DocumentCode :
1616307
Title :
Improving the Detection of Encrypted Data on Storage Devices
Author :
Thurner, Simon ; Grun, Marcel ; Schmitt, Sven ; Baier, Harald
Author_Institution :
Forensic Technol. Solutions PricewaterhouseCoopers, Frankfurt, Germany
fYear :
2015
Firstpage :
26
Lastpage :
39
Abstract :
The detection of persistently stored encrypted data plays an increasingly important role in digital forensics. This is especially true during live analysis of IT systems, when the encrypted data structures are temporarily decrypted in main memory and thus can be accessed as plaintext. One method commonly used to detect the presence of encrypted data on a storage device is the calculation of entropy. However, this method has a significant drawback: both random and compressed data have a very similar entropy compared to encrypted data, which yields a high false positive rate. That is why entropy is not very suitable to differentiate between these types of data.In this work we suggest both a workflow for detection of encrypted data structures on a storage device and an improved classification algorithm. The classification part of the workflow is based on statistical tests. For convenience of the investigator an important goal is to minimize the number of falsely classified unencrypted data structures (e.g. compressed data is classified as encrypted data). Our approach to achieve this goal is to combine different statistical tests. As a practical proof of concept we provide and evaluate a tool for automated analysis of storage devices that implements a multitude of statistical tests for improved detection of encrypted data, compared to both the application of only one such test and the calculation of entropy. More precisely our tool is able to reliably distinguish high-entropy file formats (i.e. DOCX, JPG, PDF, ZIP) from encrypted files (i.e. a truecrypt container).
Keywords :
data structures; digital forensics; entropy; pattern classification; statistical testing; classification algorithm; digital forensics; encrypted data detection; encrypted data structures; high-entropy file formats; statistical tests; storage device; storage devices; Ciphers; Data structures; Encryption; Entropy; Generators; Reliability; digital forensics; encryption detection; entropy; statistical tests;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
IT Security Incident Management & IT Forensics (IMF), 2015 Ninth International Conference on
Conference_Location :
Magdeburg
Print_ISBN :
978-1-4799-9902-6
Type :
conf
DOI :
10.1109/IMF.2015.12
Filename :
7195804
Link To Document :
بازگشت