Netinfo Security ›› 2018, Vol. 18 ›› Issue (3): 39-45.doi: 10.3969/j.issn.1671-1122.2018.03.005

• Orginal Article • Previous Articles     Next Articles

Research on Multi-layer Data Cooperative Analysis of Nodes Based on Cloud Server

Wenhua LUO1(), Jun WANG1, Yuanyuan SUN2   

  1. 1. Cyber Crime Investigation Department, Criminal Investigation Police University of China, Shenyang Liaoning 110035, China
    2. School of Computer Science & Technology, Dalian University of Technology, Dalian Liaoning 116024, China;
  • Received:2017-11-15 Online:2018-03-15 Published:2020-05-11

Abstract:

At present, the core problem of the investigation and collection of the cloud platform lies in the identification of key evidence and the construction of the chain of evidence. The behavior replay and scene construction based on the cloud server can effectively realize the association of isolated action points, and then increase the probative force of the evidence.The basis of scene reproduction are the important system files in various nodes in the cloud environment, included the metadata, the cloud environment architecture configuration, the log data and the inode structure of each Slave node. The nodes of cloud server system as the most important source of important data to reveal the user behavior, timing relationship interface between each node based on evidence, the crime scene for panoramic display. Thus, the data recovery in the distributed file system environment is realized on the basis of scene reproduction.

Key words: cloud platform, operational behavior, scene reproduction, log files, data recovery

CLC Number: