File type identification tools for digital investigations - GREYC monebiom Accéder directement au contenu
Article Dans Une Revue Forensic Science International: Digital Investigation Année : 2023

File type identification tools for digital investigations

Résumé

Digital forensics is the process of identifying, preserving, analyzing, and documenting digital evidence for investigation purposes. Building or using file analysis tools is of great interest for a forensic expert to collect high-level information in a short time. In this paper, we consider the examination of files contained in digital media, especially files with possible incorrect types. This often reveals a simple way to hide sensitive content such as porn images, passwords, or accounts. Many commercial and free forensic tools are available for file type identification (FTI). In this work, we assess the performance of ten of them on two significant datasets and scenarios. The main issue we address is the relevance of the tools for forensic purposes. The underlying question is: do expectations meet reality? Our experiments highlight the significant disparity in the accuracy and behavior of the studied tools.
Fichier principal
Vignette du fichier
filetype_greyc_hal.pdf (558.68 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
licence : CC BY NC ND - Paternité - Pas d'utilisation commerciale - Pas de modification

Dates et versions

hal-04128864 , version 1 (15-06-2023)

Identifiants

Citer

Adrien Dubettier, Tanguy Gernot, Emmanuel Giguet, Christophe Rosenberger. File type identification tools for digital investigations. Forensic Science International: Digital Investigation, 2023, 46C, pp.301574. ⟨10.1016/j.fsidi.2023.301574⟩. ⟨hal-04128864⟩
46 Consultations
465 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More