网站入侵案件中的电子证据研究  被引量:4

Research on the Digital Evidence in the Illegal Network Intrusion

在线阅读下载全文

作  者:刘建军[1] 黄政[1] 

机构地区:[1]南京市公安局网络安全保卫支队,江苏南京210005

出  处:《信息网络安全》2011年第11期87-90,共4页Netinfo Security

摘  要:为了提高电子证据勘查取证水平,有效打击网站入侵案件,笔者通过模拟网络环境对常见网站入侵方式进行研究,同时也对近两年侦办的网站入侵案件进行了分析。文章阐述了在网站入侵案件中电子证据现场勘查需要重点勘查服务器日志、网站日志、木马文件、特殊目录下的特殊文件等日志和文件,需要提取、固定IP地址、用户名、计算机名称、虚拟身份、入侵工具、木马等重要证据,并结合两个实际案例进行深入分析。In order to improve the capability of investigating digital evidence and counter-attacking such illegal invasions,the writer imitates a network and does research on common network invasions on the basis of well-grounded analysis of the cases involved in illegal network invasions the writer once participated in detecting in these two years.After exploring such illegal network invasions,the writer proposes,in the dissertation,that much attention should be posed to the server logs,website logs,the Trojan horse files,Special file of special directory,logs and files in exceptional lists.Some important evidence,such as IP,the names of users,the names of the computers,Virtual identity,the ways of invasions,the Trojan horse files,and so on,must be extracted and fixed.Furthermore,the writer,in this dissertation,also illustrates and exemplifies such conclusions based on the two real cyber crimes.

关 键 词:网站 入侵 电子证据 黑客 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象