CN1645381A - Method for arranging verification inserter structure of remote computer - Google Patents

Method for arranging verification inserter structure of remote computer Download PDF

Info

Publication number
CN1645381A
CN1645381A CN 200410025341 CN200410025341A CN1645381A CN 1645381 A CN1645381 A CN 1645381A CN 200410025341 CN200410025341 CN 200410025341 CN 200410025341 A CN200410025341 A CN 200410025341A CN 1645381 A CN1645381 A CN 1645381A
Authority
CN
China
Prior art keywords
evidence obtaining
unit
plug
evidence
obtaining plug
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN 200410025341
Other languages
Chinese (zh)
Inventor
周晴杰
林家骏
金波
张志强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
JINNUO NETWORK SCURITY TECHNICAL DEVELOPMENT Co Ltd SHANGHAI
Original Assignee
JINNUO NETWORK SCURITY TECHNICAL DEVELOPMENT Co Ltd SHANGHAI
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by JINNUO NETWORK SCURITY TECHNICAL DEVELOPMENT Co Ltd SHANGHAI filed Critical JINNUO NETWORK SCURITY TECHNICAL DEVELOPMENT Co Ltd SHANGHAI
Priority to CN 200410025341 priority Critical patent/CN1645381A/en
Publication of CN1645381A publication Critical patent/CN1645381A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A method for arranging in plug unit to take evidence on remote computer includes arranging analyzer, knowledgebank, disc, reloadable storage movable media as local client end, connecting analyzer of remote evidence taking with local computer, informing local computer operator to look for and execute plug in unit for taking evidence in assigned edition by operator from evidence taking organization (ETO), feeding executed result back to operator from EFO at evidence taking analyzer end.

