信息网络安全 ›› 2016, Vol. 16 ›› Issue (9): 60-63.doi: 10.3969/j.issn.1671-1122.2016.09.012

• • 上一篇    下一篇

基于大数据环境的电子取证研究

姜凤燕(), 姜瑾, 姜吉婷   

  1. 山东省济南市公安局网警支队,山东济南250013
  • 收稿日期:2016-07-25 出版日期:2016-09-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 姜凤燕(1987—),女,山东,硕士,主要研究方向为网络信息安全、电子取证;姜瑾(1970—),女,山东,高级工程师,本科,主要研究方向为云计算和智能信息处理、电子取证;姜吉婷(1986—),女,山东,硕士,主要研究方向为物联网大数据、电子取证。

Research on Electronic Forensic Based on Big Data Environment

Fengyan JIANG(), Jin JIANG, Jiting JIANG   

  1. Internet Police Detachment, Jinan Municipal Public Security Bureau, Jinan Shandong 250013, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

摘要:

数据是未来各行各业必争的资源,如何获取并有效利用数据将成为公安信息化建设进程中亟待解决的问题。特别是随着云计算技术的发展及应用,行业应用领域信息系统的规模日益增大,产生的数据量也急剧增加。互联网在给人们带来丰富信息的同时,网络犯罪活动也日益增多,这不仅增加了办案人员的工作量,也使传统的电子取证技术面临无法高效进行海量数据的存储和分析的挑战。串行处理技术与单处理器很难在有效时间内处理巨大的数据量,同时无法满足大规模数据集对于物理设备的需求以及数据资源的共享需求。云计算推崇的是按需付费模式,不必考虑太多底层基础设备的情况。Hadoop作为开源的云计算基础架构,是目前应用最成功和最广泛的大数据批处理平台。文章在研究Hadoop平台的基础上,将其应用于电子取证中,构建基于大数据环境的层次化取证模型,为设备资源合理调度、建设数据资源智能共享的综合取证服务平台提供理论支持。

关键词: 电子取证, 大数据, Hadoop平台, 分布式取证

Abstract:

Data is a kind of competitive resources for all walks of life in the future, thus how to get effective data will become a problem to be solved in the process of public security information construction. Especially with the development and application of cloud computing technology, the scale of information system applied in the various fields has enlarged, and the amount of data has also increased day by day. Internet brings to people rich information, and on the other side, promotes the network crime, which creates more work to investigators. The biggest challenge is the traditional electronic forensic technology has been unable to store and analyze massive data efficiently. Serial processing technology and single processor is hard to deal with a huge amount of data within a valid period of time, and cannot meet the demand of large dataset for physical devices as well as the demand of sharing various data. Cloud computing is highly prized for the mode of pay-on-demand, regardless of the conditions of many bottom infrastructures. As an open source cloud computing infrastructure, Hadoop is the most successful and popular big data batch processing platform so far. Based on the research of Hadoop platform, this article applies Hadoop to electronic forensic to establish a hierarchical forensic model under the big data environment. At the same time, this article provides theoretical support to achieve the reasonable scheduling of the equipment resources, and to construct the comprehensive forensic service platform for intelligence sharing of data resources.

Key words: electronic forensic, big data, Hadoop platform, distributed forensic

中图分类号: