Similarity Digest Search: A Survey and Comparative Analysis of Strategies to Perform Known File Filtering Using Approximate Matching

المؤلفون المشاركون

Moia, Vitor Hugo Galhardo
Henriques, Marco Aurélio Amaral

المصدر

Security and Communication Networks

العدد

المجلد 2017، العدد 2017 (31 ديسمبر/كانون الأول 2017)، ص ص. 1-17، 17ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2017-09-26

دولة النشر

مصر

عدد الصفحات

17

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Digital forensics is a branch of Computer Science aiming at investigating and analyzing electronic devices in the search for crime evidence.

There are several ways to perform this search.

Known File Filter (KFF) is one of them, where a list of interest objects is used to reduce/separate data for analysis.

Holding a database of hashes of such objects, the examiner performs lookups for matches against the target device.

However, due to limitations over hash functions (inability to detect similar objects), new methods have been designed, called approximate matching.

This sort of function has interesting characteristics for KFF investigations but suffers mainly from high costs when dealing with huge data sets, as the search is usually done by brute force.

To mitigate this problem, strategies have been developed to better perform lookups.

In this paper, we present the state of the art of similarity digest search strategies, along with a detailed comparison involving several aspects, as time complexity, memory requirement, and search precision.

Our results show that none of the approaches address at least these main aspects.

Finally, we discuss future directions and present requirements for a new strategy aiming to fulfill current limitations.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Moia, Vitor Hugo Galhardo& Henriques, Marco Aurélio Amaral. 2017. Similarity Digest Search: A Survey and Comparative Analysis of Strategies to Perform Known File Filtering Using Approximate Matching. Security and Communication Networks،Vol. 2017, no. 2017, pp.1-17.
https://search.emarefa.net/detail/BIM-1202736

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Moia, Vitor Hugo Galhardo& Henriques, Marco Aurélio Amaral. Similarity Digest Search: A Survey and Comparative Analysis of Strategies to Perform Known File Filtering Using Approximate Matching. Security and Communication Networks No. 2017 (2017), pp.1-17.
https://search.emarefa.net/detail/BIM-1202736

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Moia, Vitor Hugo Galhardo& Henriques, Marco Aurélio Amaral. Similarity Digest Search: A Survey and Comparative Analysis of Strategies to Perform Known File Filtering Using Approximate Matching. Security and Communication Networks. 2017. Vol. 2017, no. 2017, pp.1-17.
https://search.emarefa.net/detail/BIM-1202736

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1202736