首页> 外文学位 >Forensic and anti-forensic techniques for Object Linking and Embedding 2 (OLE2)-formatted documents.
【24h】

Forensic and anti-forensic techniques for Object Linking and Embedding 2 (OLE2)-formatted documents.

机译:对象链接和嵌入2(OLE2)格式文档的取证和反取证技术。

获取原文
获取原文并翻译 | 示例

摘要

Common office documents provide significant opportunity for forensic and anti-forensic work. The Object Linking and Embedding 2 (OLE2) specification used primarily by Microsoft's Office Suite contains unused or dead space regions that can be over written to hide covert channels of communication. This thesis describes a technique to detect those covert channels and also describes a different method of encoding that lowers the probability of detection.;The algorithm developed, called OleDetection, is based on the use of kurtosis and byte frequency distribution statistics to accurately identify OLE2 documents with covert channels. OleDetection is able to correctly identify 99.97 percent of documents with covert channel and only a false positive rate 0.65 percent.;The improved encoding scheme encodes the covert channel with patterns found in unmodified dead space regions. This anti-forensic technique allows the covert channel to masquerade as normal data, lowering the ability probability for any detection tool to is able to detect its presence.
机译:通用办公文件为法医和反法医工作提供了重要的机会。 Microsoft的Office Suite主要使用的对象链接和嵌入2(OLE2)规范包含未使用或无效的区域,这些区域可以被覆盖以隐藏通信的秘密通道。本文描述了一种检测那些隐蔽通道的技术,还描述了一种降低检测概率的不同编码方法。该算法被称为OleDetection,该算法基于峰度和字节频率分布统计信息的使用来准确识别OLE2文档带有暗道。 OleDetection能够正确识别具有隐秘通道的99.97%的文档,而误报率仅为0.65%。这种反取证技术允许隐蔽通道伪装成正常数据,从而降低了任何检测工具能够检测其存在的能力概率。

著录项

  • 作者

    Daniels, Jason.;

  • 作者单位

    Utah State University.;

  • 授予单位 Utah State University.;
  • 学科 Computer Science.
  • 学位 M.S.
  • 年度 2008
  • 页码 74 p.
  • 总页数 74
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号