摘要
针对计算机取证中的电子证据问题,设计并实现基于关键词匹配的打印数据获取系统。通过对硬盘中假脱机文件关键词的搜索,定位打印数据所在的物理扇区并读出相关内容。性能测试显示,该系统能快速有效地获取打印内容,适用于信息保护、电子取证等环境,具有较高的实用价值。
In order to solve the problems of the electronic evidence about computer forensics. This paper designs and implements a printing data acquisition system, based on keyword matching. The physical sector of printing data can be located by searching keywords of spooling file in hard disk. Then the printing data can be acquired efflciendy. The testing results.prove that this system has a good performance and is useful in information protection and computer forensics.
出处
《计算机工程》
CAS
CSCD
北大核心
2008年第11期263-265,共3页
Computer Engineering
基金
福建省教委科技基金资助项目(JA05290)
厦门大学"985"二期信息创新平台基金资助项目
关键词
电子证据
数据获取
关键词匹配
electronic evidence
data acquisition
keywords matching