Using Blockchain for Digital Evidence Preservation in Log Data

碩士 === 國立中興大學 === 資訊管理學系所 === 106 === Recently, the news of hackers hack into company’s network has been heard and the personal data protection law has been issued, which have made company pay attention to the field of digital forensics. In order to achieve the principle of absolute liability in per...

Full description

Bibliographic Details
Main Authors: Meng-Chiu Hsieh, 謝孟璆
Other Authors: Iuon-Chang Lin
Format: Others
Language:zh-TW
Published: 2018
Online Access:http://ndltd.ncl.edu.tw/handle/7b72ur
Description
Summary:碩士 === 國立中興大學 === 資訊管理學系所 === 106 === Recently, the news of hackers hack into company’s network has been heard and the personal data protection law has been issued, which have made company pay attention to the field of digital forensics. In order to achieve the principle of absolute liability in personal data protection law and be able to prove effectively after the event, the preservation of digital evidence is even more important. Also, the log data can be used as a track for tracking incidents, and it can prove behavior when a security incident happens. However, the log data can be easily modified, and it is hard to determine the integrity and original source of data. Therefore, it is more difficult for the judge to believe the admissibility of evidence and the probative value of evidence. In this study, we will aim at the need for company to preserve the digital evidence to develop a digital evidence preservation in log data. We use blockchain’s unmodifiable feature to store log data in blockchain distributed ledger, and use the consortium blockchain to design a blockchain, which contains one server peer and some company peers. The server peer controls peer’s permissions, and the company peers can store log data on the blockchain. When block is generated by mining peer, each peer will receive this block, thereby achieving the unmodifiable and consistency of log data. In the litigation, it can not only be used to prove the probative value of evidence, but also make the log data more powerful in admissibility of evidence. So that company can achieve the purpose of absolute liability and prove effectively after the event.