Chapter 1 CONTEXT - BASED FILE BLOCK CLASSIFICATION
نویسندگان
چکیده
In computer forensics, carving is an important trick in the digital investigator’s sleeve. Since files are typically stored as sequences of data blocks, the retrieval process basically consists of locating and appropriately collating together the original blocks of each file. Traditional file carving solutions, generally based on signatures of file headers and footers, could be improved by performing a classification of each data block in the storage media as belonging to a given file type. Unfortunately file block classification techniques tend to be far from perfect in terms of accuracy. For an improvement of the classification results the presence of compound files, i.e. files containing sub-portions that are encoded similarly to a different data type, must be taken into account during the classifier preparation. In this work, we demonstrate that this impacts heavily on the performance of file block classifiers. In addition, to generally improve the accuracy of classification, we propose a context-based classification architecture to improve block-by-block classification schemes, by exploiting the contiguity of file blocks belonging to the same file on storage media. The approach is completely general and can be easily applied to any content-based file block classification algorithm.
منابع مشابه
Chapter 5 CONTEXT - BASED FILE BLOCK CLASSIFICATION
Because files are typically stored as sequences of data blocks, the file carving process in digital forensics involves the identification and collocation of the original blocks of files. Current file carving techniques that use the signatures of file headers and footers could be improved by first classifying each data block in the storage media as belonging to a given file type. Unfortunately, ...
متن کاملIMU Based Tracking and Stabilization System
.............................................................................................................................................................. 5 Chapter 1: Introduction .................................................................................................................................... 5 Chapter 2: Requirements and Specification ......................................
متن کاملImproved Block Based Segmentation and Compression Techniques for Compound Images
Image compression is to minimize the size in bytes of a graphics file without degrading the quality of the image to an unacceptable level. The compound image compression normally based on three classification methods that is object based, layer based and block based. This paper presents two techniques under block-based classification. After a brief introduction of the classification methods, tw...
متن کاملGAMS Index for the NAG Parallel Library
C Elementary and special functions (search also class L5 ) C1 Integer-valued functions (e.g., factorial, binomial coefficient, permutations, combinations, floor, ceiling) C06GXFP Factorizes a positive integer n as n = n1 × n2. This routine may be used in conjunction with C06MCFP D Linear Algebra D1 Elementary vector and matrix operations D1a Elementary vector operations D1a1 Set to constant D1a...
متن کاملUsing Hints to Improve Inline Block-layer Deduplication
Block-layer data deduplication allows file systems and applications to reap the benefits of deduplication without requiring per-system or per-application modifications. However, important information about data context (e.g., data vs. metadata writes) is lost at the block layer. Passing such context to the block layer can help improve deduplication performance and reliability. We implemented a ...
متن کامل