首页> 外国专利> Forensic analysis method and system for document files

Forensic analysis method and system for document files

机译:证件的取证分析方法及系统

摘要

The present invention relates to a forensic analysis method and a system for document files. The forensic analysis method comprises the following steps: a file receiving step receiving a file which is an object to be forensically analyzed; a file area checking step checking if there is a normal area or an unassigned area in the received file; a file searching step searching a compound document file in the normal or unassigned areas; a verifying step verifying the compound document file; and a data restoring step restoring data in the unassigned area of the compound document file. The forensic analysis method and system for document file can restore data stored in a damaged compound document file or an unassigned area of a damaged compound document file in which data is not assigned. [Reference numerals] (AA) Start; (BB) Receiving a file for performing forensic analysis; (CC) Mounted storage device; (DD) File/directory; (EE) Dump file in the unassigned area of a file; (FF) End; (S121) Kind of the file?; (S122) Analyzing a file system for determining into a normal area or the unassigned area; (S123) Received file is determined to be at the unassigned area; (S124) Received file is determined to be at the normal area; (S130) Searching a compound document file present in the normal area or unassigned area of the file; (S140) Validation for the searched compound document file is performed; (S150) Restoring of data in the unassigned area of the compound document file
机译:本发明涉及一种用于文件文件的法证分析方法和系统。取证分析方法包括以下步骤:文件接收步骤,接收作为要取证分析的对象的文件;以及文件区域检查步骤,检查接收到的文件中是否存在正常区域或未分配区域;文件搜索步骤在普通或未分配区域中搜索复合文档文件;验证步骤,对复合文档文件进行验证;数据还原步骤,用于还原复合文档文件的未分配区域中的数据。用于文档文件的法医分析方法和系统可以恢复存储在损坏的复合文档文件中或未分配数据的损坏的复合文档文件的未分配区域中的数据。 [参考数字](AA)开始; (BB)接收进行法医分析的文件; (CC)已安装的存储设备; (DD)文件/目录; (EE)将文件转储到文件的未分配区域中; (FF)结束; (S121)文件的种类? (S122)分析文件系统以确定是正常区域还是未分配区域; (S123)确定接收到的文件在未分配区域中; (S124)确定接收到的文件在正常区域; (S130)搜索存在于文件的正常区域或未分配区域中的复合文档文件; (S140)对搜索到的复合文档文件进行验证; (S150)恢复复合文档文件的未分配区域中的数据

著录项

  • 公开/公告号KR101374239B1

    专利类型

  • 公开/公告日2014-03-13

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20120067113

  • 申请日2012-06-22

  • 分类号G06F17;G06F17/30;G06F17/21;

  • 国家 KR

  • 入库时间 2022-08-21 15:41:19

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号