A method and apparatus for remote forensic of a server

By generating access requests and login credentials on the client side, connecting to the server and writing them into the management plugin, and parsing resource files, the problem of not being able to obtain complete server file data in existing technologies is solved, thus achieving efficient remote forensics.

CN116405479BActive Publication Date: 2026-08-04QIAN PANGU (SHANGHAI) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
QIAN PANGU (SHANGHAI) INFORMATION TECH CO LTD
Filing Date
2023-03-01
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In existing technologies, remote forensics methods using servers cannot obtain complete file data, resulting in low forensics efficiency.

Method used

The client loads the server management software, generates an access request and obtains the key file, generates login credentials to connect to the server with root user privileges, writes the management plugin and parses the resource file to obtain complete server file data.

Benefits of technology

It enables complete remote forensics of the server, improving forensics efficiency and the integrity of data acquisition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405479B_ABST
    Figure CN116405479B_ABST
Patent Text Reader

Abstract

The application provides a method and device for remotely forensicing a server, for a client loaded with server management software, the method comprising: sending an access request to the server, the access request being used to request a key file of the server, the access request being generated based on preset data in the server management software; generating login credentials based on the key file returned by the server; connecting the server with root user authority through the login credentials and writing a management plug-in to the server, the management plug-in generating corresponding file data by analyzing resource files in the server; and obtaining the file data generated by the management plug-in to forensice the server. The method for remotely forensicing a server provided by the application can obtain complete server file data through two connections with the server in succession, and realizes remote forensicing of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method and apparatus for remote forensics of servers. Background Technology

[0002] Remote server forensics refers to the process of obtaining and storing evidence from data on a server remotely. Various types of file data can be used for remote server forensics, such as system logs, system audit records, network monitoring traffic, emails, system error records, and operating system files.

[0003] In existing technologies, remote forensics on servers typically involves using the server file download function of existing server management systems. This function only supports downloading a portion of the server's files and does not support creating a complete disk image, thus failing to obtain complete file data.

[0004] How to obtain complete remote evidence from the server is a technical problem that needs to be solved. Summary of the Invention

[0005] This invention provides a method and apparatus for remote forensics of servers, which solves the problem of low efficiency in obtaining complete remote forensics of servers in the prior art.

[0006] This invention provides a method for remote forensics against a server, used on a client-side device, the client having server management software loaded, the method comprising:

[0007] Send an access request to the server, the access request being used to request the server's key file, the access request being generated based on preset data in the server management software;

[0008] Login credentials are generated based on the key file returned by the server;

[0009] The login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server. The management plugin generates corresponding file data by parsing the resource files in the server.

[0010] The file data generated by the management plugin is obtained to conduct forensic analysis on the server.

[0011] According to the present invention, a method for remotely obtaining evidence from a server is provided, wherein the preset data is token data;

[0012] Before sending an access request to the server, the method further includes:

[0013] The login information is used to simulate logging into the server management software and obtain the token data; wherein, the login information is entered on the login interface of the server management software;

[0014] The access request is generated based on the token data.

[0015] According to the present invention, a method for remotely obtaining evidence from a server, which simulates logging into the server management software based on login information and obtains the token data, includes:

[0016] The login information is encrypted, and a user identity file conforming to the network protocol is constructed based on the encrypted login information and known parameters.

[0017] A network request is generated based on the user identity file, and the network request is used to simulate logging into the server management software to obtain the token data.

[0018] According to a method for remote forensics against a server provided by the present invention, the access request is generated based on the token data, comprising:

[0019] Update the network protocol using the interface address provided by the server management software;

[0020] The access request is generated based on the updated network protocol and the token data.

[0021] According to the present invention, a method for remotely obtaining evidence from a server is provided, which involves connecting to the server with root user privileges using the login credentials and writing a management plugin to the server, including:

[0022] Connect to the server using the login credentials and obtain root user privileges on the server;

[0023] The management plugin is sent to the server to run the management plugin with root user privileges.

[0024] According to a method for remote forensics against a server provided by the present invention, after obtaining the file data generated by the management plugin, the method further includes:

[0025] The file data is displayed on the client's interface.

[0026] The present invention also provides a device for remotely collecting evidence from a server, which is installed on a client side. The client side has server management software loaded on it. The device includes:

[0027] The sending module is used to send an access request to the server. The access request is used to request the server's key file and is generated based on preset data in the server management software.

[0028] The generation module is used to generate login credentials based on the key file returned by the server;

[0029] The writing module is used to connect to the server with root user privileges using the login credentials and write a management plugin to the server. The management plugin generates corresponding file data by parsing resource files in the server.

[0030] The receiving module is used to acquire file data generated by the management plugin in order to conduct forensic analysis on the server.

[0031] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method for remote forensics against a server as described in any of the above embodiments.

[0032] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for remote forensics of a server as described above.

[0033] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method for remotely obtaining evidence from a server as described above.

[0034] The method and apparatus for remote forensics against a server provided by this invention generate an access request based on preset data in the server management software and send it to the server. Login credentials are generated based on the key file returned by the server. Then, the login credentials are used to reconnect to the server, thereby writing a management plugin to the server and receiving file data generated by parsing resource files in the server through the management plugin. In this way, complete server file data can be obtained through two consecutive connections to the server, thus realizing remote forensics against the server. Attached Figure Description

[0035] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0036] Figure 1 This is one of the flowcharts illustrating the method for remotely collecting evidence from a server provided by the present invention;

[0037] Figure 2This is the second flowchart illustrating the method for remotely collecting evidence from a server provided by the present invention.

[0038] Figure 3 This is the third flowchart of the method for remotely collecting evidence from a server provided by the present invention;

[0039] Figure 4 This is the fourth flowchart of the method for remotely collecting evidence from a server provided by the present invention;

[0040] Figure 5 This is the fifth flowchart illustrating the method for remotely collecting evidence from a server provided by the present invention;

[0041] Figure 6 This is a complete flowchart of the method for remotely collecting evidence from a server provided by the present invention;

[0042] Figure 7 This is a schematic diagram of the device for remotely collecting evidence from a server provided by the present invention;

[0043] Figure 8 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0045] The following is combined with Figures 1-8 This invention describes a method and apparatus for remote forensics against a server.

[0046] Figure 1 This is a flowchart illustrating the method for remote forensics against a server provided by the present invention, as shown below. Figure 1 As shown, the method for remote forensics against a server provided by this invention is used on a client, the client having server management software loaded, and the method includes:

[0047] Step 100: Send an access request to the server. The access request is used to request the server's key file. The access request is generated based on preset data in the server management software.

[0048] It should be noted that the client has server management software installed; in this embodiment, the BT Panel is used as an example. When a user logs into the relevant software via an HTTPS request and user authentication information, if authentication is successful, a user identity file (cookie) is generated, and the cookie is always stored on the client.

[0049] Specifically, the user enters login information through the BT Panel's login interface. BT Panel encrypts this information, for example, using the MD5 algorithm. The encrypted password is then further encrypted by string concatenation. Combined with other known parameters, a cookie for the user is generated and stored on the client side. Based on this cookie, an HTTPS request is constructed and sent to simulate logging into BT Panel. It should be noted that the HTTPS protocol carries the API interface address. After a successful simulated login, the HTTPS protocol is reconstructed using BT Panel's API interface address, and a request is sent to the server to obtain the server's key file. This key file is then returned to the client's BT Panel.

[0050] Step 200: Generate login credentials based on the key file returned by the server.

[0051] Specifically, the server management software analyzes the key file and converts it into valid login credentials, facilitating subsequent connections to the server.

[0052] It should be noted that login credentials are required for remote access to the server. These credentials can be a username and password or a key file. In this embodiment, the key file can be analyzed and converted into a login credential file, such as an RSA format login credential file, to facilitate quick connection to the server later.

[0053] Step 300: Connect to the server with root user privileges using the login credentials, and write a management plugin to the server. The management plugin generates corresponding file data by parsing the resource files in the server.

[0054] Specifically, based on this login credential, the client connects to the server as a root user through the server management software. After successfully accessing the server, the client then writes the management plugin of the server management software to the server.

[0055] Step 400: Obtain the file data generated by the management plugin to perform forensic analysis on the server.

[0056] It should be noted that most server management software's official file download function cannot capture all file data. This embodiment, in order to achieve remote forensics and obtain complete resource files, uses a written management plugin to parse the server's file system, which contains all resource files on the server.

[0057] Specifically, the management plugin parses the server's resource files, generates file data, and sends it to the client. The client then displays the complete file data on the interface through the server management software, completing the remote evidence collection process.

[0058] The above describes the steps of the method for remotely obtaining evidence from a server provided by this invention. As can be seen from the above description, the method for remotely obtaining evidence from a server according to this invention generates an access request based on preset data in the server management software and sends it to the server. Login credentials are generated based on the key file returned by the server. Then, the login credentials are used to reconnect to the server, allowing the writing of a management plugin to the server and the receiving of file data generated by parsing resource files on the server through the management plugin. Through these two connections to the server, complete server file data can be obtained, thus achieving remote evidence collection from the server.

