WiFi Forensics Method, System, Storage Medium and Electronic Device
By using routers that do not connect to external networks in WiFi forensics, the problems of inaccurate and inefficient evidence in the existing technology are solved, and a more efficient and accurate WiFi forensics process is achieved.
Patent Information
- Application Number
- CN202410915501.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-09
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-07-09
AI Technical Summary
The existing WiFi evidence collection methods have problems such as inaccurate evidence collection and low evidence collection efficiency, especially because the evidence collection device is connected to an external network, causing the evidence collection device to be automatically connected to other networks, which affects the accuracy of evidence collection. The local network card transmission speed of the evidence collection device is slow and the signal is unstable, resulting in a decrease in evidence collection efficiency.
By using a dedicated router for WiFi forensics, the router does not connect to the external network, ensuring that the device to be forensics cannot automatically connect to other networks. At the same time, the router can provide high-speed and stable network services, and can release multiple WiFi hotspots at the same time, realizing parallel evidence collection for multiple WiFi tasks.
It improves the accuracy and efficiency of WiFi evidence collection, ensures the accuracy and stability of the evidence collection process, and greatly improves the evidence collection efficiency.
Smart Images

Figure CN119110429B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of data forensics, and relates to a WiFi forensics method, in particular to a WiFi forensics method, system, storage medium and electronic device. Background Art
[0002] With the popularization of wireless networks and the widespread use of mobile devices, more and more evidence exists in digital form on various devices. WiFi forensics provides a method to obtain this evidence without physical contact. WiFi forensics refers to the process of using wireless network technology to collect, analyze and save evidence by connecting to the device to be forensically investigated through WiFi. This forensics method has become increasingly important in modern information society, especially in legal investigations, network security inspections and other fields. For example, in legal investigations, WiFi forensics can be used to extract key information from devices such as suspects' mobile phones, tablets or computers, such as chat records, emails, browsing histories, files and pictures. These data can become important evidence in the case, helping law enforcement agencies to restore the truth faster and more accurately. However, existing WiFi forensics methods have problems such as inaccurate forensics and low forensics efficiency. Summary of the Invention
[0003] Embodiments of this application provide a WiFi forensics method, system, storage medium and electronic device, which are used to improve the accuracy and efficiency of WiFi forensics.
[0004] In a first aspect, embodiments of this application provide a WiFi forensics method. The WiFi forensics method includes: the router is flashed with the OpenWrt system according to the received first instruction; the router performs function settings according to the received second instruction; the forensics device generates a WiFi hotspot based on the router, and the forensics device is communicatively connected to the router in a wired manner; the device to be forensically investigated connects to the WiFi hotspot; the forensics device performs WiFi forensics through the WiFi hotspot.
[0005] In one implementation manner of the first aspect, the router being flashed with the OpenWrt system according to the received first instruction includes: the router executes the following steps according to the received first instruction: enters the recovery mode and opens the SSH connection port; flashes the original OpenWrt system and imports the OpenWrt backup package.
[0006] In one implementation manner of the first aspect, the second instruction is a uci instruction.
[0007] In one implementation manner of the first aspect, the uci instruction includes a virtual network interface creation instruction, a default gateway configuration instruction, a WiFi signal creation instruction, a firewall rule creation instruction and / or a port forwarding setting instruction.
[0008] In one implementation of the first aspect, the WiFi forensics method further includes: selecting a router mode through the forensics software interface of the forensics device to perform WiFi forensics.
[0009] In one implementation of the first aspect, the WiFi forensics method further includes: the forensics device obtains the hotspot name and password that meet the current WiFi forensics task and generates a QR code, and the device to be forensically examined connects to the WiFi hotspot by scanning the QR code.
[0010] In one implementation of the first aspect, the number of the WiFi hotspots is multiple, and the WiFi hotspots have at least two frequency bands.
[0011] In a second aspect, an embodiment of the present application provides a WiFi forensics system, which includes a router, a forensics device communicatively connected to the router in a wired manner, and a device to be forensically examined, and is used to implement the WiFi forensics method described in any one of the first aspects of the embodiments of the present application.
[0012] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the WiFi forensics method described in any one of the first aspects of the embodiments of the present application is implemented.
[0013] In a fourth aspect, an embodiment of the present application provides an electronic device, which includes: a memory storing a computer program; a processor communicatively connected to the memory, and when the computer program is called, the WiFi forensics method described in any one of the first aspects of the embodiments of the present application is executed.
[0014] As described above, the WiFi forensics method, system, storage medium, and electronic device provided by the embodiments of the present application have the following
[0015] Beneficial effects:
[0016] The WiFi forensics method releases a WiFi signal by using a dedicated router, and this router is not connected to the external network, so it can ensure that the device to be forensically examined cannot automatically connect to other networks, which is beneficial to improving the accuracy of forensics.
[0017] Compared with the technical solution of using the local network card of a forensics device such as a computer for forensics, the router can provide a faster and more stable network service, which is beneficial to improving the forensics speed and stability. In addition, the router can also release multiple WiFi hotspots at the same time to implement parallel forensics of multiple WiFi tasks, thereby greatly improving the forensics efficiency. Description of the Drawings
[0018] Figure 1 It shows a schematic diagram of an application scenario of an embodiment of the present application.
[0019] Figure 2 It shows a flowchart of the WiFi forensics method provided by an embodiment of the present application.
[0020] Figure 3 It shows a flowchart of flashing the OpenWrt system into the router in an embodiment of the present application.
[0021] Figure 4 It shows a flowchart of the WiFi forensics method provided by an embodiment of the present application.
[0022] Figure 5 It shows a schematic diagram of the structure of an electronic device provided by an embodiment of the present application.
[0023] Description of component numbers
[0024] 1 WiFi forensics system
[0025] 11 Router
[0026] 12 Forensics device
[0027] 13 Device to be forensically analyzed
[0028] 500 Electronic device
[0029] 510 Memory
[0030] 520 Processor
[0031] 530 Display
[0032] Steps S21 to S25
[0033] Steps S31 to S32
[0034] Steps S401 to S410 Detailed implementation manners
[0035] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0036] It should be noted that the illustrations provided in the following embodiments only schematically illustrate the basic concept of the present application. Therefore, only the components related to the present application are shown in the illustrations, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0037] With the popularization of wireless networks and the widespread use of mobile devices, more and more evidence exists in digital form on various devices. WiFi forensics provides a method to obtain this evidence without physical contact. WiFi forensics refers to the process of using wireless network technology to collect, analyze, and save evidence by connecting to the device to be forensically examined through WiFi. In some technical solutions, the local network card of a forensics device, such as a computer, is used for WiFi forensics. However, since the forensics device will connect to other networks when performing WiFi forensics, it causes the device to be forensically examined, such as a mobile phone, to easily connect to other networks automatically during the forensics process, resulting in inaccurate forensics. In addition, the transmission speed of the local network card of the forensics device is often slow and the signal is unstable. Using the local network card for WiFi forensics will lead to a decrease in forensics efficiency. Moreover, the above solutions cannot release multiple WiFi hotspots simultaneously, resulting in an inability to execute multiple forensics tasks in parallel during the forensics process, thus further reducing the forensics efficiency.
[0038] At least for the above problems, an embodiment of the present application provides a WiFi forensics method. The technical solutions in the embodiments of the present application will be described in detail below with reference to the accompanying drawings in the embodiments of the present application.
