首页> 外国专利> Systems and methods to counter the removal of digital forensic information by malicious software.

Systems and methods to counter the removal of digital forensic information by malicious software.

机译:通过恶意软件抵消删除数字法医信息的系统和方法。

摘要

The invention relates to a method and a system (100) for preventing anti-forensic actions. The method identifies a suspicious object from a plurality of objects on a computer device (102) monitors actions performed by the suspect object. The method intercepts a first command from the suspect object, aimed at creating and / or modifying a digital artifact on the computer device and, after the interception of the first command, intercepts a second command from the suspect object, aimed at eliminating at least a suspicious object and the digital artifact. In response to the interception of both the first command aimed at creating and / or modifying the digital artifact and the second command aimed at eliminating at least the suspicious object and the digital artifact, the method blocks the second command and saves the suspect object and the digital artifact in a digital archive (116). The system is suitable for performing the method described above. [Fig. 1]
机译:本发明涉及一种用于防止防锐动作的方法和系统(100)。该方法识别来自计算机设备上的多个对象的可疑对象(102)监视由嫌疑对象执行的动作。该方法拦截来自嫌疑对象的第一命令,旨在在计算机设备上创建和/或修改数字伪影,并且在拦截第一命令之后,拦截来自嫌疑对象的第二命令,旨在消除至少一个可疑对象和数字工件。响应于拦截旨在创建和/或修改数字工件的第一个命令和旨在消除至少可疑对象和数字工件的第二命令,该方法阻止第二个命令并保存可疑对象和数字档案中的数字工件(116)。该系统适用于执行上述方法。 [无花果。 1]

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号