ÎÞÂÛÊÇÆóÒµ»·¾³»¹ÊǸöÈËÓû§£¬Linuxϵͳ¶¼°çÑÝ×ÅÖØÒª½ÇÉ«
È»¶ø£¬µ±Éæ¼°µ½Êý×Öȡ֤ʱ£¬LinuxϵͳµÄ¸´ÔÓÐÔ¸øÈ¡Ö¤ÈËÔ±´øÀ´Á˲»ÉÙÌôÕ½
±¾ÎĽ«ÉîÈë̽ÌÖÈçºÎÔÚLinuxϵͳÖнøÐÐÓÐЧµÄÊý×Öȡ֤£¬°üÀ¨È¡Ö¤Ç°µÄ×¼±¸¡¢¹Ø¼üÊý¾ÝÊÕ¼¯¡¢·ÖÎö¼¼ÊõÒÔ¼°×î¼Ñʵ¼ù£¬Ö¼ÔÚΪȡ֤ר¼ÒÌṩһÌ×È«ÃæµÄÖ¸ÄÏ
Ò»¡¢È¡Ö¤Ç°µÄ×¼±¸ 1.¹¤¾ß×¼±¸ ÔÚȡ֤¹ý³ÌÖУ¬Ñ¡ÔñºÏÊʵŤ¾ßÖÁ¹ØÖØÒª
LinuxϵͳϵÄȡ֤¹¤¾ßÖÖÀà·±¶à£¬°üÀ¨µ«²»ÏÞÓÚ£º -The Sleuth Kit (TSK)£ºÒ»¸ö¿ªÔ´µÄÊý×Öȡ֤¹¤¾ß°ü£¬Ö§³ÖÎļþϵͳ·ÖÎö¡¢¹þϣУÑéºÍ´ÅÅ̾µÏñµÈ¹¦ÄÜ
-Autopsy£º»ùÓÚTSKµÄͼÐλ¯È¡Ö¤·ÖÎö¹¤¾ß£¬ÊʺϳõѧÕߺÍÐèÒª¿ìËÙ·ÖÎöµÄ³¡¾°
-Wireshark£ºÓÃÓÚÍøÂçȡ֤£¬¿ÉÒÔ²¶»ñºÍ·ÖÎöÍøÂçÊý¾Ý°ü
-log2timeline£º½«ÏµÍ³ÈÕ־ת»»ÎªÊ±¼äÏߣ¬±ãÓÚʼþÖØ½¨
-Volatility£ºÄÚ´æÈ¡Ö¤¹¤¾ß£¬ÓÃÓÚ·ÖÎöÄÚ´æ¾µÏñÎļþ
ȡ֤ÈËÔ±Ó¦¸ù¾Ý¾ßÌå°¸¼þÐèÇóÑ¡ÔñºÏÊʵŤ¾ß×éºÏ
2.·¨ÂÉÓëÂ×Àí¿¼Á¿ ÔÚ½øÐÐÈκÎȡ֤»î¶¯Ö®Ç°£¬±ØÐëÈ·±£·ûºÏÏà¹Ø·¨ÂɺÍÂ×Àí±ê×¼
Õâ°üÀ¨»ñµÃºÏ·¨ÊÚȨ¡¢±£»¤¸öÈËÒþ˽ÒÔ¼°±ÜÃâÊý¾ÝÎÛȾµÈ
ȡ֤ÈËÔ±Ó¦ÊìϤËùÔÚµØÇøµÄ·¨ÂÉ·¨¹æ£¬È·±£È¡Ö¤¹ý³ÌµÄºÏ·¨ÐÔ
3.ϵͳ¿ìÕÕÓë¾µÏñ ΪÁ˱ÜÃâÆÆ»µÔʼÊý¾Ý£¬È¡Ö¤µÄµÚÒ»²½Í¨³£ÊÇ´´½¨ÏµÍ³µÄ¿ìÕÕ»ò¾µÏñ