[0039] Figure 1 Shown is a schematic diagram of an application scenario of an embodiment of the present application. As Figure 1 shown, the WiFi forensics system 1 includes a router 11, a forensics device 12, and a device to be forensically examined 13. The router 11 is a dedicated router for WiFi forensics, which serves as a wireless access point in the WiFi forensics system 1 to create a local area network environment for the forensics device 12 and the device to be forensically examined 13. The router 11 is not connected to an external network (such as the Internet), so it can ensure that the device to be forensically examined 13 cannot automatically connect to the external network during the forensics process, which is beneficial to improving the accuracy of forensics. The forensics device 12 is a device for data collection, analysis, and storage, and it is communicatively connected to the router 11 in a wired manner. For example, the forensics device 12 can be connected to the LAN port of the router 11 using a network cable, but the present application is not limited thereto. The forensics device 12 is, for example, a personal computer, a tablet computer, etc. The device to be forensically examined 13 is connected to the forensics device 12 through a WiFi network to facilitate the forensics device 12 to perform data forensics. The device to be forensically examined 13 is, for example, an Android mobile phone, but the present application is not limited thereto.
[0040] Figure 2 Shown is a flowchart of the WiFi forensics method provided by an embodiment of this application. This WiFi forensics method can be applied to Figure 1 the WiFi forensics system 1 shown in the figure. As Figure 2 shown, the WiFi forensics method provided by an embodiment of this application includes the following steps S21 to S25.
[0041] S21, the router flashes the OpenWrt system according to the received first instruction. Specifically, the user can download the OpenWrt firmware file suitable for the router model and input the first instruction through the router's management interface to achieve the upload and flashing of the firmware. The OpenWrt system provides rich functions such as advanced firewall settings, VLAN support, traffic control, and monitoring, enabling the router to better meet complex network requirements and the customization requirements of advanced users. By flashing the OpenWrt system, users can make full use of the hardware performance of the router and achieve more flexible and powerful network management.
[0042] S22, the router performs function settings related to WiFi forensics according to the received second instruction. Specifically, the user can input the second instruction through the router's management interface to achieve the setting of related functions.
[0043] S23, the forensics device generates a WiFi hotspot based on the network service provided by the router.
[0044] S24, the device to be forensically analyzed connects to the WiFi hotspot.
[0045] S25, the forensics device performs WiFi forensics through the WiFi hotspot.
[0046] As described above, the WiFi forensics method provided by an embodiment of this application releases the WiFi signal by using a dedicated router and forensics device. The router is not connected to the external network, thus ensuring that the device to be forensically analyzed cannot automatically connect to other networks, which is beneficial to improving the accuracy of forensics. In addition, compared with the solution of using the local network card of a forensics device such as a computer for WiFi forensics, the router can provide a faster and more stable network service, which is beneficial to improving the speed and stability of forensics. In addition, the router cooperates with the forensics device to release multiple WiFi hotspots simultaneously, enabling parallel forensics of multiple WiFi tasks, thereby greatly improving the forensics efficiency.
[0047] Please refer to Figure 3 , in some implementation manners, the router flashing the OpenWrt system according to the received first instruction includes: the router receives the first instruction input by the user and, in response to this first instruction, executes the following steps S31 and S32.
[0048] S31, the router enters the recovery mode and opens the SSH connection port. In the recovery mode, the router starts a minimized system environment to ensure stability and operability. Opening the SSH connection port can provide an encrypted communication channel to ensure the security and integrity of data transmission and prevent unauthorized access.
[0049] S32, the router is flashed with the native OpenWrt system and the OpenWrt backup package is imported.
[0050] In some implementation manners, the second instruction is a uci (Unified Configuration Interface) instruction. The uci instruction is a command-line tool for configuring and managing the OpenWrt system. The uci instruction provides a simplified way to read and modify the device's configuration file, allowing users to manage system configurations such as network settings, wireless configurations, and firewall rules through a unified interface.
[0051] In some implementation manners, the function settings performed on the router according to the uci instruction include: creating a virtual network interface, configuring a default gateway, creating a WiFi signal, creating firewall rules, and / or setting port forwarding. The uci instruction includes a virtual network interface creation instruction, a default gateway configuration instruction, a WiFi signal creation instruction, a firewall rule creation instruction, and / or a port forwarding setting instruction. Specifically, a virtual network interface refers to a logical network interface created in the operating system, which does not directly correspond to physical network hardware. The virtual network interface can be used for various network configuration and management tasks, such as implementing network isolation, virtual private networks (VPNs), bridges, etc. By creating a virtual network interface, users can create multiple logical interfaces on a physical network interface, thereby improving the flexibility and management ability of network configuration. Firewall rules are used to control and manage the policies for incoming and outgoing network traffic. By creating firewall rules, it is possible to specify the types of traffic, source and destination addresses, port numbers, etc. that are allowed or denied, in order to enhance network security and protect the network from unauthorized access and attacks. Port forwarding is used to direct network traffic to a specific port of a device. By setting port forwarding, it is possible to forward traffic from a specified port to the corresponding port of the corresponding device in the network.
[0052] Exemplarily, the uci instruction is, for example:
[0053] "uci set network." + wInfo.InterfaceName + "=interface". This command is used to add a new network interface in the network configuration of OpenWrt, where <interfacename>It is the name of the interface, such as lan or wan.
[0054] "uci set network." + wInfo.InterfaceName + ".ifname=lan2". This command is used to set the physical interface name of the network interface to lan2. The physical interface name (ifname) refers to the actual network interface device, such as an Ethernet port, a wireless interface, etc.
[0055] "uci set network." + wInfo.InterfaceName + ".gateway=" + global.RouterBasicIp. This command is used to set the gateway address of the network interface to <routerbasicip>, that is, the basic IP address of the router.
[0056] "uci set network." + wInfo.InterfaceName + ".ipaddr=" + wInfo.InterfaceIp. This instruction is used to set the IP address of the network interface to <interfaceip>, This is the IP address of the interface in the local network.
[0057] "uci set network." + wInfo.InterfaceName + ".netmask=255.255.255.0". This command is used to set the subnet mask of the network interface to 255.255.255.0. The subnet mask is used to determine the network part and host part of the IP address.
[0058] "uci set network." + wInfo.InterfaceName + ".proto=static". This command is used to set the protocol type of the network interface to static, that is, static IP address configuration.
[0059] "uci set network." + wInfo.InterfaceName + ".type=bridge". This command is used to set the network interface to the bridge type, that is, a bridge.
[0060] It should be noted that only several uci commands are exemplarily listed above, but this application is not limited thereto. In specific applications, users can configure uci commands according to actual needs.
[0061] In some implementation manners, the forensics device is installed with forensics software. The WiFi forensics method provided by the embodiments of this application may further include: selecting the router mode through the forensics software interface of the forensics device for WiFi forensics.
[0062] Exemplarily, after selecting the router mode for WiFi forensics, the forensics software automatically executes the router forensics process, obtains the hotspot name and password that meet the current WiFi forensics task and generates a QR code, and waits for the forensics device to connect to the WiFi hotspot by scanning the QR code.
[0063] In some implementation manners, the process of generating the QR code may include the following steps.
[0064] Format the information of the WiFi hotspot (such as SSID, password, and encryption type) into a specific string format. Its format needs to follow the specifications of the WiFi Alliance to ensure compatibility and correct parsing. Exemplarily, the formatted WiFi information string structure may be: "WIFI:T: <encryption> ;S: <ssid> ;P: <password>;;", where T represents the encryption type, such as WPA, WEP, or nopass (no password). S represents the SSID, which is the wireless network name. P represents the password. For example, assuming the SSID of a WiFi network is "ExampleSSID" and the password is "password123", and using WPA encryption, the formatted string is: "WIFI:T:WPA;S:ExampleSSID;P:password123;;".
[0065] Generate a QR code. Exemplarily, the process of generating a QR code may include steps such as data encoding, error correction, matrix generation, and image rendering. Among them, data encoding is used to encode the formatted WiFi information string into QR code data. Error correction is used to add redundant data to support error correction, so as to improve the readability and damage resistance of the QR code. Matrix generation is used to generate a QR code matrix based on the encoded data, and this matrix is a square grid containing black and white modules. Image rendering is used to render the QR code matrix into an image format, such as PNG, JPEG, etc., for printing or display.
[0066] In some implementation manners, the forensic device performs WiFi forensics through a WiFi hotspot, including the following steps.
[0067] After the device to be forensically examined establishes a connection with the forensic device through a WiFi hotspot, the forensic device establishes an encrypted communication channel with the device to be forensically examined through a security protocol (such as TLS / SSL) to ensure that the transmitted data will not be intercepted or tampered with in the network, thereby maintaining the confidentiality and integrity of data transmission.
[0068] The forensic device scans the data of the device to be forensically examined through forensic software, and the scanning objects may include the file system, application data, log files, memory data, etc. The forensic software transmits the scanning results in real time through the WiFi network and marks and extracts key information, such as emails, text messages, call records, browser history, documents, and pictures.
[0069] The forensic software classifies and organizes the obtained data and stores the data in categories on the forensic device according to a predetermined forensic plan. In addition, this step may further include performing a hash check on the obtained data to ensure the integrity and authenticity of each file or data block and prevent the data from being tampered with during transmission.
[0070] Exemplarily, during the data collection process, the forensic device may also perform real-time analysis on the transmitted data and use technologies such as data mining and pattern recognition to detect abnormal activities or suspicious content.
[0071] Exemplarily, after data collection and analysis are completed, the forensic software can also automatically generate a detailed forensic report. The report content includes information such as data source, collection time, data type, content summary, etc.
[0072] Exemplarily, during the entire forensic process, the forensic software can record detailed operation logs, which include information such as the operation time, operation content, and operator for each step.
[0073] In some implementation manners, the number of WiFi hotspots can be multiple, and each WiFi hotspot can be set with an independent WiFi SSID and password. The WiFi hotspots have at least two frequency bands. For example, some WiFi hotspots are 2.4 GHz, and some WiFi hotspots are 5 GHz to meet the needs of different WiFi tasks. The port forwarding function can ensure normal data transmission between the forensic device and the device to be forensically analyzed.
[0074] Next, a specific example will be used to introduce the WiFi forensic method provided by the embodiments of the present application in detail. It should be noted that the content in this example is only used to explain and illustrate the WiFi forensic method provided by the embodiments of the present application, rather than to limit the protection scope of the present application in any way. In specific applications, corresponding steps can be added or deleted based on actual needs on the basis of this example. Figure 4 Shown is a flowchart of the WiFi forensic method in this example. As Figure 4 shown, the WiFi forensic method in this example includes the following steps.
[0075] S401, flash the OpenWrt system into the router.
[0076] S402, set multiple WiFi hotspots using uci commands.
[0077] S403, set firewall rules using uci commands.
[0078] S404, perform WiFi tasks.
[0079] S405, select router forensics on the forensic software interface of the forensic device.
[0080] S406, check whether the router configuration environment is normal. If yes, execute step S407; otherwise, execute step S401.
[0081] S407, set port forwarding in the router.
[0082] S408, obtain the account and password of the released WiFi hotspot.
[0083] S409, generate a QR code.
[0084] S410. Use the device to be forensically investigated to scan the QR code and conduct WiFi forensics.
[0085] It should be noted that the above labels S401 to S410 are only used to identify different steps, rather than to limit the execution order between these steps.
[0086] The protection scope of the WiFi forensics method provided by the embodiments of the present application is not limited to the execution order of the steps listed above. Any solution achieved by adding or reducing steps of the prior art or replacing steps according to the principle of the present application is included in the protection scope of the present application.
[0087] The embodiments of the present application also provide a WiFi forensics system. This WiFi forensics system can implement the WiFi forensics method described in the present application. However, the implementation devices of the WiFi forensics method described in the present application include, but are not limited to, the structure of the WiFi forensics system listed in this embodiment. Any structural deformation and replacement of the prior art made according to the principle of the present application are included in the protection scope of the present application.
[0088] The WiFi forensics system provided by the embodiments of the present application includes a router, a forensics device communicatively connected to the router in a wired manner, and a device to be forensically investigated. This WiFi forensics system is configured to perform the following steps: The router flashes the OpenWrt system according to the received first instruction; the router performs function settings according to the received second instruction; the forensics device generates a WiFi hotspot based on the router, and the forensics device is communicatively connected to the router in a wired manner; the device to be forensically investigated connects to the WiFi hotspot; the forensics device conducts WiFi forensics through the WiFi hotspot.
[0089] In several embodiments provided by the present application, it should be understood that the disclosed system, device or method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules / units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or modules or units can be in electrical, mechanical or other forms.
[0090] The modules / units described as separate components may or may not be physically separated, and the components shown as modules / units may or may not be physical modules, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules / units can be selected according to actual needs to achieve the objectives of the embodiments of the present application. For example, in the various embodiments of the present application, the functional modules / units can be integrated in one processing module, or each module / unit can exist physically alone, or two or more modules / units can be integrated in one module / unit.
[0091] Those of ordinary skill in the art should also be able to further realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0092] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the WiFi forensics method provided by the embodiments of the present application. Those of ordinary skill in the art can understand that all or part of the steps of the methods in the above embodiments can be completed by instructing a processor through a program. The program can be stored in a computer-readable storage medium, and the storage medium is a non-transitory medium, such as random access memory, read-only memory, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof. The above storage medium can be any available medium accessible by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid-state disk (SSD)).
[0093] The embodiments of the present application can also provide an electronic device. Figure 5 Shown is a schematic structural diagram of the electronic device 500 in the embodiments of the present application. As Figure 5 shown, in this embodiment, the electronic device 500 includes a memory 510 and a processor 520.
[0094] The memory 510 in the embodiments of the present application is used to store various types of data to support the operation of the electronic device 500. Examples of such data include: any executable programs for operating on the electronic device 500, such as an operating system and application programs; the operating system includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. Application programs may include various application programs, such as a MediaPlayer, a Browser, etc., for implementing various application services. Implementing the WiFi forensics method provided by the embodiments of the present application may be included in the application program.
[0095] Exemplarily, the memory 510 may include a computer system readable medium in the form of volatile memory, such as RAM and / or cache memory. The electronic device 500 may further include other removable / non-removable, volatile / non-volatile computer system storage media. The memory 510 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present application.
[0096] The processor 520 is connected to the memory 510 and is configured to execute the computer program stored in the memory 510 to enable the electronic device 500 to execute the WiFi forensics method.
[0097] Exemplarily, the processor 520 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc. In other embodiments, the processor 520 may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0098] In some implementations, the electronic device 500 provided by the embodiments of the present application may further include a display 530. The display 530 is communicatively connected to the memory 510 and the processor 520 and is configured to display a related Graphical User Interface (GUI) of the WiFi forensics method.
[0099] In the embodiments of the present application, the display 530 may include a display screen (display panel). In some implementations, the display panel may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. In addition, the display 530 may also be a touch panel (touch screen, touch display screen), and the touch panel may include a display screen and a touch-sensitive surface. When the touch-sensitive surface detects a touch operation on or near it, it is transmitted to the processor 520 to determine the type of touch event, and then the processor 520 provides a corresponding visual output on the display device according to the type of touch event.
[0100] The embodiments of the present application may also provide a computer program product, which includes one or more computer instructions. When the computer instructions are loaded and executed on a computing device, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website, a computer, or a data center to another website, a computer, or a data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.).
[0101] When the computer program product is executed by a computer, the computer executes the method described in the foregoing method embodiments. The computer program product may be a software installation package. In the case where the foregoing method needs to be used, the computer program product may be downloaded and executed on the computer.
[0102] The descriptions of the processes or structures corresponding to the foregoing respective drawings have their own focuses. For parts not detailed in a certain process or structure, reference may be made to the relevant descriptions of other processes or structures.
[0103] In summary, the embodiments of the present application provide a WiFi forensics method, system, storage medium, and electronic device. The WiFi forensics method releases a WiFi signal by using a dedicated router that is not connected to an external network, thereby ensuring that the device to be forensically investigated cannot automatically connect to other networks, which is beneficial to improving the accuracy of forensics. Compared with forensics devices such as computers, the router can provide a faster and more stable network service, which is beneficial to improving the speed and stability of forensics. In addition, the router can also release multiple WiFi hotspots simultaneously to implement parallel forensics of multiple WiFi tasks, thereby greatly improving the forensics efficiency. Therefore, the present application effectively overcomes various disadvantages in the prior art and has high industrial utilization value.
[0104] The above embodiments are only illustrative of the principles and effects of the present application, and are not intended to limit the present application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed in the present application should still be covered by the claims of the present application.< / password> < / ssid> < / encryption> < / interfaceip> < / routerbasicip> < / interfacename>
Claims
1. A WiFi evidence collection method, characterized in that: The WiFi evidence collection method includes: The router is flashed with the OpenWrt system according to the received first instruction, wherein the router is a dedicated router for WiFi forensics and is not connected to an external network; The router performs function settings according to the received second instruction, wherein the second instruction is a uci instruction, and the uci instruction includes a virtual network port creation instruction, a default gateway configuration instruction, a WiFi signal creation instruction, a firewall rule creation instruction and / or a port forwarding setting instruction; The evidence collection device generates a WiFi hotspot based on the router, and the evidence collection device is connected to the router in a wired communication manner; The device to be collected evidence is connected to the WiFi hotspot; The evidence collection device performs WiFi evidence collection via the WiFi hotspot.
2. The WiFi evidence collection method according to claim 1, characterized in that: The router flashes the OpenWrt system according to the first command received, including: The router performs the following steps according to the received first instruction: Enter recovery mode and open the SSH connection port; Flash the native OpenWrt system and import the OpenWrt backup package.
3. The WiFi evidence collection method according to claim 1, characterized in that: The WiFi evidence collection method further includes: selecting a router mode to perform WiFi evidence collection through an evidence collection software interface of the evidence collection device.
4. The WiFi evidence collection method according to claim 1, characterized in that: The WiFi evidence collection method also includes: the evidence collection device obtains the hotspot name and password that meets the current WiFi evidence collection task and generates a QR code, and the device to be collected connects to the WiFi hotspot by scanning the QR code.
5. The WiFi evidence collection method according to claim 1, characterized in that: There are multiple WiFi hotspots, and each WiFi hotspot has at least two frequency bands.
6. A WiFi evidence collection system, characterized in that: The WiFi evidence collection system includes a router, an evidence collection device connected to the router in a wired communication manner, and a device to be collected, and is used to implement the WiFi evidence collection method described in any one of claims 1 to 5.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the WiFi forensics method described in any one of claims 1 to 5 is implemented.
8. An electronic device, characterized in that: The electronic device comprises: A memory storing a computer program; A processor is communicatively connected to the memory, and executes the WiFi forensics method according to any one of claims 1 to 5 when calling the computer program.
Citation Information
Patent Citations
Portable wireless network detection evidence-obtaining system
CN104159244A
Rapid electronic forensics method and system
CN110191176A
Centralized investigation and evidence collection system for intelligent mobile equipment and investigation and evidence collection method based on centralized investigation and evidence collection system
CN115189935A