Evidence obtaining method, device and equipment supporting multiple operating systems and storage medium

An operating system and file system technology, applied in the fields of instruments, electrical digital data processing, hardware monitoring, etc., can solve the problem of no user trace analysis and image forensics methods, no support for offline and online forensics methods, and no way to know the computer operating system. What is the problem, to achieve the effect of convenient evidence collection

CN111338889AActive Publication Date: 2020-06-26BEIJING QIANXIN TECH +1
4 Cites 2 Cited by

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
Publication Date
2020-06-26

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses an evidence obtaining method supporting multiple operating systems, and belongs to the field of computer evidence obtaining. The method comprises the following steps: running an evidence obtaining system on an evidence obtaining object according to a starting instruction; if the starting instruction is a cold starting instruction, running the offline evidence obtaining system to recognize the operating system type of the evidence obtaining object, and starting a corresponding analysis module in the offline evidence obtaining system according to the operating system type; and if the starting instruction is a direct running instruction, running the on-line evidence obtaining system to identify the operating system type of the evidence obtaining object, and starting acorresponding on-line evidence obtaining module in the on-line evidence obtaining system according to the operating system type. According to the invention, the corresponding evidence obtaining modulecan be started in a targeted manner to obtain evidences according to the type of the operating system contained in the evidence obtaining object, and evidence obtaining of three systems is supportedat the same time.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to the field of computer evidence collection, in particular to a method, device, equipment and storage medium supporting multiple operating systems. Background technique

[0002] With the increasing number of computer crime cases and the digitalization of crime methods, the work of collecting electronic evidence has become the key to providing important clues and solving cases.

[0003] At present, the online forensics methods for computers are all based on specific computer operating system types, and it is impossible to implement one method to support online and offline online forensics for computers with multiple operating systems. Therefore, in the face of on-site evidence collection, the forensics personnel need to carry various forensic tools, because it is impossible to know in advance what the computer operating system that the on-site evidence collection is facing is.

[0004] In a nutshell, the existing technology has t...

Examples

Embodiment Construction

[0050] The present invention is further illustrated below by means of examples, but the present invention is not limited to the scope of the examples.

[0051] First of all, the present invention proposes a forensic method supporting multiple operating systems, which is used to obtain evidence for operating systems through portable storage devices. The types of operating systems mentioned here mainly refer to Windows operating systems, macOS operating systems, and Linux operating systems. .

[0052] In the first embodiment, if figure 1 As shown, the described evidence collection method supporting multiple operating systems includes the following steps:

[0053] Step 01: Run the forensic collection system on the forensics object according to the startup instruction, the startup instruction includes a cold start instruction and a direct operation instruction, and the forensics system includes an offline forensics collection system and an online forensics collection system; if t...