Õâ¿ÉÒÔͨ¹ýʹÓÃ`dd`¡¢`ddrescue`»ò`foremost`µÈ¹¤¾ßÍê³É
¾µÏñÎļþÓ¦Í×ÉÆ±£´æ£¬²¢ÔÚºóÐøµÄ·ÖÎöÖÐʹÓã¬ÒÔÈ·±£Êý¾ÝµÄÍêÕûÐÔºÍÕæÊµÐÔ
¶þ¡¢¹Ø¼üÊý¾ÝÊÕ¼¯ 1.Îļþϵͳ·ÖÎö LinuxϵͳµÄÎļþϵͳ½á¹¹¸´ÔÓ£¬µ«×ñÑÒ»¶¨µÄ±ê×¼
ȡ֤ÈËÔ±Ó¦ÖØµã¹Ø×¢`/home`¡¢`/var/log`¡¢`/etc`µÈĿ¼
-Óû§Êý¾Ý£º/homeĿ¼ÏÂͨ³£°üº¬Óû§µÄ¸öÈËÎļþ¡¢ÅäÖÃÎļþºÍÈÕÖ¾Îļþ
ÕâЩÎļþ¿ÉÄܰüº¬¹Ø¼üÖ¤¾Ý£¬ÈçÎĵµ¡¢Í¼Æ¬¡¢ÓʼþµÈ
-ϵͳÈÕÖ¾£º/var/logĿ¼°üº¬ÁËϵͳÔËÐеĸ÷ÀàÈÕÖ¾£¬ÈçÈÏÖ¤ÈÕÖ¾£¨`/var/log/auth.log`£©¡¢ÏµÍ³ÏûÏ¢ÈÕÖ¾£¨`/var/log/syslog`£©µÈ
ÕâЩÈÕÖ¾¶ÔÓÚʼþÖØ½¨ºÍʱ¼äÏß·ÖÎöÖÁ¹ØÖØÒª
-ÅäÖÃÎļþ£º/etcĿ¼ÏµÄÅäÖÃÎļþ¼Ç¼ÁËϵͳÅäÖÃÐÅÏ¢£¬ÈçÍøÂç·þÎñÅäÖá¢Óû§È¨ÏÞÉèÖõÈ
ÕâЩÐÅÏ¢ÓÐÖúÓÚÀí½âϵͳµÄÔËÐÐ״̬ºÍDZÔڵݲȫ©¶´
2.ÄÚ´æÈ¡Ö¤ ÄÚ´æÈ¡Ö¤ÊÇLinuxϵͳȡ֤µÄÖØÒªÒ»»·
ÄÚ´æ¾µÏñÖпÉÄܰüº¬ÔËÐÐÖеĽø³Ì¡¢ÍøÂçÁ¬½Ó״̬¡¢Óû§»á»°ÐÅÏ¢µÈ¹Ø¼üÊý¾Ý
ʹÓÃVolatilityµÈ¹¤¾ß¿ÉÒÔ·ÖÎöÄÚ´æ¾µÏñ£¬ÌáÈ¡ÓÐÓõÄÖ¤¾Ý
3.ÍøÂçȡ֤ Linuxϵͳͨ³£×÷Ϊ·þÎñÆ÷»òÍøÂçÉ豸ʹÓã¬ÍøÂçȡ֤Òò´ËÏÔµÃÓÈÎªÖØÒª
ͨ¹ý²¶»ñºÍ·ÖÎöÍøÂçÊý¾Ý°ü£¬¿ÉÒÔ×·×Ù¹¥»÷·¾¶¡¢Ê¶±ð¶ñÒâÁ÷Á¿ºÍÌáȡͨÐÅÄÚÈÝ
