为了有效打击计算机犯罪,解决计算机取证中的技术问题,文章对现有的计算机取证体系结构及Windows系统的取证关键技术进行分析,提出了基于Windows系统的犯罪现场易失性证据的收集和分析方法。
Solving technical problems in computer forensic is the effective way of fighting with computer criminals. This paper analyses the computer forensic architecture and some forensic technologies based on Windows operation systems and investigates into gathering and analyzing volatile evidences in crime scene.