Digital Investigation Using Hash- Based Carving
نویسندگان
چکیده
File carving is a popular method used for digital investigations for detecting the presence of specific target files on digital media. Hash based sector hashing helps to identify the presence of a target file. The hashes of physical sectors of the media is compared to the database of hashes created by hashing every block of the target files. To enable this, instead of evaluating the hashes of entire files, the hashes of individual data blocks is used for evaluation. Hash-based carving helps to identify fragmented files, files that are incomplete or that have been partially modified. To address the problem of High false identification rate and non-probative blocks, a HASH-SETS algorithm that can help in identification of files and the HASHRUNS algorithm that helps in reassembling the files is used. This technique is demonstrated using the forensic tool: bulk_extractor along with a hash database: the has hdb and an algorithm implementation written in Python.
منابع مشابه
Hash-based carving: Searching media for complete files and file fragments with sector hashing and hashdb
Hash-based carving is a technique for detecting the presence of specific “target files” on digital media by evaluating the hashes of individual data blocks, rather than the hashes of entire files. Unlike whole-file hashing, hash-based carving can identify files that are fragmented, files that are incomplete, or files that have been partially modified. Previous efforts at hash-based carving have...
متن کاملDetection of seam carving-based video retargeting using forensics hash
Seam carving is a content-aware multimedia retargeting technique to adaptively resize multimedia data for different display sizes. However, it can also be used to remove objects from digital object or video for malicious purposes. In this paper, a forensics hash-based tampering detection and localization approach is proposed for seam carving-based video retargeting. It extracts the invariant Sp...
متن کاملUsing purpose-built functions and block hashes to enable small block and sub-file forensics
This paper explores the use of purpose-built functions and cryptographic hashes of small data blocks for identifying data in sectors, file fragments, and entire files. It introduces and defines the concept of a “distinct” disk sectorda sector that is unlikely to exist elsewhere except as a copy of the original. Techniques are presented for improved detection of JPEG, MPEG and compressed data; f...
متن کاملDesign tradeoffs for developing fragmented video carving tools
When conducting a digital forensic examination, there is sometimes a need to salvage as much playable video as possible from available data sources. Although an ideal outcome might be to have all deleted and partially overwritten file fragments identified, reassembled, and repaired to provide playable videos, there are situations where this is not possible. In addition, there are complexities i...
متن کاملUsing parallel processing for file carving
File carving is one of the most important procedures in Digital Forensic Investigation (DFI). But it is also requires the most computational resources. Parallel processing on Graphics Processing Units have proven to be many times faster than when executed on standard CPU. This paper is inspecting the algorithms and methods to use parallel processing for development of file carving tools that wi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016