DocumentCode :
2510330
Title :
OleDetection Forensics and Anti-forensics of Steganography in OLE2-Formatted Documents
Author :
Erbacher, Robert F. ; Daniels, Jason ; Montiero, Steena
Author_Institution :
Comput. Sci. Dept., Utah State Univ., Logan, UT, USA
fYear :
2009
fDate :
21-21 May 2009
Firstpage :
85
Lastpage :
96
Abstract :
New and improved data hiding techniques pose a problem for forensic analysts investigating computer crime. Computer criminals are able to hide information using stego-channels available in commonly used document formats, thereby hindering an investigator from acquiring possibly important evidence. In this paper, we focus on detecting the use of stego-channels in the unused or dead space regions in the Object Linking and Embedding 2 (OLE2) specification used primarily by Microsoft´s Office. The OleDetection algorithm presented in this paper is focused on detecting the use of these stego-channels using a three-step process comprising the detection of dead regions in a document, the extraction of binary data and the generation of appropriate statistics using kurtosis and byte-frequency distribution, and the comparison of the calculated statistics with threshold values, which determines whether or not the document contains hidden data. This algorithm extends the work done by the StegOle algorithm. Our experimental results show that the OleDetection algorithm can correctly identify 99.97 percent of documents with previous stego-channel techniques with a false positive rate of only 0.65 percent. In addition, we present an anti-forensic technique wherein OLE2 documents can be modified to hide data with greater detection avoidance characteristics; thus reducing the accuracy of the current OleDetection implementation.
Keywords :
computer crime; formal specification; steganography; OLE2 specification; OLE2-formatted documents; Object Linking and Embedding 2; OleDetection algorithm; anti-forensics technique; computer crime investigation; data hiding techniques; forensics technique; steganography; Computer crime; Computer science; Conferences; Data encapsulation; Data engineering; Digital forensics; Joining processes; Object detection; Statistical distributions; Steganography; Anti-Forensics; Covert Channels; Forensics; OLE2; steganography;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering, 2009. SADFE '09. Fourth International IEEE Workshop on
Conference_Location :
Berkeley, CA
Print_ISBN :
978-0-7695-3792-4
Type :
conf
DOI :
10.1109/SADFE.2009.18
Filename :
5341560
Link To Document :
بازگشت