between evidence information are established through the data structure conversion and integrity processing and stored in the data warehouse. The combination of forward inference and reverse inference is used to analyze the evidence in the data warehouse.