TY - GEN
T1 - An efficient method of extracting strings from unfixed-form data
AU - Jeon, Sangjun
AU - Park, Jungheum
AU - Lee, Keun Gi
AU - Lee, Sangjin
N1 - Funding Information:
This research was supported by Bio R&D program through the National Research Foundation of Korea funded by the Ministry of Education, Science and Technology (2011-0027732).
PY - 2012
Y1 - 2012
N2 - As all the society becomes computerized, there increases computerized data, and for digital forensic investigations, there is a great deal of unfixed-form data collected, whose exact forms are difficult to figure out, such as physical memory or page files. The most efficient method for investigating unfixed-form data is to extract strings. In case of document files, strings extracted from unfixed-form data come to include contents of the relevant documents, and in case of physical memory or page files, they can even include passwords that users have entered in addition to traces of users' using a messenger or a web page. Although extracting strings plays an important role in investigating unfixed-form data like this, the present method of extracting string includes a number of meaningless strings, while being carried out without considering the Unicode environment properly. Accordingly, this thesis intends to suggest a way of excluding meaningless strings effectively while considering the Unicode environment during the process of extracting strings.
AB - As all the society becomes computerized, there increases computerized data, and for digital forensic investigations, there is a great deal of unfixed-form data collected, whose exact forms are difficult to figure out, such as physical memory or page files. The most efficient method for investigating unfixed-form data is to extract strings. In case of document files, strings extracted from unfixed-form data come to include contents of the relevant documents, and in case of physical memory or page files, they can even include passwords that users have entered in addition to traces of users' using a messenger or a web page. Although extracting strings plays an important role in investigating unfixed-form data like this, the present method of extracting string includes a number of meaningless strings, while being carried out without considering the Unicode environment properly. Accordingly, this thesis intends to suggest a way of excluding meaningless strings effectively while considering the Unicode environment during the process of extracting strings.
KW - Pagefile
KW - String
KW - Unallocated space
UR - http://www.scopus.com/inward/record.url?scp=84867083532&partnerID=8YFLogxK
U2 - 10.1007/978-94-007-4516-2_43
DO - 10.1007/978-94-007-4516-2_43
M3 - Conference contribution
AN - SCOPUS:84867083532
SN - 9789400745155
T3 - Lecture Notes in Electrical Engineering
SP - 425
EP - 434
BT - Future Information Technology, Application, and Service, FutureTech 2012
T2 - 7th FTRA International Conference on Future Information Technology, FutureTech 2012
Y2 - 26 June 2012 through 28 June 2012
ER -