Patents
Literature
Hiro is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Hiro

56results about How to "Improve forensics efficiency" patented technology

Sobel edge detection and image block brightness feature-based blind image tampering forensic method

The invention discloses a Sobel edge detection and image block brightness feature-based blind image tampering forensic method. The method is characterized by comprising the following steps of: converting a to-be-detected suspicious image into a grayscale image; carrying out convolution processing on the grayscale image I (i, j); obtaining a gradient image G (i, j) of the image; carrying out threshold value segmentation on the G (i, j) to obtain the gradient image G (i, j); carrying out binary processing on the gradient image G (i, j) to obtain a binary image W (i, j); carrying 1 pixelation on the binary image; and judging the similarity of two sub-image sets. According to the method, blocking processing is carried out on image sets; through brightness mean value sorting, the forensic algorithm efficiency can be effectively improved; and through comparing the similar brightness values of image blocks, the correctness is further improved and the image forensic efficiency is further improved. According to the method, the problem that the tampered images cannot be correctly detected due to cloning and tampering behaviors of large-scale zooming is solved; and through normalized image block brightness values, the detection result of cloned images with different brightness values is further improved.
Owner:FOSHAN UNIVERSITY

Method for realizing evidence collection and analysis of electronic data in evidence collection software based on custom scripts

The invention relates to a method for realizing the evidence collection and the analysis of electronic data in evidence collection software based on custom scripts. The method comprises the following steps: compiling the custom scripts by the evidence collection software, and obtaining an evidence collection and analysis object; normalizing the collected electronic data by the evidence collection software according to the compiled custom scripts, and obtaining a corresponding electronic data tree; performing the correlation analysis between the evidence collection and analysis object and the electronic data tree by the evidence collection software, and obtaining the evidence collection and analysis result. Through the adoption of the method for realizing the evidence collection and the analysis of the electronic data in the evidence collection software based on the custom script, the binding between the evidence collection and analysis logic and the evidence collection and analysis software is relieved through the custom script, the software frame of the evidence collection software is relatively open, the evidence collection software cannot be limited by application software during the operation, different custom scripts can be uploaded aiming to different kinds of software, the evidence collection method is flexible and changeable, the evidence collection efficiency is improved, the analysis process is accelerated, and the application range is wider.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Multi-line evidence obtaining method and device based on block chain, equipment and storage medium

The invention discloses a multi-line evidence obtaining method and device based on a block chain, equipment and a storage medium, and belongs to the technical field of block chains. According to the embodiment of the invention, the evidence obtaining request for the target evidence obtaining address is responded to send an evidence obtaining instruction to at least two node devices, therefore, atleast two pieces of video data obtained by recording the content displayed by the target evidence obtaining address by the at least two pieces of node equipment are obtained; the at least two pieces of video data are stored in a local database of the current node equipment, the key information of the at least two pieces of video data is stored in a block chain; the node equipment in the blockchainsystem automatically records the video data and stores the key information to the blockchain, and a multi-line evidence obtaining mode is adopted instead of a client to obtain evidences, so that thelabor cost is reduced, the obtained evidence obtaining data cannot be tampered, the authenticity of the evidence obtaining data can be ensured, and the evidence obtaining efficiency is also improved.
Owner:TENCENT TECH (SHENZHEN) CO LTD

Certificate self-help distribution device and self-help certificate collection method

The invention provides a certificate self-help distribution device. The certificate self-help distribution device comprises at least a control host as well as a certificate slot metal plate storage device, a certificate discharging device, a mechanical arm transfer device, a liquid crystal display module, a receipt printer, an identity card identification module, a photographing module which is used for photographing a certificate collector, a fingerprint identification module, a touch signature module and an RFID reading and writing module which is used for writing the information of a certificate into an RFID tag on the corresponding certificate, wherein the certificate slot metal plate storage device, the certificate discharging device, the mechanical arm transfer device, the liquid crystal display module, the receipt printer, the identity card identification module, the photographing module, the fingerprint identification module, the touch signature module and the RFID reading and writing module are in circuit connection with the control host. The certificate collector selects ''collect a certificate oneself '' or ''collect a certificate on behalf of others''; and the certificate collector can complete certificate collection through a process of identity card identification, certificate collector face photographing, fingerprint identification, signing, certificate discharging of a certificate outlet and receipt printing. According to the certificate self-help distribution device, the certificate is read and identified through the RFID tag, so that the certificate self-help distribution device can be applied to different types of certificates. With the certificate self-help distribution device adopted, the technique gap of self-help distribution of paper multi-page certificates in China can be filled.
Owner:武汉天恒信息技术有限公司

