期刊文献+

一种基于内容特征的Word文件雕复方法 被引量:3

A WORD FILE CARVING METHOD BASED ON CONTENT CHARACTER
下载PDF
导出
摘要 提出一种不依赖于文件系统元信息,而凭借于文件数据内容及其内部结构特征的Word文件雕复方法,其基本原理是利用文件头/根存储/最大扇区、分片文件的扇区分配表和分片文件的数据流等验证方法。此雕复方法能自动雕复在原始磁盘镜像中连续和分片有序存储的Word文件。实验结果表明该方法可以在Word文件自动雕复的高准确率情况下,确保低"误报"率。 This paper presents a Word File carving method based on file's content and the character of its internal structure but not depend on the metadata of file system.Its basic theory is to make use of header/root storage/max sector validation,SAT of the fragmented file validation and data stream of the fragment file validation.This carving method can carve automatically the contiguous Word files and the fragmented Word files stored in-order in original disc mirroring.Experiments show that the method can ensure lower "false positive" rate while the Word files are carved automatically with a high accuracy.
出处 《计算机应用与软件》 CSCD 2010年第1期100-102,126,共4页 Computer Applications and Software
基金 浙江省自然科学基金项目(Y106176) 浙江省科技计划项目(2007C33058)
关键词 文件雕复 内容特征 WORD文件 File carving Content character Word file
  • 相关文献

参考文献12

  • 1Golden G Richard III, Vassil Roussev. Scalpel : A frugal, high performance file carver[ C]//Proceedings of the 2005 Digital Forensic Research Workshop. New Orleans, LA,2005,.
  • 2Nicholas Mikus. An analysis of disc carving techniques [ D ]. Monterey : Naval Postgraduate School ,2005.
  • 3Simson L Garfinkel. Carving contiguous and fragmented files with fast object validation [ J ]. Digital Investigation, 2007,4 ( supplement 1 ) : 2 -12.
  • 4Joachim Metz, Rober-Jan Mora. Analysis of 2006 DFRWS forensic carving challenge [ EB/OL ]. ( 2007 - 3 - 21 ). http ://sandbox. dfrws, org/ 2006/ mora/dfrws2006, pdf.
  • 5Joachim Metz, Bas Kloet, Robert-Jan Mora. Analysis of 2007 DFRWS forensic carving challenge [ EB/OL ]. ( 2007 - 8 - 28 ). http ://sandbox. dfrws, org/2OO7/metz/dfrws20OT_carving_challenge, pdf.
  • 6Glenn Henderson, David Horvath, Jeff Jones. Submission for the 2006 DFRWS Forensics Challenge [ EB/OL]. ( 2007 - 3 - 21 ). http:// sandbox, dfrws, org/2006/buchholz/jmu-writeup, pdf.
  • 7Hyukdon Kwon, Yeog Kim, Sangjin Lee. A Tool for the detection of hid- den data in Microsoft compound document file format [ C ]//ICISS 2005 : proceedings of the 2008 International Conference on Information Science and Security. Washington. DC, USA,2008.
  • 8Daniel Rentz. OpenOffice. org's documentation of the Microsoft compound document [ EB/OL]. ( 2007 - 8 - 7 ). http://sc, openoffice. org/compdocfileformat, pdf.
  • 9Haiying Luan, Simon Mackey. Entropy analysis [ EB/OL]. (2006 - 4 - 21 ). http ://polya. computing, dcu. ie/wiki/index. php/Entropy_Analysis.
  • 10Shannon C E. A mathematical theory of communication [J]. Bell System Teehnieal Journal, 1948,27 : 379 - 423,623 - 656.

同被引文献17

引证文献3

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部