| Computer forensics as a primary means of combating computer crime cases playsan important role in maintaining stability of social and protecting the onlineenvironment, and it is an important guarantee for information security. However, nowcomputer forensics is facing many challenges, such as explosive grow of the data,growth of computer crime levels, the credibility of the reasoning conclusion, whichhave become increasingly prominent problem. Electronic data due to its characteristics-variability, makes the process of capturing the electronic evidence facing to manythreats, which are include covering the evidence, distorting the evidence, deleting theevidence, destructing of the storage media and so on, and at the same time as thefurther development of anti-forensics technology makes the tool of the electronicevidence encountering a more serious issues. The obtaining electronic evidence is notconvincing.The credibility of e-forensics is the most important prerequisite of computerforensics and the basis of analyzing the evidence; however, we only focus on theacquisition of electronic evidence, while ignoring the credibility of the obtainedelectronic evidence. The analysis of the evidence is mostly done by hand, that is lowefficiency and the higher probability of operational errors. Based on these problems,this paper makes the trusted computer forensics model as a starting point todetailedlydiscuss the discovery of electronic evidence, the evidence acquisition process,the safety of the fixed data, electronic data acquisition, analysis of the evidence andother reliability problems in various stages, and analyze the influence of the electronicevidence because of the tools of collecting evidence and the method of the evidencecollection from the perspective of the internal structure of the disk data storage,combining with knowledge of probability theory gives a quantitative evaluation, andfinally the finite state automata with time constraints on the handling of the evidenceformal analysis of electronic evidence for further scientific method, formal evidentiaryreasoning method is more standardized.To sum up, the main research work and the chapters are organized as follows:(1) Understand the forefront of the domestic and international on the field ofcomputer forensics.(2) Analyze of the common computer forensics models. (3) Introduce the work of each stage in a trusted computer forensics model.(4) Analyze of the data storage of the physical memory, the accessing of theimage file and the tools of analyzing the image file.(5) Understand the probability theory preparing for analyzing the credible ofcomputer evidence.(6) Specific assesses the probability of influence from the data collecting toolsand memory changes to the electronic evidence.(7) Finite state automata with constraints of the time factor used to formalreasoning the process of computer forensics. |