Abstract
As all the society becomes computerized, there increases computerized data, and for digital forensic investigations, there is a great deal of unfixed-form data collected, whose exact forms are difficult to figure out, such as physical memory or page files. The most efficient method for investigating unfixed-form data is to extract strings. In case of document files, strings extracted from unfixed-form data come to include contents of the relevant documents, and in case of physical memory or page files, they can even include passwords that users have entered in addition to traces of users’ using a messenger or a web page. Although extracting strings plays an important role in investigating unfixed-form data like this, the present method of extracting string includes a number of meaningless strings, while being carried out without considering the Unicode environment properly. Accordingly, this thesis intends to suggest a way of excluding meaningless strings effectively while considering the Unicode environment during the process of extracting strings.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
References
Beebe, N.: “A new process model for text string searching” International federation for information processing. In: Craiger, P., Shenoi, S. (eds.) Advances in Digital Forensics III, vol. 242, pp. 179–191. Springer, Boston (2007)
Beebe, N.L.: “Digital forensic text string searching: improving information retrieval effectiveness by thematically clustering search results”, Digital Investigation (2007)
Garia, G.L.: “Forensic physical memory analysis: an overview of tools and”, TKK T-110.5290 Seminar on Network Security
Strings, “Strings v2.41”, http://technet.microsoft.com/en-us/sysinternals/bb897439
SQLite, “SQL As Understood By SQLite”, http://www.sqlite.org/lang.html
Acknowledgments
This research was supported by Bio R&D program through the National Research Foundation of Korea funded by the Ministry of Education, Science and Technology (2011-0027732).
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2012 Springer Science+Business Media Dortdrecht
About this paper
Cite this paper
Jeon, S., Park, J., Lee, Kg., Lee, S. (2012). An Efficient Method of Extracting Strings from Unfixed-Form Data. In: J. (Jong Hyuk) Park, J., Leung, V., Wang, CL., Shon, T. (eds) Future Information Technology, Application, and Service. Lecture Notes in Electrical Engineering, vol 164. Springer, Dordrecht. https://doi.org/10.1007/978-94-007-4516-2_43
Download citation
DOI: https://doi.org/10.1007/978-94-007-4516-2_43
Published:
Publisher Name: Springer, Dordrecht
Print ISBN: 978-94-007-4515-5
Online ISBN: 978-94-007-4516-2
eBook Packages: EngineeringEngineering (R0)