随着大数据时代的到来,电子数据在体量迅速膨胀的同时,很多关键数据也会存储于云端.传统取证对象一般都是独立的物理实体,比如计算机、手机、移动存储介质以及各种可穿戴电子设备等,而大数据取证对象可包括大数据宿主计算机、大数据系统本身、客户端虚拟主机、云客户端软件以及云Web端网页等,这为电子数据取证技术带来的极大的挑战,因此,大数据取证技术成为目前电子数据取证的热点.通过对大数据的发展与随之带来的安全问题进行探讨,对大数据取证的相关技术展开论述,将大数据取证对象按照宿主层、系统层和应用层3个层面分析其取证内容,以我国最新取证法规为基础探讨了大数据取证流程,构建了基于大数据架构的取证平台,最后对大数据取证的发展趋势提出了自己的观点.
With the advent of the era of big data,the volume of electronic data is rapidly expanding. At the same time, more key data are stored in the cloud. The traditional forensics objects are generally independent physical entities,such as computer,mobile phone,mobile storage media and wearable electronic devices. But the big data forensics objects may be the host computer of big data system,big data system itself,virtual host,cloud software,and the cloud Web pages, etc. , which bring great challenge for electronic forensics. Now,the big data forensics is becoming a hot spot in electronic forensics field. The development of big data and the security problems are discussed at first Then the content of big data forensics object is analyzed according to the three levels of the host layer, system layer and application layer. On the basis of the latest forensics law in China, the process of big data forensics is built. And the forensics platform construction based on big data structure is discussed. Finally, the development trend of big data forensics is put forward.