期刊文献+

浅析“信息熵”在电子数据取证领域中的应用 被引量:1

Entropy Applied in the Field of Digital Forensics
下载PDF
导出
摘要 本文介绍"信息熵(entropy)"的重要价值及其在电子数据取证领域的应用。"信息熵"可用于未知加密类型文件、应用信息隐藏技术的文件、未知恶意代码及网络中加密或可疑通信数据的发现与分析、磁盘阵列(RAID)重组分析等。"信息熵"已成为电子数据取证领域对抗反取证技术的有力武器,它在未来的电子数据取证领域将发挥日益重要的作用,得到更为广泛的应用。 This paper describes the important value of entropy and its application in the field of digital forensics.Entropy is applicable to detect known and unknown encrypted file,files with hidden data,unknown malware,encrypted data or malware variants in the network traffic and analyze information of RAID array intelligently to get the order of disks which make up the array.Entropy becomes one of key weapons to defeat anti-forensic tools and will also play more and more important role in the field of digital forensics.
出处 《电信科学》 北大核心 2010年第S2期124-128,共5页 Telecommunications Science
关键词 取证 反取证 加密 恶意代码 RAID entropy,forensics,anti-forensic,encryption,RAID
  • 相关文献

参考文献9

  • 1http://www.google.com.hk/ggblog/googlechinablog/2006/04/4_1731.html .
  • 2Shannon M M.Forensic relative strength scoring-ASCII andentropy scoring[]..
  • 3Shawn McCreight.Guidance software,cyber security lab-entropy[].Computer and Enterprise Investigations Conference.2010
  • 4Simson Garfinkel.Anti-forensics:techniques,detection andcountermeasures[]..
  • 5.Automated mapping of large binary objects using primitivefragment type classification[].Digital Investigation.2010
  • 6M Zubair Shafiq,Syeda Momina Tabish,Muddassar Farooq.Embedded malware detection using Markovian statistical modelof benign files[]..2008
  • 7Runtime.RAID Reconstructor Help. http://www.runtime.org .
  • 8.Data Analysis in WinHex[]..
  • 9Shannon Claude E,Warren Weaver.The mathematical theory of communication[]..1963

同被引文献5

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部