论文部分内容阅读
2001年数字取证研究工作组DFRWS(Digital Forensic Research Workshop)会议,明确将网络取证作为4个主题之一进行讨论,但网络取证绝不只是对网络数据流进行分析,因为对网络数据流分析的前提是必须捕捉到网络数据包,无论是实时捕捉,还是曾经捕捉,都只是对数据包的分析,因此,本文对其进行研究,并且进行案例分析。
2001 Digital Forensic Research Workshop DFRWS (Digital Forensic Research Workshop) conference, specifically the network forensics as one of the four topics to be discussed, but network forensics is not just the network data stream analysis, because the network data stream analysis of the premise It is necessary to capture the network packet, whether it is captured in real time, or once captured, are only the analysis of the data packet, therefore, this article studies it, and carries on the case analysis.