WiresharkµÈ¹¤¾ßÔÚÕâ·½Ãæ¾ßÓÐÇ¿´ó¹¦ÄÜ
4.ʱ¼äÏß·ÖÎö ¹¹½¨Ê¼þʱ¼äÏßÊÇÀí½âϵͳ״̬ºÍʼþ·¢Õ¹Ë³ÐòµÄ¹Ø¼ü
log2timelineµÈ¹¤¾ß¿ÉÒÔ½«À´×Ô²»Í¬À´Ô´µÄÈÕÖ¾ºÍʱ¼ä´ÁÕûºÏ³Éµ¥Ò»µÄʱ¼äÏߣ¬°ïÖúȡ֤ÈËÔ±¿ìËÙ¶¨Î»¹Ø¼üʼþ
Èý¡¢·ÖÎö¼¼Êõ 1.¹þϣУÑé ÔÚȡ֤¹ý³ÌÖУ¬Ê¹ÓùþÏ£Ëã·¨£¨ÈçMD5¡¢SHA-256£©¶ÔÊÕ¼¯µÄÊý¾Ý½øÐÐУÑ飬¿ÉÒÔÈ·±£Êý¾ÝµÄÍêÕûÐÔºÍÕæÊµÐÔ
¹þÏ£ÖµµÄ±ä»¯¿ÉÄÜÒâζ×ÅÊý¾ÝÒѱ»´Û¸Ä
2.ÎļþÇ©ÃûÓëÀàÐÍʶ±ð ͨ¹ýÎļþÇ©Ãû£¨ÈçMagic Number£©ºÍÀàÐÍʶ±ð¹¤¾ß£¨Èç`file`ÃüÁ£¬¿ÉÒÔ¿ìËÙʶ±ðÎļþÀàÐÍ£¬´Ó¶øËõС·ÖÎö·¶Î§£¬Ìá¸ßȡ֤ЧÂÊ
3.×Ö·û´®ËÑË÷ÓëÕýÔò±í´ïʽ ʹÓÃ`grep`¡¢`awk`µÈ¹¤¾ß½øÐÐ×Ö·û´®ËÑË÷£¬½áºÏÕýÔò±í´ïʽ£¬¿ÉÒÔÔÚ´óÁ¿Êý¾ÝÖпìËÙ¶¨Î»¹Ø¼üÐÅÏ¢
Õâ¶ÔÓÚÈÕÖ¾·ÖÎöºÍÎļþÄÚÈÝÌáÈ¡ÓÈÎªÖØÒª
4.Êý¾Ý»Ö¸´ ÔÚijЩÇé¿öÏ£¬¹Ø¼üÊý¾Ý¿ÉÄÜÒѱ»É¾³ý»òËð»µ
´Ëʱ£¬¿ÉÒÔʹÓÃ`testdisk`¡¢`photorec`µÈÊý¾Ý»Ö¸´¹¤¾ß³¢ÊÔ»Ö¸´Êý¾Ý
ÕâЩ¹¤¾ßÄܹ»Ê¶±ðÎļþϵͳµÄ½á¹¹£¬´Ó´ÅÅ̵ÄÊ£Óà¿Õ¼äÖÐÌáÈ¡Êý¾Ý
ËÄ¡¢×î¼Ñʵ¼ù 1.Îĵµ¼Ç¼ Õû¸öȡ֤¹ý³ÌÓ¦Ïêϸ¼Ç¼£¬°üÀ¨Ã¿Ò»²½µÄ²Ù×÷¡¢Ê¹ÓõŤ¾ß¡¢ÊÕ¼¯µÄÊý¾ÝÒÔ¼°·ÖÎö½á¹û
Õâ²»½öÓÐÖúÓÚºóÐøµÄ±¨¸æ×«Ð´£¬»¹ÄÜÔÚÐèҪʱÌṩÉó¼ÆºÍÑéÖ¤µÄÒÀ¾Ý
