摘要
针对传统网络取证技术的特点和技术挑战,对Bloom filter的特性进行了分析研究,设计了基于Bloom filter的网络取证系统。该系统利用Bloom filter数据结构的特点,能够实时对网络原始数据进行采集、压缩、存储,有效节省存储空间,支持高效的网络取证事后分析查询。最后指出了进一步的研究方向。
Aiming at technical challenges of traditional network forensics,this paper researches the trait of Bloom filter.A network forensics system based on Bloom filter is proposed and designed.Making use of the characteristics of Bloom filter data structure,the system can collect,compress and store the raw network data,so that the storage space is efficiently saved and post-event querying and analyzing is supported.At last some advices about future works are given.
出处
《计算机工程与应用》
CSCD
北大核心
2010年第14期91-94,共4页
Computer Engineering and Applications