首页> 外文会议>International conference on control, instrumentation, communication and computational technologies >An automated forensic tool for image metadata and Windows 7 Recycle Bin
【24h】

An automated forensic tool for image metadata and Windows 7 Recycle Bin

机译:用于图像元数据和Windows 7回收站的自动取证工具

获取原文

摘要

Different tools are used to aid the investigation process. Many commercial and open source forensic tools are available but most of them have little way of shaping data in way meaningful to investigator. In this paper we have proposed a python based tool which will have two separate functionalities. One of the functionality which we are calling as PhotoLocator will automate the complete process of image metadata analysis, extracting coordinates information from metadata and locating the image geographically using Google Earth & KML (Keyhole markup language). It will also be capable of locating multiple images simultaneously along with thumbnail of images on Google Earth for which sample results are presented. Other functionality will provide forensics for Windows 7 Recycle Bin. Analysis of deleted files often provides useful information for the forensic computer examiner. To know where to find the deleted files, and how to understand the metadata associated with the file's deletion, make up the backbone of a successful forensic computer examination. This functionality will provide a CSV file of all the files and related metadata for each user recycle bin.
机译:使用了不同的工具来辅助调查过程。可以使用许多商业和开源取证工具,但大多数工具几乎没有以对研究者有意义的方式来整形数据。在本文中,我们提出了一个基于python的工具,该工具将具有两个单独的功能。我们称为PhotoLocator的功能之一将自动完成图像元数据分析的整个过程,从元数据中提取坐标信息,并使用Google Earth&KML(Keyhole标记语言)在地理上定位图像。它还将能够同时定位多张图片以及Google地球上显示了示例结果的图片的缩略图。其他功能将为Windows 7回收站提供取证。分析删除的文件通常为法医检查员提供有用的信息。要知道在哪里可以找到已删除的文件,以及如何理解与该文件的删除相关的元数据,请组成成功的法医计算机检查的基础。此功能将为每个用户回收站提供所有文件的CSV文件和相关元数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号