Method for realizing evidence collection and analysis of electronic data in evidence collection software based on custom scripts

An electronic data and self-defined technology, applied in the direction of electronic digital data processing, special data processing applications, instruments, etc., can solve problems such as the inability to combine multiple forensics ideas, the inability to share forensics expert forensics ideas, and the inability to provide support for forensics methods, etc. , to achieve the effects of flexible forensics methods, favorable development and wide application range

Active Publication Date: 2015-02-18
THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF2 Cites 10 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] 1. The applications supported by the electronic data forensics software are limited. Once the supported application range is exceeded, it will not be able to provide forensics support
[0004] 2. Since each software is developed relatively independently, the software architecture is relatively closed, and it is difficult for users to customize and edit. It is impossible to share the forensics ideas of forensics experts, and it is also impossible to combine multiple forensics ideas.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method for realizing evidence collection and analysis of electronic data in evidence collection software based on custom scripts
  • Method for realizing evidence collection and analysis of electronic data in evidence collection software based on custom scripts
  • Method for realizing evidence collection and analysis of electronic data in evidence collection software based on custom scripts

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0033] In order to describe the technical content of the present invention more clearly, further description will be given below in conjunction with specific embodiments.

[0034] In one embodiment, as figure 2 As shown, the method for realizing electronic data forensics analysis based on a custom script in the evidence collection software of the present invention comprises the following steps:

[0035] (1) The forensic software compiles and processes the custom script, and obtains the object of forensic analysis;

[0036] (2) The forensics software performs normalization processing on the collected electronic data according to the compiled custom script, and obtains the corresponding electronic data tree;

[0037] (3) The forensic software performs correlation analysis on the forensic analysis object and the electronic data tree, and obtains a forensic analysis result.

[0038] In a preferred embodiment, the forensic software performs normalization processing on the collec...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a method for realizing the evidence collection and the analysis of electronic data in evidence collection software based on custom scripts. The method comprises the following steps: compiling the custom scripts by the evidence collection software, and obtaining an evidence collection and analysis object; normalizing the collected electronic data by the evidence collection software according to the compiled custom scripts, and obtaining a corresponding electronic data tree; performing the correlation analysis between the evidence collection and analysis object and the electronic data tree by the evidence collection software, and obtaining the evidence collection and analysis result. Through the adoption of the method for realizing the evidence collection and the analysis of the electronic data in the evidence collection software based on the custom script, the binding between the evidence collection and analysis logic and the evidence collection and analysis software is relieved through the custom script, the software frame of the evidence collection software is relatively open, the evidence collection software cannot be limited by application software during the operation, different custom scripts can be uploaded aiming to different kinds of software, the evidence collection method is flexible and changeable, the evidence collection efficiency is improved, the analysis process is accelerated, and the application range is wider.

Description

technical field [0001] The invention relates to the field of data analysis, in particular to the field of electronic data forensics and analysis, and specifically refers to a method for realizing electronic data forensics and analysis in forensics software based on a custom script. Background technique [0002] With the increasing number of computer crime cases and the digitalization of crime methods, the work of collecting electronic evidence has become the key to providing important clues and solving cases. Restoring damaged computer data and providing relevant electronic data evidence is electronic forensics. However, with the rapid development of the mobile Internet and the rapid transfer of traditional network applications to the mobile Internet, electronic data forensics will face traces of the use of more types of applications. analyze. Traditional electronic data forensics software mainly proposes forensic analysis techniques and solutions for corresponding applicat...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): G06F9/44G06F17/30
Inventor 吴松洋金波熊雄刘善军何俊峰
Owner THE THIRD RES INST OF MIN OF PUBLIC SECURITY
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products