A Microsoft Word Documents Carving Method Base on Interior Virtual Streams

Article Preview

Abstract:

Microsoft word is widely used for word processing and document production. So the loss of the Word file would be great damages for their owner. File carving can reconstruct files based on their content and their own structure rather than using the metadata of the file system. The existing methods do not work very well on carving fragmented Word files. This paper presents a Microsoft Word documents carving method based on interior virtual streams. Firstly, we locate the header section and control streams-SAT to construct the framework for a Word file; then find its fragment regions by utilizing the framework information, and use the sequential hypothesis testing on the data streams in the fragment region to detect the fragment point. Based on DFRWS data sets and real data set, experiments show our method can automatically carve continuous and fragmented Microsoft word file. Moreover, the comparative experiments demonstrate that the proposed method is better than others’ in accurateness and effectiveness.

You might also be interested in these eBooks

Info:

Periodical:

Advanced Materials Research (Volumes 433-440)

Pages:

3028-3032

Citation:

Online since:

January 2012

Authors:

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2012 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

[1] A Pal and N Memon. Signal Processing Magazine. IEEE. Vol. 3 (2009), p.59.

Google Scholar

[2] S Garfinkel. Digital Investigation. Vol. 4(Supplement 1)(2007), p.2.

Google Scholar

[3] Michael Cohen. Digital Investigation. Vol. 4(2007), p.119.

Google Scholar

[4] Information on http: /www. microsoft. com/interop/osp/default. mspx.

Google Scholar

[5] A Pal , H Sencar and N Memon. Digital Investigation. Vol. 5 (Supplement 1)(2008), p.2.

Google Scholar

[6] G Conti, S Bratus, A Shubina, et al. Digital Investigation. Vol. 7 (Supplement 1) (2010), p.3.

Google Scholar

[7] Information on http: /www. dfrws. org/index. shtml.

Google Scholar