loading...
Statistical Disk Cluster Classification for File Carving
Manchester, United Kingdom August 29-August 31
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/IAS.2007.752007 The Third International Symposiu ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
Cor J. Veenman, University of Amsterdam, the Netherlands; Netherlands Forensic Institute, Netherlands
File carving is the process of recovering files from a disk without the help of a file system. In forensics, it is a helpful tool in finding hidden or recently removed disk content. Known signatures in file headers and footers are especially useful in carving such files out, that is, from header until footer. However, this approach assumes that file clusters remain in order. In case of file fragmentation, file clusters can be disconnected and the order can even be disrupted such that straighforward carving will fail. In this paper, we focus on methods for classifying clusters into file types by using the statistics of the clusters. By not exploiting the possible embedded signatures, we generate evidence from a different source that can be integrated lateron. We propose a set of characteristic features and use statistical pattern recognition to learn a supervised classification model for a range of relevant file types. We exploit the statistics of a restricted number of neighboring clusters (context) to improve classification performance. In the experiments we show that the proposed features indeed enable the differentation of clusters into file types. Moreover, for some file types the incorporation of cluster context improves the recognition performance significantly.
Citation:
Cor J. Veenman, "Statistical Disk Cluster Classification for File Carving," ias, pp.393-398, 2007 The Third International Symposium on Information Assurance and Security, 2007
Usage of this product signifies your acceptance of the Terms of Use.