Journal on Communications ›› 2021, Vol. 42 ›› Issue (7): 117-127.doi: 10.11959/j.issn.1000-436x.2021143

• Papers • Previous Articles     Next Articles

Memory fragment file carving algorithm based on the reverse of the structure chain

Binglong LI, Zhenyu ZHOU, Yu ZHANG, Heyu ZHANG, Chaowen CHANG   

  1. Cryptography Engineering Academy, Information Engineering University, Zhengzhou 450001, China
  • Revised:2021-03-01 Online:2021-07-25 Published:2021-07-01
  • Supported by:
    The National Natural Science Foundation of China(60903220)

Abstract:

To address the extraction of document evidence for doc, pdf, and other common file types in the memory image, the model of fragment file carving based on memory image was proposed.Then, on the basis of the model, the fragment file carving algorithm based on the reverse of file object structure chain was designed and implemented, the algorithm was able to get file data left behind in the memory image file.The experimental results show that the proposed algorithm can successfully carve out of memory file’s metadata, and the accuracy is 100%, and in a typical application case, the accuracy of the algorithm for memory file can achieve 87.5%, far higher than disk-based file caving algorithm.

Key words: file carving, memory forensics, memory fragment, fragment adjacent, structure reverse

CLC Number: 

No Suggested Reading articles found!