{"title":"Detecting Disk Sectors Data Types Using Hidden Markov Model","authors":"S. Sadegh Mousavi","doi":"10.1109/ISCISC51277.2020.9261906","DOIUrl":null,"url":null,"abstract":"file carving is process of recovering data without knowledge of file system like recovering files from a formatted disk. Sometime the file systems do not write a file to disk in continues sectors and may split it to more than one chunks. Recovering of such a fragmented file can be difficult because if we found the first chunk of the file, the second chunk can be anywhere on disk. If the disk is large, the search process for finding the second chunk of file will be a time-consuming process. Data type classification help to classify disk sectors based on the type stored on them. Understanding the type of stored data on disk sectors, help to search for a specified file only on area of disk that more likely have the file type we want. In this article we propose an approach to create a hidden markov model that can help classifying disk sector based on their type and detect the point of disk that a fragmentation probably happened. The created hidden markov model classify sectors based on their entropy. The results show 52% of correct data type detection on disks with 512Bytes sector size.","PeriodicalId":206256,"journal":{"name":"2020 17th International ISC Conference on Information Security and Cryptology (ISCISC)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-09-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 17th International ISC Conference on Information Security and Cryptology (ISCISC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCISC51277.2020.9261906","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
file carving is process of recovering data without knowledge of file system like recovering files from a formatted disk. Sometime the file systems do not write a file to disk in continues sectors and may split it to more than one chunks. Recovering of such a fragmented file can be difficult because if we found the first chunk of the file, the second chunk can be anywhere on disk. If the disk is large, the search process for finding the second chunk of file will be a time-consuming process. Data type classification help to classify disk sectors based on the type stored on them. Understanding the type of stored data on disk sectors, help to search for a specified file only on area of disk that more likely have the file type we want. In this article we propose an approach to create a hidden markov model that can help classifying disk sector based on their type and detect the point of disk that a fragmentation probably happened. The created hidden markov model classify sectors based on their entropy. The results show 52% of correct data type detection on disks with 512Bytes sector size.