[0059] Based on the above embodiments, in this embodiment, the preset data is token data. Figure 2 This is the second flowchart illustrating the method for remote forensics against a server provided by this invention, as shown below. Figure 2 As shown, before sending an access request to the server, the method further includes:

[0060] Step 210: Simulate logging into the server management software based on the login information and obtain the token data; wherein, the login information is entered on the login interface of the server management software.

[0061] Step 220: Generate the access request based on the token data.

[0062] It's important to note that the token is a string generated by the server to serve as a pass for client requests. The server generates a token upon the user's first login and returns it to the client. Subsequent login attempts only require this token; the user can then use the same username and password without needing to re-enter the client.

[0063] However, in step 210 of this embodiment, the client does not need to actually access the server. Instead, it logs into the server management software by simulating login and obtains token data after successful login. Based on this token data, an access request is generated.

[0064] The method for remotely obtaining evidence from a server provided in this embodiment can ensure a rapid connection to the server by sending a request to the server based on token data.

[0065] Based on the above embodiments, Figure 3This is the third flowchart illustrating the method for remote forensics against a server provided by this invention, as shown below. Figure 3 As shown, step 210, which involves simulating login to the server management software based on login information to obtain the token data, includes:

[0066] Step 310: Encrypt the login information, and construct a user identity file that conforms to the network protocol based on the encrypted login information and known parameters;

[0067] Step 320: Generate a network request based on the user identity file, simulate logging into the server management software through the network request, and obtain the token data.

[0068] Specifically, as mentioned in the above embodiments, the user enters login information through the login interface of the server management software. The server management software encrypts this information, for example, using the MD5 algorithm. The encrypted password is then further encrypted by string concatenation. Combined with other known parameters, a user identity file conforming to the network protocol is generated and saved on the client. Based on this user identity file, a network request is generated to simulate logging into the server management software. After successful simulated login, token data is obtained and returned to the client.

[0069] The method for remotely obtaining evidence from a server provided in this embodiment simulates logging into the server management software based on login information to obtain token data, which can ensure a rapid connection with the server in the future.

[0070] Based on the above embodiments, Figure 4 This is the fourth flowchart illustrating the method for remote forensics against a server provided by this invention, as follows: Figure 4 As shown, step 220, which generates the access request based on the token data, includes:

[0071] Step 410: Update the network protocol using the interface address provided by the server management software.

[0072] Step 420: Generate the access request based on the updated network protocol and the token data.

[0073] It should be noted that in this embodiment, a form needs to be sent to the server. For example, the form can be packaged and sent to the server via a POST request.

[0074] Specifically, as mentioned in the above embodiments, after successfully simulating login to the server management software, the network protocol used during the initial connection to the server can be updated via the API interface address provided by the server management software. Based on the updated network protocol and the obtained token data, an access request can be generated and sent to the server; this access request can be a POST request. Based on this, the server's key file can be obtained.

[0075] The method for remotely obtaining evidence from a server provided in this embodiment updates the network protocol and sends an access request to the server, thereby achieving two consecutive connections with the server and ensuring that complete server file data is obtained.

[0076] Based on the above embodiments, Figure 5 This is the fifth flowchart illustrating the method for remote forensics against a server provided by this invention, as shown below. Figure 5 As shown, in step 300, the login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server, including:

[0077] Step 510: Connect to the server using the login credentials and obtain root user privileges on the server.

[0078] It's important to note that root user privileges are a type of system privilege. Generally, obtaining root privileges means having the highest level of access to the server, allowing for easy reading and modification of files.

[0079] Step 520: Send the management plugin to the server to run the management plugin based on root user privileges.

[0080] Specifically, in this embodiment, the management plugin can be an Agent program used to parse the file system and obtain complete resource files from the server.

[0081] Resource files can include various types, such as system logs, system audit records, network monitoring traffic, emails, and operating system files.

[0082] The method for remotely obtaining evidence from a server provided in this embodiment generates a request based on the received login information and sends it to the server. It generates login credentials based on the key file returned by the server and then reconnects to the server with root user privileges using the login credentials. This allows the writing of a management plugin to the server, enabling two consecutive connections to the server, thereby obtaining complete server file data.

[0083] Based on the above embodiments, in this embodiment, after obtaining the file data generated by the management plugin, the method further includes:

[0084] The file data is displayed on the client's interface.

[0085] Specifically, after the server parses all resource files based on the management plugin, it generates corresponding file data and returns it to the client. The file data is then displayed through the interface of the server management software for the user to view.

