首页> 外文会议>International Conference on Future Information Technology >The Study on the Detection of the Damaged File Using the Graph of the Information Entropy for File Trust Management
【24h】

The Study on the Detection of the Damaged File Using the Graph of the Information Entropy for File Trust Management

机译:使用信息熵图进行文件信任管理的图表检测损坏文件的研究

获取原文

摘要

Information entropy refers to the complexity of information included in set of data in a mathematical way. Entropy is now usually used for the classification of files or detection and analysis of malicious code. Information entropy graph shows the probability of occurrence of each information included in set of data using information entropy. Each Well Known File has different entropy and each file can be sorted using this. When it comes to binary file, however, different files can have the same entropy values so there is error possibility. Thus, the identification of files for the least errors can be possible when using entropy and graph patters. In the forensic analysis process, detections of hidden and tampered files are handled. With existing forensic method, the extensions of header and footer of tampered files are not automatically detected. When the other functions such as calculation and comparison of graphs are added, accuracy of experiment is increased in the forensic process. In this study, we proved that different files but have the same entropy values are assorted with the information entropy graphs. The information entropy graphs of Well Known Files showed the meaningful patterns for analysis and detection. When it comes to the damaged file header, footer, and even body, they sustained the same graph patterns even though they showed different entropy values.
机译:信息熵是指以数学方式在数据集中包含的信息的复杂性。熵通常用于分类文件或检测和分析恶意代码。信息熵图显示了使用信息熵在数据集中包含的每个信息的发生概率。每个众所周知的文件都有不同的熵,可以使用此文件进行排序。但是,涉及二进制文件时,不同的文件可以具有相同的熵值,因此存在错误。因此,当使用熵和图形图案时,可以实现最少错误的文件的识别。在取消分析过程中,处理隐藏和篡改文件的检测。使用现有的法医方法,不会自动检测篡改文件的标题和页脚的扩展。当添加其他功能之类的诸如图形的计算和比较时,法医过程中的实验精度增加。在这项研究中,我们证明了不同的文件,但具有相同的熵值与信息熵图分类。众所周知的文件的信息熵图显示了分析和检测的有意义模式。当涉及损坏的文件头,页脚甚至正文时,即使它们显示出不同的熵值,它们也持续了相同的图形模式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号