@inproceedings{0272f478312d4347ad2e8bbaed4d58c1,
title = "Data hiding in windows executable files",
abstract = "A common technique for hiding information in executable files is the embedding a limited amount of information in program binaries. The hiding technique is commonly achieved by using special software tools as e.g. the tools presented by Hydan and Stilo in (Rakan, 2004, Bertrand, 2005). These tools can be used to commit crimes as e.g. industrial spy activities or other forms of illegal data access. In this paper, we propose new methods for hiding information in Portable Executable (PE) files. PE is a file format for executables used in the 32-bit and 64-bit versions of the Windows operating system. In addition, we discuss the analysis techniques which can be applied to detect and recover data hidden using each of these methods. The existing techniques for hiding information in an executable file determine the total number of bytes to be hidden on the foundation of the size of the executable code. Our novel methods proposed here do not limit the amount of hidden code.",
keywords = "Executable file, Hiding information, Portable executable (PE), Program binaries",
author = "Shin, {Dae Min} and Yeog Kim and Byun, {Keun Duck} and Sangjin Lee",
year = "2008",
language = "English",
isbn = "9780729806664",
series = "Proceedings of the 6th Australian Digital Forensics Conference",
pages = "153--159",
booktitle = "Proceedings of the 6th Australian Digital Forensics Conference",
note = "6th Australian Digital Forensics Conference ; Conference date: 01-12-2008 Through 03-12-2008",
}