DocumentCode
1616307
Title
Improving the Detection of Encrypted Data on Storage Devices
Author
Thurner, Simon ; Grun, Marcel ; Schmitt, Sven ; Baier, Harald
Author_Institution
Forensic Technol. Solutions PricewaterhouseCoopers, Frankfurt, Germany
fYear
2015
Firstpage
26
Lastpage
39
Abstract
The detection of persistently stored encrypted data plays an increasingly important role in digital forensics. This is especially true during live analysis of IT systems, when the encrypted data structures are temporarily decrypted in main memory and thus can be accessed as plaintext. One method commonly used to detect the presence of encrypted data on a storage device is the calculation of entropy. However, this method has a significant drawback: both random and compressed data have a very similar entropy compared to encrypted data, which yields a high false positive rate. That is why entropy is not very suitable to differentiate between these types of data.In this work we suggest both a workflow for detection of encrypted data structures on a storage device and an improved classification algorithm. The classification part of the workflow is based on statistical tests. For convenience of the investigator an important goal is to minimize the number of falsely classified unencrypted data structures (e.g. compressed data is classified as encrypted data). Our approach to achieve this goal is to combine different statistical tests. As a practical proof of concept we provide and evaluate a tool for automated analysis of storage devices that implements a multitude of statistical tests for improved detection of encrypted data, compared to both the application of only one such test and the calculation of entropy. More precisely our tool is able to reliably distinguish high-entropy file formats (i.e. DOCX, JPG, PDF, ZIP) from encrypted files (i.e. a truecrypt container).
Keywords
data structures; digital forensics; entropy; pattern classification; statistical testing; classification algorithm; digital forensics; encrypted data detection; encrypted data structures; high-entropy file formats; statistical tests; storage device; storage devices; Ciphers; Data structures; Encryption; Entropy; Generators; Reliability; digital forensics; encryption detection; entropy; statistical tests;
fLanguage
English
Publisher
ieee
Conference_Titel
IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
Conference_Location
Magdeburg
Print_ISBN
978-1-4799-9902-6
Type
conf
DOI
10.1109/IMF.2015.12
Filename
7195804
Link To Document