针对当前证据有效性不足的缺点,结合概率论,提出了基于可信概率的电子数据取证有效性模型.以Petri网为基础,将取证后经形式化处理的数据抽象为Petri网中的库所,操作行为和取证方法抽象为变迁,后一节点为运用该操作方法对前一节点进行某种变换所形成.给出了取证过程中的基本定义和形式化处理方法,研究了概率计算的相关算法,描述了详细的推理过程.利用"可信度+数据源+取证规则"作为对所得证据的有效性说明,为可信取证的动态取证行为可信提供理论基础.通过概率计算的方法,最终得到具体的概率数据,在保证数据源信息可信的基础上(即静态属性可信的假设前提),通过可信概率(概率值接近0或者1)的方法保证处理过程所使用的取证规则可信(即使用可信的动态取证方法或行为),最终实现电子数据作为证据的高的可信度.最后,设计了有效性证明系统,利用实际案例,分析并验证了可信概率在电子数据取证有效性模型中的具体应用.
According to the shortage of the current evidence's validity,one validity model of digital data forensics based on trusted probability is put forward.Based on Petri net,after collecting the evidence,the digital data processed through formalization is abstracted as the place of Petri net,at the same time,the operating behaviors and forensics methods are abstracted as the transitions.Then the backward nodes are formed by making some transformation on the forward nodes using the methods described above.The model puts forward the basic definitions and the methods of formalization processing.Moreover,it makes some researches on the related algorithms of probability calculation and describes the reasoning process in detail.The validity of evidence is proved by the combination architecture "Credit+Data source+Forensics rules",which provides theoretical basis for credibility of dynamic behavior in trusted forensics.Using the method of probability calculation,the concrete probability value can be finally gained.If the data source is supposed to be trusted,which means the data has trusted static attribute,then we can use the method of trusted probability,whose value is closing to 0 or 1,to ensure the forensics rules to be trusted within the processing,and the methods or the behaviors of dynamic forensics are trusted too.These models and methods give high confidence to the digital data as the evidence.In the end,a system of validity proof is designed to analyze and verify the trusted probability through its concrete application in the validity model of digital data forensics.