发明名称 A COMPUTER-READABLE RECORDING MEDIUM STORING A PROGRAM FOR EXECUTING THE COLLECTION AND METHODS OF DIGITAL EVIDENCE
摘要 The present invention relates to a digital evidence collecting method and, specially to a digital evidence collecting method for digital forensics which collects data, changed or deleted arbitrarily or intentionally by a user, from an Oracle database which is an analysis object within a warrant range. The digital evidence collecting method comprises: detecting specifications of queries executed by the user from a flashback database log file in order to delete or change data in tables after making access to the Oracle database via a master account detected in the Oracle database; and collecting evidence data, deleted or changed by the user, corresponding to the detected specifications of the queries. According to the present invention, the data specified in the Oracle database-arbitrarily or intentionally changed or deleted by the user- is easily and rapidly acquired within the warrant range though all the files included in the Oracle database are not acquired. [Reference numerals] (200) DB steam collecting system;(AA) Oracle database A;(BB) Oracle database B;(CC) Oracle database C;(DD) Oracle database D;(EE) Oracle database E;(FF) Oracle database F;(GG) Oracle database G;(HH) Oracle database H
申请公布号 KR101329329(B1) 申请公布日期 2013.11.15
申请号 KR20120120494 申请日期 2012.10.29
申请人 REPUBLIC OF KOREA (SUPREME PUBLIC PROSECUTOR'S OFFICE) 发明人 SUNG, KI BUM
分类号 G06F21/00;G06F17/30;G06F17/40 主分类号 G06F21/00
代理机构 代理人
主权项
地址