隨著資訊科技的興起與電腦時代的來臨,利用電腦以及網路犯罪的問題,讓執法單位面臨了更大的挑戰與困難,司法警察往往在扣押了犯罪者電腦主機證物之後,發現開機不了,便無法順利進入作業系統調查證據,但以目前電腦作業系統來看,以XP 作業系統佔有率最高,文本研究提出XP Live CD 整合電腦鑑識工具,建置實驗環境並分析鑑識工具與電腦犯罪使用時機。在使用光碟開機所建立的獨立性作業系統下,不更動電腦系統硬體狀態,間接隔絕電腦主硬碟開機所帶來電腦病毒侵害的可能,避免破壞鑑識檔案所採集數位證據的完整性。分析過程中,產生的電腦犯罪相關癥結,相信能讓鑑識人員於擷取數位證據上趨於完善,在法庭呈現上的證據多一分效力。
With the rise of information technology and the advent of the computer era, the Internet related crimes have risen drastically and the law enforcement agencies face greater challenges and difficulties in collecting digital evidences; often time the investigators failed to boot up the perpetrator's computers to gather digital evidences; since Window XP is widely used operating system, this paper focus on the XP live CD; setup an experimental environment, and applies the XP Live CD integrated computer forensics tools to selected cases. The use of CD-ROM start-up establishes an independent operating system environment without changing the computer hardware, insolates the computer hard drive to avoid the potential computer virus attack, and maintains the integrity of digital evidences to be collected by forensics officers; thus improves the chance at the court when the evidences are presented.