Car insurance claim evidence information collection method and device

The invention provides a car insurance claim evidence information collection device which comprises a radio frequency identification module, a camera forensic module, a location positioning module, a display module and a communication module. The radio frequency identification module, the camera forensic module, the location positioning module, the display module and the communication module communicate with a system control module and receive an instruction issued by the system control module. The radio frequency identification module is used to accurately read encrypted vehicle registration information stored in a vehicle electronic identifier on a vehicle. The camera forensic module is used to photograph pictures when car insurance claim evidence information is collected, and carry out image identification on the photographed vehicle pictures to identify a vehicle license plate number from the vehicle pictures. The location positioning module is used to record location latitude and longitude information and forensic time information when photographing is carried out. The communication module is used to automatically send the acquired car insurance claim evidence information to an insurance company or a traffic police department. The system control module is used to control the operation of the modules, record relevant information and display relevant results on the display module. According to the invention, the problems of malicious fraud and the like are solved.
Owner:TRAFFIC MANAGEMENT RES INST OF THE MIN OF PUBLIC SECURITY

Blockchain-based offline process evidence obtaining and storing method

The invention relates to the technical field of blockchain evidence storage, in particular to a blockchain-based offline process evidence obtaining and storing method. The method comprises the following steps that: a server sends an offline evidence obtaining console installation package to a user; a virtual machine operation desktop is constructed for the user to operate, a mouse and keyboard operation process of the user is recorded, a user operation process file is formed and uploaded to the server; the user operation process file is called to construct a virtual machine, the user operation process is restored, and virtual machine desktop images are stored at a certain frequency; the stored desktop images are stored according to a time sequence to form a video, and the video is associated with timestamps so as to be adopted as evidence obtaining data; a preservation certificate is generated, and a compressed data packet is formed; and the compressed data packet is signed and storedand is subjected to digital fingerprint extraction, so that evidence storage data can be formed, the evidence storage data is broadcasted to a block chain network, and anchored to a public block chain. With the method adopted, the concurrent pressure of the server is reduced, the efficiency of the process evidence obtaining of the server is improved, and the process evidence obtaining is more convenient.
Owner:浙江数秦科技有限公司

Evidence obtaining method and system based on image recognition, computer equipment and storage medium

The invention discloses an evidence obtaining method and system based on image recognition, computer equipment and a storage medium. The evidence obtaining method comprises the steps that an image collection terminal judges whether a collected latest image is similar to a corresponding historical image or not according to a preset similarity judgment model, so as to obtain a similarity judgment result; if the similarity judgment result is negative, the latest image and the historical image are sent to the user terminal as target image information; a user terminal receives the target image information, and classifies the target image information according to a preset classification model to obtain type information; and an evidence file corresponding to the target image information is generated according to a preset evidence file generation rule and the type information. Based on the similarity matching technology, the evidence obtaining method can quickly and efficiently analyze massivehigh-definition images, can generate corresponding evidence obtaining materials based on the collected high-definition images, and can greatly improve the evidence obtaining efficiency based on the massive high-definition images.
Owner:ONE CONNECT SMART TECH CO LTD SHENZHEN

Text-oriented digital forensic analysis method and device and computer readable medium

An embodiment of the invention provides a text-oriented digital forensic analysis method and a device and a computer readable medium. The method comprises the following steps of: preprocessing the text content of the text to be taken as evidence to obtain a plurality of main words; generating an LDA model based on the trained document theme to obtain feature words in the main words, obtaining a plurality of feature words, and determining feature word vectors based on a plurality of feature words; calculating a semantic similarity between the feature word vector and the preset sensitive word vector, and obtaining a semantic similarity maximum vector based on the semantic similarity; and determining whether the text to be taken as evidence is a forensic target based on the semantic similarity maximum vector. According to the text-oriented digital forensic analysis method and the device and the computer readable medium, the technical problems in the prior art of inefficiency and labor wastage is solved, which are caused by only manually browsing the text content to determine whether the text to be taken as evidence is a forensic target when taking evidence of the text content of the text to be taken as evidence , , thereby realizing the technical effect of saving labor costs and improving the forensic efficiency of the text content.
Owner:BEIJING UNIV OF TECH

Method for obtaining remote data based on remote control system

The invention provides a method for obtaining remote data based on a remote control system. The remote control system comprises a client side, a server side, a remote control program module, a network carrier, a remote implantation program module and a remote configuration program module. The remote control program module is used for remotely controlling the server side, the remote implantation program module is used for sneaking into the server side and obtaining the operation authority of the server side, the remote configuration program module is used for setting parameters of the remote control program, and the parameters comprise the port number of the remote control program module, triggering conditions and a remote control software name. According to the method for obtaining the remote data based on the remote control system, the effect of concealing oneself is achieved by using an virtual IP, the concealing effect is improved through the technologies such as connection bounce, port reuse and course injection, and the evidence obtaining efficiency of the public security organization is effectively improved. Meanwhile, data stored in the server side are automatically deleted after the data are obtained, only needed content is collected, and the harm range is small.
Owner:LINEWELL SOFTWARE

