【24h】

A New Approach to Multimedia Files Carving

机译:多媒体文件雕刻的新方法

获取原文

摘要

Traditional file recovery methods rely on file system information, which are ineffective when file system information isn't available. File carving is a file recovery method that recovers files according to their structure and content without file system information, which is widely used in digital forensics. As the important carriers of digital information, multimedia files are important digital evidence. In this paper, a new multimedia file carving approach is proposed to improve the recovery accuracy of high entropy file fragments. The fragmented files can be recovered by a hierarchical carving process, including file header identification via entropy, file fragment type classification, and file reassembly via parallel unique path approach. A new file type classification method is constructed based on support vector machine, by using the features of BFD (byte frequency distribution) and ROC (rate of change). Four different datasets, such as DFRWS 2006/2007 challenge datasets, dataset simulating actual disk, dataset with randomly disordered fragments, and dataset with biomedical images, are employed in our experiments. The results show that JPEG recovery accuracy is improved greatly compared with that of Photo Rec tool. Our method performs best in the situation where the order of fragments is completely confusing.
机译:传统的文件恢复方法依赖于文件系统信息,当文件系统信息不可用时无效。文件雕刻是一种文件恢复方法,可根据其结构和内容恢复文件,而无需文件系统信息,这些方法被广泛用于数字取证。作为数字信息的重要运营商,多媒体文件是重要的数字证据。本文提出了一种新的多媒体文件雕刻方法,提高了高熵文件片段的恢复精度。分段文件可以通过分层雕刻过程恢复,包括通过熵,文件片段类型分类和文件通过并行唯一路径方法重组文件头标识。通过使用BFD(字节频率分布)和ROC(变化率)的特征,基于支持向量机构建新的文件类型分类方法。在我们的实验中采用四个不同的数据集,例如DFRWS 2006/2007挑战数据集,数据集,模拟实际磁盘,与随机紊乱的片段的数据集,以及具有生物医学图像的数据集。结果表明,与照片REC工具相比,JPEG恢复精度得到了改善。我们的方法在碎片顺序完全混淆的情况下表现最佳。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号