首页> 外文会议>Systematic Approaches to Digital Forensic Engineering, 2009. SADFE '09 >File Fragment Classification-The Case for Specialized Approaches
【24h】

File Fragment Classification-The Case for Specialized Approaches

机译:文件碎片分类-专业方法案例

获取原文

摘要

Increasingly advances in file carving, memory analysis and network forensics requires the ability to identify the underlying type of a file given only a file fragment. Work to date on this problem has relied on identification of specific byte sequences in file headers and footers, and the use of statistical analysis and machine learning algorithms taken from the middle of the file. We argue that these approaches are fundamentally flawed because they fail to consider the inherent internal structure in widely used file types such as PDF, DOC, and ZIP. We support our argument with a bottom-up examination of some popular formats and an analysis of TK PDF files. Based on our analysis, we argue that specialized methods targeted to each specific file type will be necessary to make progress in this area.
机译:在文件雕刻,内存分析和网络取证方面,日渐发展的技术要求仅给出文件片段即可识别文件的基础类型。迄今为止,针对此问题的工作依赖于在文件页眉和页脚中特定字节序列的标识,以及使用从文件中间获取的统计分析和机器学习算法。我们认为这些方法从根本上来说是有缺陷的,因为它们没有考虑广泛使用的文件类型(例如PDF,DOC和ZIP)中的固有内部结构。我们通过对某些流行格式的自下而上的检查以及对TK PDF文件的分析来支持我们的论点。根据我们的分析,我们认为针对每种特定文件类型的专门方法对于在此领域取得进展将是必要的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号