Method and system for recovering deleted privacy data

The invention provides a method for recovering deleted privacy data. The method comprises the steps of monitoring the deletion operation of a user and determining whether the deletion operation belongs to a restricted deletion operation in a data recovery on mode, if so, performing next step, otherwise, monitoring the deletion operation of the user, obtaining a restricted deletion operation object of the restricted deletion operation, performing a first pre-processing manner on the restricted deletion operation object to obtain a unique deletion index value of the restricted deletion operation object, determining whether the restricted deletion operation object needs to perform crushing deletion according to the requirements of a user, and if so, thoroughly grinding the restricted deletion operation object and continuing monitoring, otherwise, performing a second pre-processing manner on the restricted deletion operation object to recover the restricted deletion operation object to a corresponding original position. According to the method, the privacy data of the user are reconstructed, the analysis difficulty of the data is reduced, the evidence efficiency is effectively improved and smooth completion of the evidence collection work is guaranteed.
Owner:SHANGHAI TAIYU INFORMATION TECH

Device and method for showing potential trace by means of far infrared rays

ActiveCN104013409AWill not harmImprove the quality of forensicsPerson identificationFiberPerspiration
The invention discloses a device and method for showing a potential trace by means of far infrared rays to solve the problem that the potential trace on paper is hard to extract. The device comprises a main table, a far infrared treatment table, a laser power supply and pump and an evidence obtaining device, wherein an oblique table used for installation of the evidence obtaining device is arranged on the main table, the far infrared treatment table is arranged in the main table and used for conducting far infrared treatment on an object to be detected, perspiration matter permeating through the paper is crystallized into a trace in the small crystal particle mode from fiber intervals after the object to be detected is treated with far infrared rays, laser emitted by the laser power supply and pump irradiates the object to be detected treated with far infrared rays to enable the trace formed in the crystallized mode on the object to be detected to emit fluorescent light so that the potential trace can be shown, and the evidence obtaining device is used for taking a photo of the shown trace to extract the trace. According to the device and method, perspiration matter permeating through the paper can be shown in the small crystal particle mode from fiber intervals on the premise that the integrity of the permeable paper is kept, fluorescent light is emitted under the excitation of laser with a specific spectrum, the potential trace is shown on the paper without damage caused, and evidence obtaining quality is improved.
Owner:SHANGHAI CRIMINAL SCI TECH RES INST +1

Cloud data online evidence obtaining system and method

The invention discloses a cloud data online evidence obtaining system and method. According to the scheme, the system is composed of a cloud evidence obtaining analysis system, an evidence storage data cloud, an evidence calling interface and an evidence storage interface in a matched mode. The cloud forensic analysis system is used for acquiring a dynamic evidence obtaining analysis demand and calling cloud data required by evidence obtaining analysis from a corresponding cloud service provider through the evidence calling interface according to the evidence obtaining analysis demand; the evidence storage data cloud receives and stores the cloud data returned by the cloud service provider through the evidence storage interface; and the cloud evidence obtaining analysis system obtains thecloud data returned by the cloud service provider from the evidence storage data cloud and carries out evidence obtaining analysis on the cloud data to form data evidence. According to the scheme, byconstructing the cloud platform capable of carrying out online evidence obtaining, whole-course online evidence obtaining of the cloud data is achieved, the difficulty of cloud data evidence obtainingis greatly reduced, and the problems that data fixing is difficult, evidence extraction is difficult and event reappearing is difficult in the whole conventional cloud evidence obtaining process areeffectively solved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Real-time evidence obtaining method and device for Android application and electronic device

The embodiment of the invention provides a real-time evidence obtaining method for an Android application. The method comprises the steps of obtaining the to-be-obtained evidence information during acurrent application, wherein the to-be-obtained evidence information comprises the to-be-obtained evidence object types and the to-be-obtained evidence content; identifying a target application according to the to-be-obtained evidence object types, constructing an evidence obtaining rule based on the to-be-obtained evidence object types and the to-be-obtained evidence content, retrieving the target application, receiving the retrieval information in real time, matching the retrieval information with the evidence obtaining rule, and obtaining the evidence if matching succeeds. The current application has the to-be-obtained evidence information, so that the target application can be determined directly according to the to-be-obtained evidence object types in the to-be-obtained evidence information, the pertinence is high, not only the retrieval information retrieved from the target application is received, but also the extraction of the to-be-obtained evidence information is completed. The verification of the to-be-obtained evidence information is completed by matching the retrieval information with the evidence obtaining rule, so that the evidence obtaining efficiency is improved. In addition, the online real-time evidence obtaining enables the service processing capacity of a system to be improved.
Owner:SHANGHAI QIYUE INFORMATION TECH CO LTD

