MetaFor: Metadata Signatures for Automated Remote File Identification in Forensic Investigations
نویسندگان
چکیده
The increased use of the Internet to store data ensures that it provides a valuable resource for a forensics examiner during an investigation. Of particular interest is evidence related to the dissemination of indecent images of children that are spread via social networking sites and Web fora. This paper posits a novel approach, MetaFor, which using a Web crawler searches for metadata signatures for automated identification of files residing on remote Web servers. In this way, it may identify potential repositories of illegal images or sources of evidence related to traditional crimes, such as utilising geo-location metadata to identify digital pictures taken during a crime in progress. This approach differs from other forensic signature schemes in that it utilises JPEG header metadata rather than image or file data as the basis of a signature. In this way, MetaFor can be extended to search for unknown files that may be relevant to an investigation. In order to demonstrate the applicability of the approach, this paper applies the approach to a case study of two Web servers and presents the results.
منابع مشابه
Analyzing registry, log files, and prefetch files in finding digital evidence in graphic design applications
The products of graphic design applications leave behind traces of digital information which can be used during a digital forensic investigation in cases where counterfeit documents have been created. This paper analyzes the digital forensics involved in the creation of counterfeit documents. This is achieved by first recognizing the digital forensic artifacts left behind from the use of graphi...
متن کاملUnique file identification in the National Software Reference Library
The National Software Reference Library (NSRL) provides a repository of known software, file profiles, and file signatures for use by law enforcement and other organizations involved with computer forensic investigations. The NSRL is comprised of three major elements: 1. A physical library of commercial software packages. 2. A database of information about each file within each software package...
متن کاملOn the role of file system metadata in digital forensics
Most of the effort in today’s digital forensics community lies in the retrieval and analysis of existing information from computing systems. Little is being done to increase the quantity and quality of the forensic information on today’s computing systems. In this paper we pose the question of what kind of information is desired on a system by a forensic investigator. We give an overview of the...
متن کاملNDNFS: An NDN-friendly File System
NDNFS is a file system designed for Named Data Networking (NDN) and supports efficient data access by both local and remote applications. It provides the standard file system interface for local file operations, but stores files internally as NDN Data packets, which can be directly sent out as responses to the incoming Interests, saving the overhead of encoding the packets and generating signat...
متن کاملFORSIGS: Forensic Signature Analysis of the Hard Drive for Multimedia File Fingerprints
Computer forensics is emerging as an important tool in the fight against crime. Increasingly, computers are being used to facilitate new criminal activity, or used in the commission of existing crimes. The networked world has seen increases in, and the volume of, information that may be shared amongst hosts. This has given rise to major concerns over paedophile activity, and in particular the s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013