Detecting Data Concealment Programs Using Passive File System Analysis

IFIP Int. Conf. Digital Forensics(2006)

引用 1|浏览5
暂无评分
摘要
Individuals who wish to avoid leaving evidence on computers and networks often use programs that conceal data from conventional digital forensic tools. This paper discusses the application of passive file system analysis techniques to detect trace evidence left by data concealment programs. In addition, it describes the design and operation of Seraph, a tool that determines whether certain encryption, steganography and erasing programs were used to hide or destroy data.
更多
查看译文
关键词
data concealment programs,trace evidence,program detection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要