[0086] The method for remotely obtaining evidence from a server provided in this embodiment can ensure complete remote server evidence collection by obtaining complete server file data and displaying it on the client page.

[0087] The complete process of remote forensics against a server provided in the embodiments of the present invention is described below.

[0088] Figure 6 This is a complete flowchart of the method for remote forensics of a server provided by the present invention, as follows: Figure 6 As shown, the method for remote forensics against a server provided by this invention is used on a client side to achieve two connections with the server, ensuring the acquisition of complete server file data and realizing remote forensics against the server. The specific steps are as follows:

[0089] Step S1: The user enters login information in the UI interface of the server management software, and the client receives the login information entered by the user.

[0090] Step S2: The client uses relevant algorithms to encrypt the login information, and then performs string concatenation on the encrypted password for further encryption. Based on the encrypted login information and known parameters, a user identity file is generated.

[0091] Step S3: Simulate login to the server management software based on the user identity file and obtain token data.

[0092] Step S4: Based on the token data, the client generates an access request and sends it to the server through the API interface address carried in the HTTPS protocol of the server management software to obtain the server's key file.

[0093] Step S5: The server returns the key file to the client.

[0094] Step S6: The client generates login credentials based on the key file, which are used to reconnect to the server.

[0095] Step S7: The client reconnects to the server based on the login credentials and writes the management plugin.

[0096] Step S8: Use the management plugin to parse all resource files on the server and generate the corresponding file data.

[0097] Step S9: The client receives file data generated by the server based on the management plugin.

[0098] Step S10: The client displays the complete file data through the server management software, completing the remote evidence collection process.

[0099] The method for remotely obtaining evidence from a server provided by this invention generates an access request based on preset data in the server management software and sends it to the server. Login credentials are generated based on the key file returned by the server. Then, the login credentials are used to reconnect to the server, thereby writing a management plugin to the server and receiving file data generated by parsing resource files in the server through the management plugin. In this way, complete server file data can be obtained through two consecutive connections to the server, thus realizing remote evidence collection from the server.

[0100] The apparatus for remotely collecting evidence from a server provided by the present invention will be described below. The apparatus for remotely collecting evidence from a server described below can be referred to in correspondence with the method for remotely collecting evidence from a server described above.

[0101] Figure 7 This is a schematic diagram of the device for remote forensics against a server provided by the present invention, as shown below. Figure 7 As shown, the device for remotely collecting evidence from a server provided by the present invention is installed on a client side, the client side having server management software loaded, and the device includes:

[0102] The sending module 701 is used to send an access request to the server. The access request is used to request the key file of the server. The access request is generated based on preset data in the server management software.

[0103] The generation module 702 is used to generate login credentials based on the key file returned by the server;

[0104] The writing module 703 is used to connect to the server with root user privileges through the login credentials and write a management plugin to the server. The management plugin generates corresponding file data by parsing resource files in the server.

[0105] The receiving module 704 is used to obtain file data generated by the management plugin in order to perform forensics on the server.

[0106] The device for remotely obtaining evidence from a server provided by this invention generates an access request based on preset data in the server management software and sends it to the server. It generates login credentials based on the key file returned by the server and then connects to the server again with the login credentials. This allows the device to write a management plugin to the server and receive file data generated by parsing resource files on the server through the management plugin. By connecting to the server twice, the device can obtain complete server file data and achieve remote evidence collection from the server.

[0107] Based on the above embodiments, in this embodiment, the preset data is token data. This embodiment of the invention provides a device for remotely obtaining evidence from a server, the device further comprising:

[0108] The request generation module is used to simulate logging into the server management software based on login information and obtain the token data before sending an access request to the server; wherein the login information is entered on the login interface of the server management software;

[0109] The access request is generated based on the token data.

[0110] Based on the above embodiments, this embodiment of the invention provides an apparatus for remotely collecting evidence from a server, wherein the request generation module is further configured to:

[0111] The login information is encrypted, and a user identity file conforming to the network protocol is constructed based on the encrypted login information and known parameters.

[0112] A network request is generated based on the user identity file, and the network request is used to simulate logging into the server management software to obtain the token data.

[0113] Based on the above embodiments, this embodiment of the invention provides an apparatus for remotely collecting evidence from a server, wherein the request generation module is further configured to:

[0114] Update the network protocol using the interface address provided by the server management software;

[0115] The access request is generated based on the updated network protocol and the token data.

[0116] Based on the above embodiments, this embodiment of the invention provides an apparatus for remotely collecting evidence from a server, wherein the writing module 703 is further configured to:

[0117] Connect to the server using the login credentials and obtain root user privileges on the server;

[0118] The management plugin is sent to the server to run the management plugin with root user privileges.

