Authors: Vassil Roussev, Ph.D. (University of New Orleans), Candice Quates
DFRWS USA 2013
Abstract
Over the past decade, a substantial effort has been put into developing methods to classify file fragments. Throughout, it has been an article of faith that data fragments, such as disk blocks, can be attributed to different file types. This work is an attempt to critically examine the underlying assumptions and compare them to empirically collected data. Specifically, we focus most of our effort on surveying several common compressed data formats and show that the simplistic conceptual framework of prior work is at odds with the realities of actual data. We introduce a new tool, sniff, which allows us to analyze deflate-encoded data, and we use it to perform an empirical survey of deflate-coded text, images, and executables. The results offer a conceptually new type of classification capabilities that cannot be achieved by other means.