期刊文献+

基于文件结构的改进In-Place File Carving方法

Improved In-Place File Carving Method Based On File Structure
下载PDF
导出
摘要 针对现有文件雕复方法存在的文件恢复误报率较高的问题,提出基于文件结构的现场文件雕复方法。该方法在传统现场雕复方法的基础上,结合各类型文件的物理结构信息,利用通用框架对文件类型进行识别,并基于文件结构对所得文件进行筛选和恢复。实验结果表明,与现有雕复工具相比,该方法能够有效减少误报率,提升文件恢复效果。 In view of the problem of high file recovery false positive rate in the existing file carving method,this paper proposes an in-place file carving method based on file structure.Based on the traditional in-place file carving method,this method combines the physical structure information of each type of file,uses the general framework to identify the file type,and filters and restores the obtained file based on the file structure.The experimental results show that compared with the existing carving tools,this method can effectively reduce the false positive rate and improve the file recovery effect.
作者 杨忠信 张平 YANG Zhongxin;ZHANG Ping(Information Engineering University, Zhengzhou 450001, China)
机构地区 信息工程大学
出处 《信息工程大学学报》 2019年第5期576-581,596,共7页 Journal of Information Engineering University
关键词 现场文件雕复 数据恢复 文件结构 误报 in-place file carving data recovery file structure false positive
  • 相关文献

参考文献2

二级参考文献12

  • 1黄步根.数据恢复与计算机取证[J].计算机安全,2006(6):79-80. 被引量:19
  • 2Mark Russinovich,David A Solomon.Inside Microsoft Windows 2000[M].US:Microsoft Press,2004.
  • 3Richard Russon, Yuval Fledel. NTFS documentation [DB/OL]. http://www.linux-ntfs.org/content/view/104/43/.
  • 4Nikolai Bezroukov.Windows NTFS file system intemals[EB/ OL] .http://www.so ftpanorama.org/Intemals/Filesystems/ntfs. shtml.
  • 5Gary Nebbett.Windows NT/2000 native API reference[M].US: Sams,1999.
  • 6NTFS Research Group.Disk scan for deleted entries[DB/OL]. http://www.ntfs.com/disk-scan.htm.
  • 7Mikus N. An analysis of disc carving techniques [ D ]. Monterey: Naval Postgraduate School,2005.
  • 8Richard GGIII, Vassil Roussev. Scalpel: A frugal high performance file carver [ EB/OL]. http://www, dfrws, org/2005/ proceedings/richard_scalpel, pdf, 2005 - 01 - 01.
  • 9PhotoRec G P L. TeskDisk [ CP/DK]. http://www, cgsecurity, org/wiki/Main_Page, 2008 -01 -01.
  • 10Fu Z. Forensic investigation of OOXML format documents L J J. Digital Investigation, 2011, (8) : 48 -55.

共引文献34

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部