Description

A kind of method of disposing remote computer evidence obtaining plug-in architecture
Technical field
The present invention relates to a kind of electric digital data processing method and system thereof, particularly relate to a kind of method of disposing remote computer evidence obtaining plug-in architecture.
Background technology
In recent years; continuous development along with computer and network technologies; the computer security incident day by day increases; influence increasing; in time collect, analyze, confirm, protection, extract and all kinds of electronic evidences of filing computer system, become the emergency response of computer security incident and hit the technical barrier that needs to be resolved hurrily most in the computer crime activity.Domestic existing computer forensics technical requirement is reached the spot through the technician of professional training, operation and inspection computer system, the dismounting cabinet also takes out storage medium, utilize specialized equipments such as hard-disk duplicator to duplicate storage medium to reach the purpose of saving original evidence from damage, and then utilize the evidence-obtaining system analysis computer system and duplicate after storage medium, as shown in Figure 1.In the said process,, must reach the spot, complicated dismounting, work such as duplicate for a long time in order to obtain final forensics analysis conclusion, consuming time very long and complicated.In addition, during the file system of the operating system that evidence-obtaining system is installed on loading storage medium, tend to write on one's own initiative partial information, thereby cause the raw information on the storage medium to be destroyed.The crime one's share of expenses for a joint undertaking that part is unique, even can utilize the leak of operating system inside, make operating system when loading, destroy responsive evidence.Adopt the direct storage medium of analyzing after duplicating of evidence-obtaining system,, can destroy the data after dump equally, thereby cause to analyze crucial raw information though can avoid original storage medium itself to be destroyed.External computer forensics system such as Guidance Software, the Encase system of Inc company exploitation, its 3.0 version support realizes the closely evidence obtaining of computer system by parallel port communication, its 4.0 up-to-date versions begin to support the information of will collecting evidence to transmit by telecommunication network, but its structural requirement data must come to analyze by Network Transmission, processing speed is slow, and data security can not get guaranteeing, also has very big gap from the long-range evidence obtaining of practicality.Therefore, existing forensic technologies response speed is slow, and efficient is low, and is poor to the evidence protection, and personnel are required height, and practicality is relatively poor, seriously restricted the work of China's computer security incident emergency response and strike computer crime activity.
Summary of the invention
The objective of the invention is to overcome existing remote computer electronic evidence-collecting system and method thereof and exist not enoughly, provide that a kind of response speed is fast, efficient is high, good to the evidence protectiveness, to field staff's technical ability require low, be easy to safeguard, the method for deployment remote computer evidence obtaining plug-in architecture that practicality is high.
To achieve these goals, the technical scheme that is adopted: a kind of method of disposing remote computer evidence obtaining plug-in architecture comprises following step:
The first step: mechanism disposes the forensics analysis device in evidence obtaining, evidence obtaining plug-in unit knowledge base, store classifiedly the version number information of a plurality of evidence obtaining plug-in units and evidence obtaining plug-in unit in the described evidence obtaining plug-in unit knowledge base, described evidence obtaining plug-in unit comprises fixedly safety system, the logic recovery system, three subsystems of user interface system, the wherein said subsystem of fixedly saving from damage carries out read-only obtaining to the data in the storage medium under the prerequisite of not destroying storage medium, and the image file that produces carried out the checking and the preservation of multiple check and digital signature, described logic recovery subsystem adopts mode that accurate media drive location reads that the incomplete data of the impaired storage medium of physics and logic is searched, the location, extract and recovery, and by association analysis to incomplete data, data in recovery file system and the application system, described user interface subsystem provides newly-increased, open, the user interface of preserving and closing, user interface newly-increased and the deletion image file is provided, the medium preview is provided, medium obtains, the user interface that medium is browsed provides the location of data and the user interface of file system recovery;
Second step: dispose CD and the client of the storage move media that can write in the computing machine place of need evidence obtaining as local computer, on described CD, deposit evidence obtaining plug-in unit backup library, on the mobile memory medium that can write, deposited the tabulation of evidence obtaining plug-in unit and some evidence obtaining plug-in units;
The 3rd step: during to the above-mentioned computer forensics that needs evidence obtaining, the network that the evidence obtaining operating personnel of mechanism notify the local computer operating personnel to set up long-range forensics analysis device and local computer is connected, the local computer operating personnel put into described specific computer CD ROM with described CD, the mobile memory medium that can write is installed on the described specific computing machine movable storage device interface, the operating personnel of evidence obtaining mechanism that are positioned at remote port connect by network, check the situation of local computer, and the evidence obtaining plug-in version of the definite employing of categorizing selection from the evidence obtaining plug-in unit knowledge base that is deployed in evidence obtaining mechanism, then, the evidence obtaining operating personnel of mechanism notify the local computer operating personnel from evidence obtaining plug-in unit backup library, the evidence obtaining plug-in unit of sequential search and execution indicated release in the tabulation of evidence obtaining plug-in unit;
Remote computer evidence obtaining plug-in architecture by above three steps deployment, the local computer operating personnel can carry out the evidence obtaining plug-in unit of the long-range evidence obtaining operating personnel of mechanism appointment, and the result that will collect evidence feeds back to the long-range evidence obtaining operating personnel of mechanism and finishes the evidence obtaining of remote computer.
The technical solution used in the present invention provides the forensics analysis technological frame of an opening, by teleinstruction transmission and load various evidence obtaining plug-in units, realize forensics analysis in this locality, and send the result to long-range forensics analysis personnel, compared with prior art, have following tangible advantage and good effect:
