摘要
计算机网络犯罪形形色色,但都会被计算机系统或网络设备“记录”下数据。计算机取证(Computerforensics)又称为数字取证或电子取证,是对计算机犯罪的证据进行获取、保存、分析和出示,它实质上是一个详细扫描计算机系统以及重建入侵事件的过程。计算机取证既需要应用数据,又需要有些软件或工具在运行过程中产生的记录运行状态和操作结果的系统数据。
With the rapid development of network technology, the problems of network security become more and more severe. In this paper, a survey presents on various aspects of computer cyber crime form the basic concepts to the principal problems and the underlying investigation techniques, including intrusion detection technology, data mining technology, honey pot technology, and so on.
关键词
网络犯罪侦查
计算机取证
电子证据
Cyber Crime Investigation
Computer Forensics
Electronic Evidence