暗网取证研究  被引量:3

Research on Dark Web Forensics

在线阅读下载全文

作  者:苏再添 张莹莹 黄志炜[1] SU Zaitian;ZHANG Yingying;HUANG Zhiwei(Xiamen Meiya Pico Information Co.,Ltd.,Xiamen Fujian 361008,China)

机构地区:[1]厦门市美亚柏科信息股份有限公司,福建厦门361008

出  处:《信息安全与通信保密》2021年第3期99-107,共9页Information Security and Communications Privacy

摘  要:随着互联网技术的高速发展,人们对上网的需求不只局限在内容上,更多地开始重视对网络信息内容、网络通信双方身份及通信模式的隐匿保护。暗网正是采用隐匿上网者的IP报文信息的手段,来保护个人私有信息并实现防追踪功能。由于暗网的特性,当前针对暗网的监管较少,同时暗网的“匿名技术”使得寻常手段很难追踪到暗网的使用者。以上因素造成了大量的违法交易选择在暗网进行,给执法部门的案件侦破带来很大的困难。在分析了一系列暗网违法交易过程之后,提出以虚拟专用网络取证、内存取证、洋葱浏览器取证、数字货币取证、网络流量取证以及镜像网站取证为主的取证方案,旨在针对利用暗网实施犯罪行为的可疑人员,进行证据固定和证据提取。With the rapid development of Internet technology,people's demand for Internet access is not limited to content.More attention has been paid to the hidden protection of network information content and the identity and communication mode of both parties of network communication.The dark web is a method of hiding the IP message information of Internet users to protect personal private information and prevent tracking.Due to the characteristics of the dark web,there is currently less regulation on the dark web.At the same time,the anonymity technology of the dark web makes it difficult for ordinary users to track the users of the dark web.The above factors have caused a large number of illegal transactions to be conducted on the dark web,which has caused great interference in the detection of cases by law enforcement agencies.After analyzing a series of illegal transactions on the dark web,a forensic scheme based on virtual private network forensics,memory forensics,onion browser forensics,digital currency forensics,network traffic forensics,and mirroring website forensics is proposed.It aims to fix and extract evidence against suspicious individuals who use the dark web to commit crimes.

关 键 词:暗网 虚拟专用网络取证 内存取证 洋葱浏览器取证 数字货币取证 

分 类 号:TN915.08[电子电信—通信与信息系统]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象