1. response speed is fast
Traditional evidence obtaining work or requiring to reach the spot through the evidence obtaining personnel collects evidence, or need analyze and fixedly the saving from damage of evidence by transmitted data on network, can not satisfy the evidence obtaining needs of quick emergency response.The present invention need not the evidence obtaining personnel and reaches the spot, and also need not by the Network Transmission mass data, only needs to and guide the operating personnel of local side to carry out the evidence obtaining plug-in unit of appointment in the remote port analysis, just can finish evidence obtaining work.Therefore when finding suspicious case, as long as set up being connected of long-range evidence-obtaining device and local computer, just can begin evidence obtaining work immediately, the computer security incident that happens suddenly is promptly collected evidence has responding ability fast.
2. efficient height
In computer forensics work in the past, the caseload that can finally obtain valuable evidence only accounts for the minimum ratio of suspicious caseload.If each in order to obtain final forensics analysis conclusion, must reach the spot, complicated dismounting, duplicate for a long time, work such as analysis, consuming time very long and complicated.The present invention has abandoned these processes, carries out the evidence obtaining plug-in unit by the local side operating personnel and just can draw the result of forensics analysis, if find valuable evidence, reinforms long-range forensics analysis personnel and carries out the scene evidence obtaining to this locality, has improved efficient greatly.
3. good to the evidence protectiveness
During file system on loading storage medium of traditional evidence obtaining work, the operating system that evidence-obtaining system has been installed, tend to write on one's own initiative partial information, thereby cause the raw information on the storage medium to be destroyed.The crime one's share of expenses for a joint undertaking that part is unique, even can utilize the leak of operating system inside, make operating system when loading, destroy responsive evidence.Adopt the direct storage medium of analyzing after duplicating of evidence-obtaining system,, can destroy the data after dump equally, thereby cause to analyze crucial raw information though can avoid original storage medium itself to be destroyed.Evidence obtaining plug-in unit of the present invention directly carries out read-onlyly obtaining and analyzing to storage medium at local client, avoided media data losing of duplicating, may cause in the loading, transmission course or destroy, and improved the protectiveness to evidence.
4. require low to field staff's technical ability
The present invention only requires that the field staff operates according to long-range forensics analysis personnel's requirement and instruction, does not need to possess the evidence obtaining knowledge and skills of specialty.
5. be easy to safeguard
Along with development of computer, various new file system and storage medium will be increasing, and the evidence obtaining need of work is handled with the evidence obtaining plug-in unit of different editions at the concrete condition of different spots.Utilize the present invention, daily need are upgraded to the evidence obtaining knowledge base of emergency center or investigation mechanism, when evidence obtaining, just the client that needs redaction are sent the evidence obtaining plug-in unit by network, upgrade the plug-in unit tabulation.This long-range evidence obtaining plug-in architecture has reduced the cost of daily upgrade maintenance, makes long-range evidence-obtaining system be easier to safeguard.
6. practicality height
The present invention is only need be in the Internet bar etc. common need the computing machine place of evidence obtaining dispose CD and the storage move media that can write as client, dispose forensics analysis device, evidence obtaining plug-in unit knowledge base at emergency center or investigation mechanism, just can when taking place, suspicious case connect the purpose that realizes long-range evidence obtaining by network, dispose simple, the framework extended capability is strong, system is progressively expanded and strengthen the evidence obtaining ability, have advantages of high practicability.
Description of drawings
Fig. 1 is active computer evidence obtaining workflow synoptic diagram;
The remote computer evidence obtaining plug-in architecture synoptic diagram that Fig. 2 disposes for adopting the inventive method;
Fig. 3 is a process flow diagram of the present invention.
Embodiment
Below in conjunction with accompanying drawing 1~3, the present invention is described in further detail: as shown in Figure 3, a kind of method of disposing remote computer evidence obtaining plug-in architecture: the first step: mechanism disposes the forensics analysis device in evidence obtaining, evidence obtaining plug-in unit knowledge base, store classifiedly the version number information of a plurality of evidence obtaining plug-in units and evidence obtaining plug-in unit in the described evidence obtaining plug-in unit knowledge base, described evidence obtaining plug-in unit comprises fixedly safety system, the logic recovery system, three subsystems of user interface system, each subsystem all makes up by OO soft plug-in part technology, the wherein said subsystem of fixedly saving from damage carries out read-only obtaining to the data in the storage medium under the prerequisite of not destroying storage medium, and the image file that produces carried out the checking and the preservation of multiple check and digital signature, described logic recovery subsystem adopts mode that accurate media drive location reads that the incomplete data of the impaired storage medium of physics and logic is searched, the location, extract and recovery, and by association analysis to incomplete data, data in recovery file system and the application system, described user interface subsystem provides newly-increased, open, the user interface of preserving and closing, user interface newly-increased and the deletion image file is provided, the medium preview is provided, medium obtains, the user interface that medium is browsed provides the location of data and the user interface of file system recovery; Second step: dispose CD and the client of the storage move media that can write as local computer in the computing machine place of possible need evidence obtaining, on described CD, deposit evidence obtaining plug-in unit backup library, on the mobile memory medium that can write, deposited the tabulation of evidence obtaining plug-in unit and some evidence obtaining plug-in units; The 3rd step: when needing to the specific computer forensics in the above-mentioned computing machine place that needs evidence obtaining, the network that the evidence obtaining operating personnel of mechanism notify the local computer operating personnel to set up long-range forensics analysis device and local computer is connected, the local computer operating personnel put into described