{"title":"在NTFS目录索引中隐藏消息的反取证工具的开发","authors":"Gyusang Cho","doi":"10.1109/WorldCIS.2015.7359431","DOIUrl":null,"url":null,"abstract":"This research is about a development of software tool for hiding message in a directory index in Windows NTFS file system. A method of hiding message in directory index slack space is a newly proposed technique. A B-tree is adopted to manage file indexes in a directory in NTFS. Operating characteristics of the B-tree is utilized for hiding message in the slack space of an index record. Not to be revealed the hidden message, we make use of a disguised file name for a MFT entry. To develop the tool for the proposed method, we use Visual Studio 2013 with C/C++ and MFC class and a program type is a Windows dialog based application. The program has features to control a message length from 8 characters to n characters, to select working path, to make directory name and to attach file name prefix and suffix. We show screen shots of the developed tool and the case of the hidden messages in the index record.","PeriodicalId":234497,"journal":{"name":"2015 World Congress on Internet Security (WorldCIS)","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Development of an anti-forensic tool for hiding message in a directory index of NTFS\",\"authors\":\"Gyusang Cho\",\"doi\":\"10.1109/WorldCIS.2015.7359431\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"This research is about a development of software tool for hiding message in a directory index in Windows NTFS file system. A method of hiding message in directory index slack space is a newly proposed technique. A B-tree is adopted to manage file indexes in a directory in NTFS. Operating characteristics of the B-tree is utilized for hiding message in the slack space of an index record. Not to be revealed the hidden message, we make use of a disguised file name for a MFT entry. To develop the tool for the proposed method, we use Visual Studio 2013 with C/C++ and MFC class and a program type is a Windows dialog based application. The program has features to control a message length from 8 characters to n characters, to select working path, to make directory name and to attach file name prefix and suffix. We show screen shots of the developed tool and the case of the hidden messages in the index record.\",\"PeriodicalId\":234497,\"journal\":{\"name\":\"2015 World Congress on Internet Security (WorldCIS)\",\"volume\":\"24 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 World Congress on Internet Security (WorldCIS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WorldCIS.2015.7359431\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 World Congress on Internet Security (WorldCIS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WorldCIS.2015.7359431","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
摘要
本课题研究的是在Windows NTFS文件系统的目录索引中隐藏消息的软件工具的开发。在目录索引空闲空间中隐藏消息是一种新提出的技术。在NTFS中,采用b树来管理目录中的文件索引。利用b树的操作特性在索引记录的空闲空间中隐藏消息。为了不暴露隐藏的消息,我们对MFT条目使用了一个伪装的文件名。为了开发该方法的工具,我们使用Visual Studio 2013,使用C/ c++和MFC类,程序类型是基于Windows对话框的应用程序。该程序具有控制消息长度从8个字符到n个字符,选择工作路径,制作目录名称和附加文件名前缀和后缀的功能。我们展示了开发的工具的屏幕截图,以及索引记录中隐藏消息的情况。
Development of an anti-forensic tool for hiding message in a directory index of NTFS
This research is about a development of software tool for hiding message in a directory index in Windows NTFS file system. A method of hiding message in directory index slack space is a newly proposed technique. A B-tree is adopted to manage file indexes in a directory in NTFS. Operating characteristics of the B-tree is utilized for hiding message in the slack space of an index record. Not to be revealed the hidden message, we make use of a disguised file name for a MFT entry. To develop the tool for the proposed method, we use Visual Studio 2013 with C/C++ and MFC class and a program type is a Windows dialog based application. The program has features to control a message length from 8 characters to n characters, to select working path, to make directory name and to attach file name prefix and suffix. We show screen shots of the developed tool and the case of the hidden messages in the index record.