File type identification tools for digital investigations

Uloženo v:
Podrobná bibliografie
Název: File type identification tools for digital investigations
Autoři: Dubettier, Adrien, Gernot, Tanguy, Giguet, Emmanuel, Rosenberger, Christophe
Přispěvatelé: Equipe SAFE - Laboratoire GREYC - UMR6072, Groupe de Recherche en Informatique, Image et Instrumentation de Caen (GREYC), Université de Caen Normandie (UNICAEN), Normandie Université (NU)-Normandie Université (NU)-École Nationale Supérieure d'Ingénieurs de Caen (ENSICAEN), Normandie Université (NU)-Centre National de la Recherche Scientifique (CNRS)-Université de Caen Normandie (UNICAEN), Normandie Université (NU)-Centre National de la Recherche Scientifique (CNRS)
Zdroj: ISSN: 2666-2817 ; EISSN: 2666-2825 ; Forensic Science International: Digital Investigation.
Informace o vydavateli: HAL CCSD
Elsevier
Rok vydání: 2023
Sbírka: Archive ouverte HAL (Hyper Article en Ligne, CCSD - Centre pour la Communication Scientifique Directe)
Témata: Digital forensics, Digital evidence assessment, Comparative evaluation of forensics tools, Benchmarking, File type identification, File systems, [INFO.INFO-CR]Computer Science [cs]/Cryptography and Security [cs.CR]
Popis: International audience ; Digital forensics is the process of identifying, preserving, analyzing, and documenting digital evidence for investigation purposes. Building or using file analysis tools is of great interest for a forensic expert to collect high-level information in a short time. In this paper, we consider the examination of files contained in digital media, especially files with possible incorrect types. This often reveals a simple way to hide sensitive content such as porn images, passwords, or accounts. Many commercial and free forensic tools are available for file type identification (FTI). In this work, we assess the performance of ten of them on two significant datasets and scenarios. The main issue we address is the relevance of the tools for forensic purposes. The underlying question is: do expectations meet reality? Our experiments highlight the significant disparity in the accuracy and behavior of the studied tools.
Druh dokumentu: article in journal/newspaper
Jazyk: English
Relation: hal-04128864; https://hal.science/hal-04128864; https://hal.science/hal-04128864/document; https://hal.science/hal-04128864/file/filetype_greyc_hal.pdf
DOI: 10.1016/j.fsidi.2023.301574
Dostupnost: https://hal.science/hal-04128864
https://hal.science/hal-04128864/document
https://hal.science/hal-04128864/file/filetype_greyc_hal.pdf
https://doi.org/10.1016/j.fsidi.2023.301574
Rights: info:eu-repo/semantics/OpenAccess
Přístupové číslo: edsbas.D5B47DC6
Databáze: BASE
Popis
Abstrakt:International audience ; Digital forensics is the process of identifying, preserving, analyzing, and documenting digital evidence for investigation purposes. Building or using file analysis tools is of great interest for a forensic expert to collect high-level information in a short time. In this paper, we consider the examination of files contained in digital media, especially files with possible incorrect types. This often reveals a simple way to hide sensitive content such as porn images, passwords, or accounts. Many commercial and free forensic tools are available for file type identification (FTI). In this work, we assess the performance of ten of them on two significant datasets and scenarios. The main issue we address is the relevance of the tools for forensic purposes. The underlying question is: do expectations meet reality? Our experiments highlight the significant disparity in the accuracy and behavior of the studied tools.
DOI:10.1016/j.fsidi.2023.301574