specific computer CD ROM with described CD, the mobile memory medium that can write is installed on the described specific computing machine movable storage device interface, the operating personnel of evidence obtaining mechanism that are positioned at remote port connect by network, check the situation of local computer, and the evidence obtaining plug-in version of the definite employing of categorizing selection from the evidence obtaining plug-in unit knowledge base that is deployed in evidence obtaining mechanism, then, the evidence obtaining operating personnel of mechanism notify the local computer operating personnel from evidence obtaining plug-in unit backup library, the evidence obtaining plug-in unit of sequential search and execution indicated release in the tabulation of evidence obtaining plug-in unit; Remote computer evidence obtaining plug-in architecture by above three steps deployment, the local computer operating personnel can carry out the evidence obtaining plug-in unit of the long-range evidence obtaining operating personnel of mechanism appointment, and the result that will collect evidence feeds back to the long-range evidence obtaining operating personnel of mechanism and finishes the evidence obtaining of remote computer.In the described step 3, if can not find the evidence obtaining plug-in unit of indicated release in the evidence obtaining plug-in unit tabulation of local computer operating personnel in mobile memory medium, the operating personnel of mechanism that then collect evidence give local computer with the evidence obtaining plug-in unit of indicated release by Network Transmission from evidence obtaining plug-in unit knowledge base, the evidence obtaining plug-in unit that will newly be received by the local computer operating personnel is stored on the mobile memory medium that can write, upgrade the tabulation of evidence obtaining plug-in unit, and carry out this evidence obtaining plug-in unit.
In the method for the long-range evidence obtaining plug-in architecture of the present invention, the mainboard of the computing machine that start has CD-ROM drive and movable storage device interface, and supports optical disk start-up.CD-ROM drive can be a CD-ROM drive, or CD writer, or DVD driver, or DVD burner, or compound driver (Combo Driver) etc., CD can be CD-ROM, or CD-R, or DVD-ROM, or DVD-R etc., the movable storage device interface can be USB (Universal Serial Bus, the general serial line), or PCMCIA (Personal Computer Memory Card International Assocaition, PCMCIA (personal computer memory card international association)), or IEEE 1394 (claims FireWire again, live wire, i.LINK), or CF (Compact Flash), or SM (SmartMedia Flash), or SD (Secure Digital) or MMC (MultiMedia), or memory stick interfaces such as (Memory Stick), the mobile memory medium that can write can be based on the external storage of above-mentioned interface, or storage card, or memory card, or memory stick, or flash memory, or little dish (MicroDrive) etc.As shown in Figure 2, at remote port, dispose forensics analysis device and evidence obtaining plug-in unit knowledge base as emergency center or investigation mechanism, in the Internet bar etc. the computing machine place of common need evidence obtaining dispose CD and the storage move media that can write as client, deposit evidence obtaining plug-in unit backup library on the CD, deposit the tabulation of evidence obtaining plug-in unit and a small amount of evidence obtaining plug-in unit on the mobile memory medium that can write.The present invention is by teleinstruction transmission and load various evidence obtaining plug-in units, realizes forensics analysis in this locality, and the result that will collect evidence sends long-range forensics analysis personnel to, and replacing needs the evidence obtaining personnel to rush for the spot to carry out on-the-spot forensics analysis in the traditional approach.For finishing above-mentioned work, CD-ROM drive, CD, movable storage device interface have been introduced among the present invention and the mobile memory medium hardware that can write is realized the framework method of long-range evidence obtaining plug-in unit.Wherein, CD-ROM drive is used for reading the data in the CD, CD is used for depositing various evidence obtaining plug-in units, version and relevant information, and the movable storage device interface is used for reading and writing the mobile memory medium that can write, and the mobile memory medium that can write is used for storing the tabulation of evidence obtaining plug-in unit and a small amount of plug-in unit of collecting evidence.
As shown in Figure 3, concrete implementing procedure of the present invention is described below:
Dispose evidence obtaining plug-in unit knowledge base at remote port, store classifiedly various evidence obtaining plug-in units, version and relevant information;
Evidence obtaining plug-in unit backup library is provided in the CD that provides for client, the tabulation of evidence obtaining plug-in unit is provided in the mobile memory medium of writing that provides, these are equivalent to the local cache of long-range evidence obtaining plug-in unit knowledge base.
When beginning to collect evidence work, the client operation personnel put into the CD-ROM drive of client computer with CD, and the mobile memory medium that can write is connected on the movable storage device interface of client computer;
In the system situation of remote port evidence obtaining personnel according to client computer, check evidence obtaining plug-in unit knowledge base according to classification, determine the version of the evidence obtaining plug-in unit of employing;
Remote port evidence obtaining personnel notify the client operation personnel according to the evidence obtaining plug-in unit of searching indicated release in the evidence obtaining plug-in unit tabulation of evidence obtaining plug-in version number in mobile memory medium;
If should not collect evidence plug-in unit in the tabulation of the evidence obtaining plug-in unit of client, then give client with this evidence obtaining plug-in unit by Network Transmission by remote port evidence obtaining personnel, client personnel are after receiving successfully, it is saved in the mobile memory medium that can write, and refresh the tabulation of evidence obtaining plug-in unit, carry out this evidence obtaining plug-in unit at last;
After the evidence obtaining plug-in unit was carried out and finished, the client operation personnel fed back to remote port evidence obtaining personnel with analysis result.
By the deployment of above-mentioned long-range evidence obtaining plug-in architecture and implementing procedure as seen, the present invention is by the teleinstruction transmission and load various evidence obtaining plug-in units, realize forensics analysis in this locality, and the result that will collect evidence sends long-range forensics analysis personnel to, obviously be different from the tradition framework of collecting evidence.Provide that a kind of response speed is fast, efficient is high, good to the evidence protectiveness, to field staff's technical ability require low, be easy to safeguard, the method for long-range evidence obtaining plug-in architecture that practicality is high, have obvious superiority.

