...
首页> 外文期刊>Digital investigation >A novel file carving algorithm for National Marine Electronics Association (NMEA) logs in GPS forensics
【24h】

A novel file carving algorithm for National Marine Electronics Association (NMEA) logs in GPS forensics

机译:美国国家海洋电子协会(NMEA)登录GPS取证的新型文件雕刻算法

获取原文
获取原文并翻译 | 示例
           

摘要

Globe positioning system (GPS) devices are an increasing importance source of evidence, as more of our devices have built-in GPS capabilities. In this paper, we propose a novel framework to efficiently recover National Marine Electronics Association (NMEA) logs and reconstruct GPS trajectories. Unlike existing approaches that require file system metadata, our proposed algorithm is designed based on the file carving technique without relying on system metadata. By understanding the characteristics and intrinsic structure of trajectory data in NMEA logs, we demonstrate how to pinpoint all data blocks belonging to the NMEA logs from the acquired forensic image of GPS device. Then, a discriminator is presented to determine whether two data blocks can be merged. And based on the discriminator, we design a reassembly algorithm to re-order and merge the obtained data blocks into new logs. In this context, deleted trajectories can be reconstructed by analyzing the recovered logs. Empirical experiments demonstrate that our proposed algorithm performs well when the system metadata is available/unavailable, log files are heavily fragmented, one or more parts of the log files are overwritten, and for different file systems of variable cluster sizes. (c) 2017 Elsevier Ltd. All rights reserved.
机译:随着我们越来越多的设备具有内置的GPS功能,全球定位系统(GPS)设备越来越重要。在本文中,我们提出了一个新颖的框架来有效地恢复美国国家海洋电子协会(NMEA)的日志并重建GPS轨迹。与现有的需要文件系统元数据的方法不同,我们提出的算法是基于文件雕刻技术设计的,而无需依赖系统元数据。通过了解NMEA日志中轨迹数据的特征和内在结构,我们演示了如何从所获取的GPS设备取证图像中查明属于NMEA日志的所有数据块。然后,提供鉴别器以确定两个数据块是否可以合并。并且基于鉴别器,我们设计了一种重组算法,以对获得的数据块进行重新排序并将其合并到新的日志中。在这种情况下,可以通过分析恢复的日志来重建删除的轨迹。经验实验表明,当系统元数据可用/不可用,日志文件严重碎片化,日志文件的一个或多个部分被覆盖以及群集大小可变的不同文件系统时,我们提出的算法性能良好。 (c)2017 Elsevier Ltd.保留所有权利。

著录项

  • 来源
    《Digital investigation》 |2017年第12期|11-21|共11页
  • 作者单位

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China|Hangzhou Dianzi Univ, Sch Cyberspace, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Cyberspace, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China;

    Hangzhou Dianzi Univ, Sch Comp Sci & Technol, Hangzhou, Zhejiang, Peoples R China;

    Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    GPS forensics; NMEA; Metadata-based recovery; File carving; Trajectory reconstruction;

    机译:GPS取证;NMEA;基于元数据的恢复;文件雕刻;轨迹重建;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号