Title :
SÁDI - Statistical Analysis for Data Type Identification
Author :
Moody, Sarah J. ; Erbacher, Robert F.
Author_Institution :
Dept. of Comput. Sci., Utah State Univ., Logan, UT
Abstract :
A key task in digital forensic analysis is the location of relevant information within the computer system. Identification of the relevancy of data is often dependent upon the identification of the type of data being examined. Typical file type identification is based upon file extension or magic keys. These typical techniques fail in many typical forensic analysis scenarios such as needing to deal with embedded data, such as with Microsoft Word files, or file fragments. The SADI (Statistical Analysis Data Identification) technique applies statistical analysis of the byte values of the data in such a way that the accuracy of the technique does not rely on the potentially misleading metadata information but rather the values of the data itself. The development of SADI provides the capability to identify what digitally stored data actually represents and will also allow for the selective extraction of portions of the data for additional investigation; i.e., in the case of embedded data. Thus, our research provides a more effective type identification technique that does not fail on file fragments, embedded data types, or with obfuscated data.
Keywords :
criminal law; data structures; statistical analysis; Microsoft Word files; computer system; data byte value; data relevancy; data type identification; digital forensic analysis; digitally stored data; embedded data; file extension; file fragments; file type identification; magic keys; metadata information; obfuscated data; relevant information location; selective data portion extraction; statistical analysis; Computer science; Data encapsulation; Data engineering; Data mining; Digital forensics; Failure analysis; Information analysis; Information retrieval; Operating systems; Statistical analysis; Data type identification; Digital Forensics;
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering, 2008. SADFE '08. Third International Workshop on
Conference_Location :
Oakland, CA
Print_ISBN :
978-0-7695-3171-7
DOI :
10.1109/SADFE.2008.13