信息网络安全 ›› 2018, Vol. 18 ›› Issue (3): 39-45.doi: 10.3969/j.issn.1671-1122.2018.03.005

• • 上一篇    下一篇

基于云服务端的节点多层次数据协同分析研究

罗文华1(), 王俊1, 孙媛媛2   

  1. 1.中国刑事警察学院网络犯罪侦查系,辽宁沈阳110035
    2.大连理工大学计算机科学与技术学院,辽宁大连116024
  • 收稿日期:2017-11-15 出版日期:2018-03-15 发布日期:2020-05-11
  • 作者简介:

    作者简介:罗文华(1977—),男,辽宁,教授,硕士,主要研究方向为网络犯罪侦查、电子数据取证;王俊(1993—),男,山东,硕士研究生,主要研究方向为网络安全;孙媛媛(1979—),女,山东,副教授,博士,主要研究方向为网络安全。

  • 基金资助:
    国家自然科学基金[61572103];公安部技术研究计划[2017JSYJA10]

Research on Multi-layer Data Cooperative Analysis of Nodes Based on Cloud Server

Wenhua LUO1(), Jun WANG1, Yuanyuan SUN2   

  1. 1. Cyber Crime Investigation Department, Criminal Investigation Police University of China, Shenyang Liaoning 110035, China
    2. School of Computer Science & Technology, Dalian University of Technology, Dalian Liaoning 116024, China;
  • Received:2017-11-15 Online:2018-03-15 Published:2020-05-11

摘要:

当前,云平台调查取证的核心难点在于关键证据识别以及证据链条构建。基于云服务端的行为重现与场景构建能够有效实现孤立行为点关联,进而增强证据的证明力。场景重现的基础是云环境下各类节点中的重要系统文件,包括管理应用数据所需的元数据、云环境架构配置和日志数据,同时还涉及各Slave节点的inode结构。文章将云服务端各节点重要系统数据作为揭示用户操作行为的最重要来源,基于时序关系考量各节点证据之间的有效衔接,使得全景展示犯罪场景变为可能,从而在场景重现基础上实现分布式文件系统环境下的删除数据恢复。

关键词: 云平台, 操作行为, 场景重现, 日志文件, 数据恢复

Abstract:

At present, the core problem of the investigation and collection of the cloud platform lies in the identification of key evidence and the construction of the chain of evidence. The behavior replay and scene construction based on the cloud server can effectively realize the association of isolated action points, and then increase the probative force of the evidence.The basis of scene reproduction are the important system files in various nodes in the cloud environment, included the metadata, the cloud environment architecture configuration, the log data and the inode structure of each Slave node. The nodes of cloud server system as the most important source of important data to reveal the user behavior, timing relationship interface between each node based on evidence, the crime scene for panoramic display. Thus, the data recovery in the distributed file system environment is realized on the basis of scene reproduction.

Key words: cloud platform, operational behavior, scene reproduction, log files, data recovery

中图分类号: