The invention provides a private
encryption type ENC electronic file analysis evidence obtaining method and
system, relates to the technical field of computer electronic evidence obtaining, and solves the problem of case-related evidence chain breakage caused by difficulty in evidence obtaining of undisclosed private
encryption type files in the prior art. The method comprises the following steps: firstly, initializing a target
system in a hardware isolation environment, positioning and extracting a binary static feature sample, performing semantic analysis, dividing a feature function chain boundary, and establishing a binary module association index to extract a decryption module; based on Session structured dynamic taint analysis, a specific
pollution source is tracked, and variable propagation, cross check
password generation logic and
traceability password check execution flow are self-defined; and finally, through dynamic
anchor point positioning based on hardware breakpoints, reconstructing and restoring a private
encryption and decryption protocol, and outputting a matrix for evaluating and verifying the evidence obtaining feasibility of the ENC electronic file. According to the method, the evidence obtaining and analysis process does not depend on an original
software system, and complete autonomy and
controllability in technology are achieved.