首页> 外文会议>IEEE International Conference on Advanced Information Networking and Applications >Forensically-Sound Methods to Collect Live Network Evidence
【24h】

Forensically-Sound Methods to Collect Live Network Evidence

机译:收集现场网络证据的取证方法

获取原文

摘要

In the last decade Digital Forensics has experienced several issues when dealing with network evidence. An analyst, which is in charge of managing evidence flowing over a network have to face problems due to the volatile nature of such information. In facts, such data may change over time, may be lying on a server out of the his jurisdiction, or geographically far from where the crime was committed. In this paper two methods to allow remote collection of network evidence produced by online services such as web pages, chats, documents, photos and videos are presented. They enable the analyst to drive the acquisition process through the online services considered potential sources of evidence. During the process, all data flowing through the network is automatically collected (i.e., all the IP packets). The second one also collects the graphical representation of the acquisition (e.g., how the browser visualizes such data). Both methods introduce a trusted third party (acting as a digital notary) which is in charge of collecting and ``certifying'' network evidence. Before closing the acquisition process, a detailed report of the collected evidence is generated and made available to the analyst along with the collected data. Cryptographic primitives are used to demonstrate ex post data integrity, how it has been acquired and the acquisition time. As a proof of concept two prototypes have been implemented. To enhance the Court confidence of the collected evidence, at the same time, the service could be run across multiple coordinated servers acquiring the same data from different point of the network.
机译:在过去的十年中,数字取证在处理网络证据时遇到了多个问题。由于此类信息的易变性,负责管理流经网络的证据的分析师必须面对问题。实际上,此类数据可能会随时间变化,可能位于其管辖范围之外的服务器上,或者在地理上远离犯罪地。在本文中,提出了两种方法来允许远程收集由在线服务(例如网页,聊天,文档,照片和视频)产生的网络证据。它们使分析师能够通过被认为是潜在证据来源的在线服务来推动收购过程。在此过程中,将自动收集流经网络的所有数据(即所有IP数据包)。第二个也收集采集的图形表示(例如,浏览器如何可视化此类数据)。两种方法都引入了一个受信任的第三方(充当数字公证人),该第三方负责收集和``证明''网络证据。在结束获取过程之前,将生成一份详细的收集的证据报告,并将其与收集的数据一起提供给分析人员。加密原语用于演示事后数据的完整性,如何获取数据以及获取时间。作为概念验证,已实现了两个原型。为了增强法院对收集到的证据的信心,可以同时在多个协作服务器上运行该服务,这些服务器从网络的不同点获取相同的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号