25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

cache file fragments. The headers identified in the first check using the WinHex<br />

file are used again for this extensive check of the entire fragment. If a header is<br />

found which is not part of a thumbnail cache file the fragment is rejected. As the<br />

Linux visual thumbnails are stored in individual PNG files the PNG header<br />

signature will only be found at the start of a fragment and would therefore have<br />

been identified in the first check of this stage. If the fragment contains a JPEG,<br />

PNG or BMP header the fragment is passed to Stage 3 as these are the file<br />

types used to store visual thumbnails in the Windows 7 thumbnail cache.<br />

<strong>After</strong> the final preliminary check if the fragment has not been rejected or passed<br />

directly to another stage it is passed to Stage 2.<br />

8.6.2 Stage 2: H1 Validation Checks<br />

If the fragment completes the Stage 1 checks and is not rejected or identified as<br />

containing a thumbnail cache file H2 or H4 file header then it is assessed for H1<br />

classification; given the ability of the structural and syntactical approach to<br />

identify H1 fragments with no false positives it was decided to use the checks<br />

defined in Section 7.7.1. If these checks are all positive the fragment is<br />

classified as H1; if any check fails the fragment is passed to H2.<br />

8.6.3 Stage 3: H2 Validation Checks<br />

A fragment can be passed to stage 3 by either stage 1 or 2. If the fragment is<br />

passed directly from Stage 1 then it begins with the file signature “CMMM”; in<br />

this case if the fragment belongs to a thumbnail cache the file signature is either<br />

followed by the remainder of the thumbnail cache file header or the subrecord<br />

header structure. In Section 7.7.2 the implementation for identification of H2<br />

fragments using the structural and syntactical approach was described. The<br />

method identified all the thumbnail cache file fragments in the three data sets<br />

used in the previous chapters without identifying any false positives. Therefore<br />

Page<br />

218

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!