期刊文献+

浏览器取证技术 被引量:3

Overview of Browser Forensics Technology
下载PDF
导出
摘要 随着信息时代的来临,一些不法分子在实施犯罪之前往往会上网查询信息,他们所用的浏览器便成了司法机关取证的关键.能否提取有效的犯罪线索或证据,取决于浏览器取证方法的好坏,本文介绍了目前主流的火狐浏览器、IE浏览器的取证技术,概述了IE缓存文件和基于SQLite数据库的火狐浏览器历史系统的日志文件结构,提出了信息恢复方法.通过对已删除日志文件或缓存文件信息提取,来达到获取证据的目的,分析用户的行为. With the advent of the information age, some criminals always tend to query information from the Internet before they engaged in criminal activity. So the browser they used has become the key to the forensics of judicial authorities. Whether we can extract the effective evidence of crime depends on the forensics method of browser. This article introduces the forensics technology of Firefox and IE browser which are the current mainstream browsers, outlined the browser temporary file structure, such as the IE cache file and the SQLite database log files of the Firefox, proposed information recovery method. It can collect information of the deleted log files or cache files. evidence and analyze the user's behavior by extract the
出处 《计算机系统应用》 2014年第5期8-15,共8页 Computer Systems & Applications
关键词 浏览器取证 SQLITE数据库 日志文件 信息提取 browser forensic SQLite database log file information extraction
  • 相关文献

参考文献5

  • 1Pereira MT. Forensic analysis of the Firefox 3 intemet history and recovery of deleted SQLite records. Digital Investigation, 2009, (5): 93-103. 被引量:1
  • 2Chen L. Computer Forensics. Wuchang: Wuhan University, 2007: 1-13. 被引量:1
  • 3FirefoxForensic.Firefoxmoz-page-thumbs. http://kb.digital- detective.co.uk/. 被引量:1
  • 4Oh J, Lee S, Lee S. Advanced evidence collection and analysis of web browser activity. Digital Investigation, 2011, (8): 62-70. 被引量:1
  • 5Jones KJ. Forensic Analysis of Intemet Explorer Activity Files, 2003. 被引量:1

同被引文献18

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部