DocumentCode :
3170014
Title :
An Efficient Piecewise Hashing Method for Computer Forensics
Author :
Chen, Long ; Wang, Guoyin
Author_Institution :
SouthWest JiaoTong Univ., Chengdu
fYear :
2008
fDate :
23-24 Jan. 2008
Firstpage :
635
Lastpage :
638
Abstract :
Hashing, a basic tool in computer forensics, is used to ensure data integrity and to identify known data objects efficiently. Unfortunately, intentional tiny modified file can not be identified using this traditional technique. Context triggered piecewise hashing separates a file into pieces using local context characteristic, and produces a hash sequence as a hash signature. The hash signature can be used to identify similar files with tiny modifications such as insertion, replacement and deletion. The algorithm of currently available scheme is designed for junk mail detection, which is low efficient and not suitable for file system investigation. In this paper, an improved algorithm based on the Store-Hash and Rehash idea is developed for context triggered piecewise hashing technique. Experiment results show that the performance of speed and the ability of similarity detection of the new scheme are better than that of spamsum. It is valuable for forensics practice.
Keywords :
cryptography; data integrity; digital signatures; unsolicited e-mail; computer forensics; context triggered piecewise hashing; data integrity; data object identification; file system investigation; hash sequence; hash signature; junk mail detection; local context characteristic; piecewise hashing method; Application software; Costs; Cryptography; Data mining; File systems; Forensics; Information science; Postal services; Software maintenance; Telecommunication computing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Knowledge Discovery and Data Mining, 2008. WKDD 2008. First International Workshop on
Conference_Location :
Adelaide, SA
Print_ISBN :
978-0-7695-3090-1
Type :
conf
DOI :
10.1109/WKDD.2008.80
Filename :
4470474
Link To Document :
بازگشت