DocumentCode
3610185
Title
Digital forensics of Microsoft Office 2007???2013 documents to prevent covert communication
Author
Zhangjie Fu ; Xingming Sun ; Jie Xi
Author_Institution
Coll. of Comput. & Software, Nanjing Univ. of Inf. Sci. & Technol., Nanjing, China
Volume
17
Issue
5
fYear
2015
Firstpage
525
Lastpage
533
Abstract
MS Office suit software is the most widely used electronic documents by a large number of users in the world, which has absolute predominance in office software market. MS Office 2007-2013 documents, which use new office open extensible markup language (OOXML) format, could be illegally used as cover mediums to transmit secret information by offenders, because they do not easily arouse others suspicion. This paper proposes nine forensic methods and an integrated forensic tool for OOXML format documents on the basis of researching the potential information hiding methods. The proposed forensic methods and tool cover three categories; document structure, document content, and document format. The aim is to prevent covert communication and provide security detection technology for electronic documents downloaded by users. The proposed methods can prevent the damage of secret information embedded by offenders. Extensive experiments based on real data set demonstrate the effectiveness of the proposed methods.
Keywords
digital forensics; document handling; MS Office suit software; Microsoft Office 2007-2013 document; OOXML format document; digital forensics; electronic documents; integrated forensic tool; office open extensible markup language format; security detection technology; software market; Compounds; Compression algorithms; Data mining; Digital forensics; Metadata; XML; Covert communication; Microsoft Office 2007???2013; OOXML format; digital forensics; security;
fLanguage
English
Journal_Title
Communications and Networks, Journal of
Publisher
ieee
ISSN
1229-2370
Type
jour
DOI
10.1109/JCN.2015.000091
Filename
7324152
Link To Document