...
首页> 外文期刊>Digital investigation >Forensic investigation of OOXML format documents
【24h】

Forensic investigation of OOXML format documents

机译:OOXML格式文档的法医调查

获取原文
获取原文并翻译 | 示例
           

摘要

MS Office documents could be illegally copied by offenders, and forensic investigators still face great difficulty in investigating and tracking the source of these illegal copies. This paper mainly proposes a forensic method based on the unique value of the revision identifier (RI) to determine the source of suspicious electronic documents. This method applies to electronic documents which use Office Open XML (OOXML) format, such as MS Office 2007, Mac Office 2008 and MS Office 2010. According to the uniqueness of the RI extracted from documents, forensic investigators can determine whether the suspicious document and another document are from the same source. Experiments demonstrate that, for a copy of an electronic document, even if all the original characters are deleted or formatted by attackers, forensic examiners can determine that the copy and the original document are from the same source through detecting the RI values. Additionally, the same holds true if attackers just copy some characters from the original document to a newly created document. As long as there is one character left whose original format has not been cleared, forensic examiners can determine that the two documents are from the same source using the same method. This paper also presents methods for OOXML format files to detect the time information and creator information, which can be used to determine who the real copyright holder is when a copyright dispute occurs.
机译:犯罪分子可能会非法复制MS Office文档,法医调查人员在调查和跟踪这些非法副本的来源方面仍然面临很大的困难。本文主要提出一种基于修订标识符(RI)唯一值的取证方法,以确定可疑电子文档的来源。此方法适用于使用Office Open XML(OOXML)格式的电子文档,例如MS Office 2007,Mac Office 2008和MS Office2010。根据从文档中提取的RI的唯一性,法医研究人员可以确定可疑文档和另一个文档来自同一来源。实验表明,对于电子文档的副本,即使所有原始字符都已被攻击者删除或格式化,法医检查人员也可以通过检测RI值来确定该副本和原始文档来自同一来源。此外,如果攻击者仅将某些字符从原始文档复制到新创建的文档中,这同样适用。只要剩下一个字符,其原始格式尚未清除,法医检查员就可以使用相同的方法确定这两个文档来自同一来源。本文还介绍了OOXML格式文件检测时间信息和创建者信息的方法,这些方法可用于确定发生版权纠纷时真正的版权所有者是谁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号