摘要
针对现有文件雕复方法存在的文件恢复误报率较高的问题,提出基于文件结构的现场文件雕复方法。该方法在传统现场雕复方法的基础上,结合各类型文件的物理结构信息,利用通用框架对文件类型进行识别,并基于文件结构对所得文件进行筛选和恢复。实验结果表明,与现有雕复工具相比,该方法能够有效减少误报率,提升文件恢复效果。
In view of the problem of high file recovery false positive rate in the existing file carving method,this paper proposes an in-place file carving method based on file structure.Based on the traditional in-place file carving method,this method combines the physical structure information of each type of file,uses the general framework to identify the file type,and filters and restores the obtained file based on the file structure.The experimental results show that compared with the existing carving tools,this method can effectively reduce the false positive rate and improve the file recovery effect.
作者
杨忠信
张平
YANG Zhongxin;ZHANG Ping(Information Engineering University, Zhengzhou 450001, China)
出处
《信息工程大学学报》
2019年第5期576-581,596,共7页
Journal of Information Engineering University
关键词
现场文件雕复
数据恢复
文件结构
误报
in-place file carving
data recovery
file structure
false positive