[0119] Based on the above embodiments, this embodiment of the invention provides an apparatus for remotely collecting evidence from a server, the apparatus further comprising:

[0120] The display module is used to display the file data generated by the management plugin on the client's interface after obtaining the file data.

[0121] Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8 As shown, the electronic device may include: a processor 810, a communications interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communications interface 820, and the memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions in the memory 830 to execute a method for remotely obtaining evidence from a server. This method is used on a client, which has server management software loaded. The method includes:

[0122] Send an access request to the server, the access request being used to request the server's key file, the access request being generated based on preset data in the server management software;

[0123] Login credentials are generated based on the key file returned by the server;

[0124] The login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server. The management plugin generates corresponding file data by parsing the resource files in the server.

[0125] The file data generated by the management plugin is obtained to conduct forensic analysis on the server.

[0126] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0127] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program that can be stored on a non-transitory computer-readable storage medium, wherein when the computer program is executed by a processor, the computer is capable of executing the methods for remote forensics of a server provided by the above methods, the method being used on a client, the client having server management software loaded, the method comprising:

[0128] Send an access request to the server, the access request being used to request the server's key file, the access request being generated based on preset data in the server management software;

[0129] Login credentials are generated based on the key file returned by the server;

[0130] The login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server. The management plugin generates corresponding file data by parsing the resource files in the server.

[0131] The file data generated by the management plugin is obtained to conduct forensic analysis on the server.

[0132] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for remotely obtaining evidence from a server as provided by the methods described above. The method is used on a client, the client having server management software loaded, and the method includes:

[0133] Send an access request to the server, the access request being used to request the server's key file, the access request being generated based on preset data in the server management software;

[0134] Login credentials are generated based on the key file returned by the server;

[0135] The login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server. The management plugin generates corresponding file data by parsing the resource files in the server.

[0136] The file data generated by the management plugin is obtained to conduct forensic analysis on the server.

[0137] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0138] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method of remote forensic acquisition of a server, characterized by, For a client, the client having server management software loaded, the method includes: Send an access request to the server, the access request being used to request the server's key file, the access request being generated based on preset data in the server management software; Login credentials are generated based on the key file returned by the server; The login credentials are used to connect to the server with root user privileges, and a management plugin is written to the server. The management plugin generates corresponding file data by parsing the resource files in the server. Obtain the file data generated by the management plugin to conduct forensic analysis on the server; The preset data is token data; Before sending an access request to the server, the method further includes: The login information is used to simulate logging into the server management software and obtain the token data; wherein, the login information is entered on the login interface of the server management software; The access request is generated based on the token data.

2. The method of Claim 1, wherein, Based on the login information, simulate logging into the server management software to obtain the token data, including: The login information is encrypted, and a user identity file conforming to the network protocol is constructed based on the encrypted login information and known parameters. A network request is generated based on the user identity file, and the network request is used to simulate logging into the server management software to obtain the token data.

3. The method of claim 2, wherein, Generating the access request based on the token data includes: Update the network protocol using the interface address provided by the server management software; The access request is generated based on the updated network protocol and the token data.

4. The method of Claim 1, wherein, Connect to the server with root user privileges using the login credentials and write management plugins to the server, including: Connect to the server using the login credentials and obtain root user privileges on the server; The management plugin is sent to the server to run the management plugin with root user privileges.

5. The method of Claim 1, wherein, After obtaining the file data generated by the management plugin, the method further includes: The file data is displayed on the client's interface.

6. An apparatus for remote forensic of a server, the apparatus comprising: The device is configured on a client-side unit, which loads server management software, and includes: The sending module is used to send an access request to the server. The access request is used to request the server's key file and is generated based on preset data in the server management software. The generation module is used to generate login credentials based on the key file returned by the server; The writing module is used to connect to the server with root user privileges using the login credentials and write a management plugin to the server. The management plugin generates corresponding file data by parsing resource files in the server. A receiving module is used to acquire file data generated by the management plugin in order to conduct forensic analysis on the server. The preset data is token data, and the device further includes: The request generation module is used to simulate logging into the server management software based on login information and obtain the token data before sending an access request to the server; wherein the login information is entered on the login interface of the server management software; The access request is generated based on the token data.

7. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method for remotely obtaining evidence from a server as described in any one of claims 1 to 5.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for remotely obtaining evidence from a server as described in any one of claims 1 to 5.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for remotely obtaining evidence from a server as described in any one of claims 1 to 5.