2.³ÖÐøÑ§Ï°ÓëÅàѵ Êý×Öȡ֤¼¼ÊõÈÕÐÂÔÂÒ죬ȡ֤ÈËÔ±Ó¦²»¶ÏѧϰÐÂ֪ʶ¡¢ÕÆÎÕй¤¾ß
²Î¼ÓרҵÅàѵ¡¢ÔĶÁ×îеÄÑо¿±¨¸æºÍ²Î¼ÓÐÐÒµ»áÒé¶¼ÊÇÌáÉý¼¼ÄܵÄÓÐЧ;¾¶
3.ÍŶӺÏ×÷Óë¿ç²¿ÃÅÐ×÷ Êý×Öȡ֤ÍùÍùÉæ¼°¶à¸öÁìÓòµÄ֪ʶºÍ¼¼ÄÜ£¬Èç¼ÆËã»ú¿ÆÑ§¡¢·¨ÂÉ¡¢ÍøÂ簲ȫµÈ
Òò´Ë£¬½¨Á¢¿çѧ¿ÆµÄÍŶӺÏ×÷»úÖÆ£¬¼ÓÇ¿ÓëÆäËû²¿ÃÅ£¨Èç·¨Îñ¡¢ÍøÂ簲ȫÍŶӣ©µÄ¹µÍ¨ÓëÐ×÷£¬¶ÔÓÚÌá¸ßȡ֤ЧÂʺÍÖÊÁ¿ÖÁ¹ØÖØÒª
4.°²È«ÒâʶÌáÉý ȡ֤ÈËÔ±Ó¦¾ß±¸Á¼ºÃµÄ°²È«Òâʶ£¬Á˽ⳣ¼ûµÄ¹¥»÷ÊÖ·¨ºÍ·ÀÓù´ëÊ©
ÕâÓÐÖúÓÚÔÚȡ֤¹ý³ÌÖÐʶ±ðDZÔÚµÄÍþвºÍ©¶´£¬ÎªºóÐøµÄ·À·¶ºÍÕû¸ÄÌṩ½¨Òé
Îå¡¢½áÓï Linuxϵͳȡ֤ÊÇÒ»ÏÔÓ¶ø¾«Ï¸µÄ¹¤×÷£¬ÐèҪȡ֤ÈËÔ±¾ß±¸ÔúʵµÄרҵ֪ʶ¡¢·á¸»µÄʵ¼ù¾ÑéºÍÃôÈñµÄ¶´²ìÁ¦
ͨ¹ýºÏÀíµÄ×¼±¸¡¢¿ÆÑ§µÄÊý¾ÝÊÕ¼¯¡¢¸ßЧµÄ·ÖÎö¼¼ÊõºÍÑϸñµÄ×î¼Ñʵ¼ù£¬È¡Ö¤ÈËÔ±Äܹ»¸üÓÐЧµØÌáÈ¡ºÍ·ÖÎöLinuxϵͳÖеĹؼüÖ¤¾Ý£¬Îª°¸¼þµÄÕìÆÆºÍ·¨ÂɵĹ«Õý²Ã¾öÌṩÓÐÁ¦Ö§³Ö
Ëæ×ż¼ÊõµÄ²»¶Ï½ø²½ºÍ·¨ÂɵÄÈÕÒæÍêÉÆ£¬Linuxϵͳȡ֤½«ÔÚδÀ´·¢»Ó¸ü¼ÓÖØÒªµÄ×÷ÓÃ
CÓïÑÔʵÏÖÔ¶³ÌLinuxϵͳ¹ÜÀí¼¼ÇÉ
µãÔÞLinux£º×¿Ô½¿ªÔ´ÏµÍ³µÄÎÞÏÞ÷ÈÁ¦
LinuxÏÂPipµÄ°²×°°ü¹ÜÀí¹¤¾ßÏê½â
Xshell½Ì³Ì£ºÇáËɽøÈëÓû§¹ÜÀí½çÃæ
LinuxϵͳÏÂÇáËÉʶ±ðÁ¬½ÓÊÖ»ú¼¼ÇÉ