Network forensics method and device based on alarm aggregation

ActiveCN109218305AImprove forensics efficiencyShow the whole picture of the invasionTransmissionEvidence mappingNetwork forensics
The invention belongs to the technical field of network security, in particular to a network forensics method and a network forensics device based on alarm aggregation. And the intrusion detection data of the key nodes of the network are obtained, and the intrusion detection data are used as the alarm evidence set of the forensic analysis of the network; The alarm evidence in the alarm evidence set is mapped to the attack graph, and the alarm evidence chain is obtained. Clustering the alarm evidence chain to construct the network intrusion scene and recover the network crime scene. The invention aims at the problems of missing report and false report existing in the network forensics by using the intrusion detection system, and can accurately and completely display the intrusion panorama of the attacker and improve the network forensics efficiency through the alarm evidence mapping, the evidence chain generation, the evidence chain clustering and the intrusion scene construction. Alarmdata related to intrusion scenes become important electronic evidence, which has strong practicability and operability, and provides reliable basis for collecting network data evidence, returning tothe crime scene and litigation cases.
Owner:PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU

A Blockchain-based Offline Process Evidence Collection and Evidence Storage Method

The present invention relates to the technical field of blockchain evidence storage, in particular to a blockchain-based offline process evidence collection and evidence storage method, comprising the following steps: the server sends the offline evidence collection console installation package to the user; constructs a virtual machine operation desktop for User operation, record the user's mouse and keyboard operation process, form a user operation process file and upload it to the server; call the user operation process file, build a virtual machine, restore the user operation process, save the virtual machine desktop image at a certain frequency; save the saved desktop The images are stored in chronological order to form a video, and the associated time stamp is used as evidence collection data; a security certificate is generated to form a compressed data package; the compressed data package is signed, stored and extracted to form a deposit certificate data, and the deposit certificate data is broadcast to the blockchain network and anchor to the public blockchain. The substantive effects of the invention are: reducing the concurrency pressure of the server, improving the process evidence collection efficiency of the server, and making the process evidence collection more convenient.
Owner:浙江数秦科技有限公司

Flexible soft physical evidence shooting device and shooting method thereof

The invention discloses a flexible soft physical evidence shooting device and a shooting method thereof, and relates to the physical evidence obtaining technology. The problem of the prior art of inconvenient evidence obtaining can be solved. The flexible soft physical evidence shooting device comprises a flattening device used for flattening a soft physical evidence; a light source device used for the development illumination of the flattened flexible soft physical evidence; and a physical evidence camera used for imaging evidence obtaining of the developed physical evidence. The flattening device comprises a bottom support; a fixing support fixedly disposed on the bottom support; a flattening support, which is disposed on the fixing support, and can be used for rotating and positioning. The flattening support is formed by detachably superposing a plurality of hollow wide edge square frames having different sizes by adopting the magnetic attraction, and a plurality of flattening frames can be formed. The flexible soft physical evidence can be disposed on the corresponding flattening frame according to the size, and the frames, which are smaller than the flexible soft physical evidence can be detached, and the periphery of the flexible soft physical evidence can be disposed between the frame magnetic stone and the inner frame magnetic strip of the flattening support in a clamped manner, and the physical evidence can be flattened by adopting the magnetic force. The form of the flattened flexible object can be fully displayed, and the evidence obtaining efficiency can be improved.
Owner:SHANGHAI CRIMINAL SCI TECH RES INST +1

Blockchain-based multi-line evidence collection method, device, equipment and storage medium

The invention discloses a multi-line evidence obtaining method and device based on a block chain, equipment and a storage medium, and belongs to the technical field of block chains. According to the embodiment of the invention, the evidence obtaining request for the target evidence obtaining address is responded to send an evidence obtaining instruction to at least two node devices, therefore, atleast two pieces of video data obtained by recording the content displayed by the target evidence obtaining address by the at least two pieces of node equipment are obtained; the at least two pieces of video data are stored in a local database of the current node equipment, the key information of the at least two pieces of video data is stored in a block chain; the node equipment in the blockchainsystem automatically records the video data and stores the key information to the blockchain, and a multi-line evidence obtaining mode is adopted instead of a client to obtain evidences, so that thelabor cost is reduced, the obtained evidence obtaining data cannot be tampered, the authenticity of the evidence obtaining data can be ensured, and the evidence obtaining efficiency is also improved.
Owner:TENCENT TECH (SHENZHEN) CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products