Claims (2)

1. method of disposing remote computer evidence obtaining plug-in architecture is characterized in that following step:
The first step: mechanism disposes the forensics analysis device in evidence obtaining, evidence obtaining plug-in unit knowledge base, store classifiedly the version number information of a plurality of evidence obtaining plug-in units and evidence obtaining plug-in unit in the described evidence obtaining plug-in unit knowledge base, described evidence obtaining plug-in unit comprises fixedly safety system, the logic recovery system, three subsystems of user interface system, the wherein said subsystem of fixedly saving from damage carries out read-only obtaining to the data in the storage medium under the prerequisite of not destroying storage medium, and the image file that produces carried out the checking and the preservation of multiple check and digital signature, described logic recovery subsystem adopts mode that accurate media drive location reads that the incomplete data of the impaired storage medium of physics and logic is searched, the location, extract and recovery, and by association analysis to incomplete data, data in recovery file system and the application system, described user interface subsystem provides newly-increased, open, the user interface of preserving and closing, user interface newly-increased and the deletion image file is provided, the medium preview is provided, medium obtains, the user interface that medium is browsed provides the location of data and the user interface of file system recovery;
Second step: dispose CD and the client of the storage move media that can write in the computing machine place of need evidence obtaining as local computer, on described CD, deposit evidence obtaining plug-in unit backup library, on the mobile memory medium that can write, deposited the tabulation of evidence obtaining plug-in unit and some evidence obtaining plug-in units;
The 3rd step: during to the computer forensics of need evidence obtainings, the network that the evidence obtaining operating personnel of mechanism notify the local computer operating personnel to set up long-range forensics analysis device and local computer is connected, the local computer operating personnel put into described specific computer CD ROM with described CD, the mobile memory medium that can write is installed on the described specific computing machine movable storage device interface, the operating personnel of evidence obtaining mechanism that are positioned at remote port connect by network, check the situation of local computer, and the evidence obtaining plug-in version of the definite employing of categorizing selection from the evidence obtaining plug-in unit knowledge base that is deployed in evidence obtaining mechanism, then, the evidence obtaining operating personnel of mechanism notify the local computer operating personnel from evidence obtaining plug-in unit backup library, the evidence obtaining plug-in unit of sequential search and execution indicated release in the tabulation of evidence obtaining plug-in unit.
2. a kind of method of disposing remote computer evidence obtaining plug-in architecture according to claim 1, it is characterized in that in the described step 3, can not find the evidence obtaining plug-in unit of indicated release in the evidence obtaining plug-in unit tabulation of local computer operating personnel in mobile memory medium, the operating personnel of mechanism that then collect evidence give local computer with the evidence obtaining plug-in unit of indicated release by Network Transmission from evidence obtaining plug-in unit knowledge base, the evidence obtaining plug-in unit that will newly be received by the local computer operating personnel is stored on the mobile memory medium that can write, upgrade the tabulation of evidence obtaining plug-in unit, and carry out this evidence obtaining plug-in unit.
CN 200410025341 2004-06-22 2004-06-22 Method for arranging verification inserter structure of remote computer Pending CN1645381A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 200410025341 CN1645381A (en) 2004-06-22 2004-06-22 Method for arranging verification inserter structure of remote computer

