如何描述和规范计算机取证需求是计算机取证基本理论及基本方法研究中较为突出的一个问题.本文结合软件工程及安全工程的思想提出了场景需求定义法,它对计算机取证需求的制定给出了一套定义方法.基于以上定义方法,需求的制定可以面向所有计算机取证环境,即它不限定哪类取证环境应该提供哪些取证需求,而是在实际应用中根据实际需要来确定,这为描述不断变化的复杂现实应用环境中的安全需求提供了灵活性.
How to describe and standardize the digital forensic requirement is an important part in digital forensic methodology. The paper propose the definition method of digital forensic requirement and an abstract model, named Environment Request Description (ERD). ERD definite three methods to describe digital forensic environment and requirement:Components,Environment Profile and Environment Target. ERD don't depend on a special digital forensic environment. Customer, developer and others depending on active usage could decide requirement. It will be useful to definite a forensic requirement in different and complex digital forensic environment.