File type identification tools for digital investigations - GREYC monebiom Access content directly
Journal Articles Forensic Science International: Digital Investigation Year : 2023

File type identification tools for digital investigations

Abstract

Digital forensics is the process of identifying, preserving, analyzing, and documenting digital evidence for investigation purposes. Building or using file analysis tools is of great interest for a forensic expert to collect high-level information in a short time. In this paper, we consider the examination of files contained in digital media, especially files with possible incorrect types. This often reveals a simple way to hide sensitive content such as porn images, passwords, or accounts. Many commercial and free forensic tools are available for file type identification (FTI). In this work, we assess the performance of ten of them on two significant datasets and scenarios. The main issue we address is the relevance of the tools for forensic purposes. The underlying question is: do expectations meet reality? Our experiments highlight the significant disparity in the accuracy and behavior of the studied tools.
Fichier principal
Vignette du fichier
filetype_greyc_hal.pdf (558.68 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
licence : CC BY NC ND - Attribution - NonCommercial - NoDerivatives

Dates and versions

hal-04128864 , version 1 (15-06-2023)

Identifiers

Cite

Adrien Dubettier, Tanguy Gernot, Emmanuel Giguet, Christophe Rosenberger. File type identification tools for digital investigations. Forensic Science International: Digital Investigation, 2023, 46C, pp.301574. ⟨10.1016/j.fsidi.2023.301574⟩. ⟨hal-04128864⟩
52 View
545 Download

Altmetric

Share

Gmail Facebook X LinkedIn More