Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering

Previous Articles    

E-mail Fragment Carving Model and Algorithm Based on Set Theory

LI Bing-long a,b, ZHANG Chuan-fu c, HAN Zong-da a,b, WANG Qing-xian a,b   

  1. (a. Fourth Institute; b. State Key Laboratory of Mathematical Engineering and Advanced Computing; c. Third Institute, PLA Information Engineering University, Zhengzhou 450004, China)
  • Received:2013-01-22 Online:2014-05-15 Published:2014-05-14

基于集合论的E-mail碎片雕刻模型及算法

李炳龙a,b,张传富c,韩宗达a,b,王清贤a,b   

  1. (解放军信息工程大学,a. 四院;b. 数学工程与先进计算国家重点实验室;c. 三院,郑州 450004)
  • 作者简介:李炳龙(1974-),男,副教授、CCF会员,主研方向:数字犯罪取证调查,信息系统容灾;张传富,讲师;韩宗达,硕士研究生;王清贤,教授、博士生导师。
  • 基金资助:
    国家自然科学基金资助项目(60903220);郑州市科技攻关计划基金资助项目“基于内存及存储介质的网络取证调查系统”。

Abstract: To acquire fragment E-mail evidence from storage medium, this paper analyzes the E-mail fragment file carving problem on the base of the set partition theory, determines the fragment file carving thought. According to the model, it designs E-mail fragment file carving algorithm model including preprocessing, E-mail file fragment subset determination, connected relation determination between E-mail fragments. By using hexadecimal editor, it expounds internal structure features of E-mail file, combined with the characteristics of fragment mail head and tail and embedded html files, discusses the fragment attributes in storage medium, and gives the adjacent rules among concentration characteristics, follow characteristics, linear properties and information characteristics from the fragments. Experimental results show that the algorithm can acquire E-mail evidence more effectively.

Key words: E-mail file carving, digital crime investigation, fragment subset, characteristic identifier, compound file type, fragment adjacent rule

摘要: 为获取存储介质中的碎片E-mail证据,利用集合论原理对邮件碎片文件雕刻问题进行分析,确定基于集合论划分思想的碎片文件雕刻思路。设计包含预处理、E-mail文件碎片子集确定、E-mail碎片间的连接关系确定等过程的邮件碎片文件雕刻算法模型。利用十六进制编辑器,阐述E-mail文件的内部结构特征,结合碎片邮件头尾和内嵌的html文件特征,论述存储介质上碎片的属性,给出碎片间的集中特性、跟随特性、线性特性以及信息特性的连接规则。实验结果表明,碎片邮件文件雕刻算法能更有效地获取邮件证据。

关键词: E-mail文件雕刻, 数字犯罪调查, 碎片子集, 特征标, 复合文件类型, 碎片连接规则

CLC Number: