DocumentCode :
2234704
Title :
File Type Identification of Data Fragments by Their Binary Structure
Author :
Karresand, Martin ; Shahmehri, Nahid
Author_Institution :
Dept. of Comput. & Inf. Sci., Linkoping Univ.
fYear :
2006
fDate :
21-23 June 2006
Firstpage :
140
Lastpage :
147
Abstract :
Rapidly gaining information superiority is vital when fighting an enemy, but current computer forensics tools, which require file headers or a working file system to function, do not enable us to quickly map out the contents of corrupted hard disks or other fragmented storage media found at crime scenes. The lack of proper tools slows down the hunt for information, which would otherwise help in gaining the upper hand against IT based perpetrators. To address this problem, this paper presents an algorithm which allows categorization of data fragments based solely on their structure, without the need for any meta data. The algorithm is based on measuring the rate of change of the byte contents of digital media and extends the byte frequency distribution based Oscar method presented in an earlier paper. The evaluation of the new method shows a detection rate of 99.2 %, without generating any false positives, when used to scan for JPEG data. The slowest implementation of the algorithm scans a 72.2 MB file in approximately 2.5 seconds and scales linearly
Keywords :
police data processing; JPEG data; Oscar method; binary structure; byte frequency distribution; computer forensics tools; data categorization; data fragments; file type identification; working file system; Computer crime; Computer hacking; Computer networks; Data mining; File systems; Forensics; Hard disks; Information science; Military computing; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance Workshop, 2006 IEEE
Conference_Location :
West Point, NY
Print_ISBN :
1-4244-0130-5
Type :
conf
DOI :
10.1109/IAW.2006.1652088
Filename :
1652088
Link To Document :
بازگشت