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 200410025341 CN1645381A (en) 2004-06-22 2004-06-22 Method for arranging verification inserter structure of remote computer

Publications (1)

Publication Number Publication Date
CN1645381A true CN1645381A (en) 2005-07-27

Family

ID=34868462

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 200410025341 Pending CN1645381A (en) 2004-06-22 2004-06-22 Method for arranging verification inserter structure of remote computer

Country Status (1)

Country Link
CN (1) CN1645381A (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100414554C (en) * 2006-10-10 2008-08-27 中国科学院软件研究所 Electronic data evidence obtaining method and system for computer
CN102025743A (en) * 2010-12-20 2011-04-20 北京世纪互联工程技术服务有限公司 Method and device for exporting mirror image of virtual machine in cloud computing
CN101535952B (en) * 2005-08-19 2014-06-04 谷歌公司 Software architecture for displaying information content from plug-in modules in a user interface
CN111062008A (en) * 2018-10-17 2020-04-24 上海越钰信息技术有限公司 Remote electronic evidence obtaining system and method

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101535952B (en) * 2005-08-19 2014-06-04 谷歌公司 Software architecture for displaying information content from plug-in modules in a user interface
CN100414554C (en) * 2006-10-10 2008-08-27 中国科学院软件研究所 Electronic data evidence obtaining method and system for computer
CN102025743A (en) * 2010-12-20 2011-04-20 北京世纪互联工程技术服务有限公司 Method and device for exporting mirror image of virtual machine in cloud computing
CN111062008A (en) * 2018-10-17 2020-04-24 上海越钰信息技术有限公司 Remote electronic evidence obtaining system and method
CN111062008B (en) * 2018-10-17 2023-05-30 上海越钰信息技术有限公司 Remote electronic evidence obtaining system and method

Similar Documents

Publication Publication Date Title
Richard III et al. Scalpel: a frugal, high performance file carver.
Richard III et al. Next-generation digital forensics
CN1738352A (en) Document processing device, document processing method, and storage medium recording program therefor
CN108319543A (en) A kind of asynchronous processing method and its medium, system of computer log data
Shaw et al. A practical and robust approach to coping with large volumes of data submitted for digital forensic examination
CN101060436A (en) A fault analyzing method and device for communication equipment
CN1822004A (en) System and method for using a file system to automatically backup a file as a generational file
CN101354715A (en) Systems, methods and computer program products for operating a data processing system
CN1815451A (en) Log information management method and system
CN1737800A (en) Method and system for delayed deletion of extended attributes
CN1877550A (en) Method for implementing real-time hot-plug of USB memory under TV embedded Linux system
Sankar et al. Digitizing a million books: Challenges for document analysis
CN1968349A (en) TV set software upgrade method
CN1645381A (en) Method for arranging verification inserter structure of remote computer
US20090299935A1 (en) Method and apparatus for digital forensics
CN104156669A (en) Computer information evidence obtaining system
CN114647624A (en) Method, system and storage medium for capturing database consistent point in block-level CDP
CN113448946B (en) Data migration method and device and electronic equipment
CN1264094C (en) Method for construction of computer application system using compact disc and mobile memory medium
US9110595B2 (en) Systems and methods for enhancing performance of software applications
US7263468B2 (en) Method for storing access record in network communication device
CN1645382A (en) Computer long-distance electronic evidence obtaining method and system
CN1975701A (en) Master machine driving external equipment method and system
CN106874147B (en) Method for recovering and analyzing pre-read file of Windows operating system
CN101510211A (en) Multimedia data processing system and method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Open date: 20050727