信息安全研究 ›› 2017, Vol. 3 ›› Issue (9): 795-802.

• 学术论文 • 上一篇    下一篇

大数据取证技术综述

张其前   

  1. 浙江警察学院计算机与信息技术系
  • 收稿日期:2017-09-07 出版日期:2017-09-15 发布日期:2017-09-06
  • 通讯作者: 张其前

Overview of Big Data Forensics Technology

  • Received:2017-09-07 Online:2017-09-15 Published:2017-09-06

摘要: 随着大数据时代的到来,电子数据在体量迅速膨胀的同时,很多关键数据也会放置于云端. 传统取证对象一般都是独立的物理实体,比如计算机、手机、移动存储介质以及各种可穿戴电子设备等,而大数据取证对象可包括大数据宿主计算机、大数据系统本身、客户端虚拟主机、云客户端软件,以及云Web端网页等,这为电子数据取证技术带来的极大的挑战,因此,大数据取证技术成为目前电子数据取证的热点.通过对大数据的发展与随之带来的安全问题进行探讨,对大数据取证的相关技术展开论述,将大数据取证对象按照宿主层、系统层和应用层3个层面分析其取证内容,以我国最新取证法规为基础构建了大数据取证流程,构建了基于大数据构架的取证平台,最后对大数据取证的发展趋势提出了自己的观点.

关键词: 大数据取证, 云计算, Hadoop取证, 大数据安全, 大数据取证流程

Abstract: With the advent of the era of big data, the volume of electronic data is rapidly expanding. At the same time, more key data are placed in the cloud site. The traditional forensics objects are generally independent physical entity, such as computer, mobile phone, mobile storage media and wearable electronic devices. But the big data forensics objects may be the host computer of big data system , big data system itself, virtual host, cloud software, and the cloud Web pages, etc., which bringing great challenge for electronic forensics. Now, the big data forensics is becoming a hot spot in electronic forensics field. The development of big data and the security problems were discussed at first. Then the content of big data forensics object is analyzed in the host layer, system layer and application layer. On the basis of the latest forensics law in China the process of big data forensics is built. And the forensics platform construction based on big data structure is discussed. Finally, the development trend of large data forensics is put forward with author’s view.

Key words: big data forensics, cloud computing, hadoop forensics, big data security, big data forensics process