• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Guo, Jun (Guo, Jun.) | He, Jingsha (He, Jingsha.) (Scholars:何泾沙) | Huang, Na (Huang, Na.)

Indexed by:

CPCI-S

Abstract:

File carving is a technique of recovering data from disk without depending on the File System, and the key step is the extraction and reassembly of file fragments. Efficient recognition and extraction of file fragments is not only the prerequisite of recovering file, but also the guarantee of a low false positive rate and high accuracy Digital Forensics. In this paper, when the entropy of file fragments is low, the validation algorithms I used for the extraction are header/footer validation and entropy feature extraction validation, but when the entropy of file fragments is high, besides the previous two algorithms I introduced Bloom filter feature extraction validation, byte frequency distribution (BFD) feature extraction validation and support vector machine (SVM) with supervised learning ability to detect the type of file fragments. After the extraction, I used Parallel Unique Path (PUP) for the reassembly of file fragments. I used DFRWS 2007 carving challenge data set to test my method and the result is better than only using entropy to classify multiple-type files especially in the case of high entropy.

Keyword:

PUP Entropy File Carving File Fragments Bloom filter SVM BFD

Author Community:

  • [ 1 ] [Guo, Jun]Beijing Univ Technol, Dept Software Engn, Beijing 100124, Peoples R China
  • [ 2 ] [He, Jingsha]Beijing Univ Technol, Dept Software Engn, America 100124, Peoples R China

Reprint Author's Address:

  • 何泾沙

    [Guo, Jun]Beijing Univ Technol, Dept Software Engn, Beijing 100124, Peoples R China;;[He, Jingsha]Beijing Univ Technol, Dept Software Engn, America 100124, Peoples R China

Show more details

Related Keywords:

Related Article:

Source :

PROCEEDINGS OF THE 2015 4TH NATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS AND COMPUTER ENGINEERING ( NCEECE 2015)

ISSN: 2352-5401

Year: 2016

Volume: 47

Page: 521-528

Language: English

Cited Count:

WoS CC Cited Count: 0

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 1

Online/Total:1214/10990524
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.