Title :
Extraction of Residual Information in the Microsoft PowerPoint file from the Viewpoint of Digital Forensics considering PerCom Environment
Author :
Park, Jungheum ; Park, Bora ; Lee, Sangjin ; Hong, Seokhie ; Park, Jong Hyuk
Author_Institution :
Center for Inf. Security Technol., Korea Univ., Seoul
Abstract :
Electronic documents made by some application (e.g. Microsoft PowerPoint application) have traces of work like editing, and these traces exist in the format of electronic documents. In digital forensic investigation, examiners have failed to notice traces of past work. It is because of that the traces of the past work cannot be identified by its application easily. However, identifying traces of the past work is important for digital forensic investigation because this data can be essential information which is created by culprit´s intention not appeared in electronic document. This paper focuses on analyzing the Microsoft PowerPoint application (version 97 ~ 2003) which has the feature that it has traces of past work. In case of Microsoft PowerPoint file, it is possible to identify traces of past work by analyzing saving algorithm of application. To detect the traces automatically, PRIX (PPT residual information extractor) tool is developed.
Keywords :
computer crime; document handling; ubiquitous computing; Microsoft PowerPoint file; PerCom environment; digital forensics; electronic documents; residual information extraction; Algorithm design and analysis; Application software; Computer science; Data mining; Digital forensics; File systems; Information analysis; Information security; Pervasive computing; Power engineering and energy; MS PowerPoint; Residual Information;
Conference_Titel :
Pervasive Computing and Communications, 2008. PerCom 2008. Sixth Annual IEEE International Conference on
Conference_Location :
Hong Kong
Print_ISBN :
978-0-7695-3113-7
DOI :
10.1109/PERCOM.2008.98