25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

processing time of the reassembly method. For this research the identified<br />

information maximised the data retrieved and provided information which<br />

assisted in proving the research hypothesis.<br />

In Chapter 8 the research considered the characteristics of JPEG file<br />

fragments, both from the thumbnail cache and other sources. The research<br />

considered JPEG start of sequence markers; table 8.1 lists the 8 sequence<br />

markers found in the visual thumbnails tested. As all 8 sequence markers<br />

occurred in every JPEG thumbnail cache image tested a decision was made to<br />

exclude fragments which contained any other sequence starting with 0xFF. This<br />

meant that other sequences, which were valid markers in the JPEG<br />

specification, would have resulted in a fragment being rejected. Given the<br />

number of thumbnails tested it is possible that the 8 markers are the only ones<br />

which occur in visual thumbnails; however it is also possible that thumbnail<br />

caches outside the test data may contain other sequences.<br />

The use of observed characteristics instead of the specification made it possible<br />

to significantly reduce the number of false positive JPEG identifications; this led<br />

to a smaller number of fragments for the reassembly method. The reduction in<br />

false positives improved the performance and feasibility of the reassembly<br />

approach. If JPEG visual thumbnails exist which contain other sequence<br />

markers they will not be identified; therefore this may significantly impact the<br />

artefacts available for an analyst to present in his report. Further work is<br />

required to explore the characteristics of JPEG and JPEG thumbnail cache file<br />

fragments to assist with distinguishing between them for file fragment<br />

identification and reassembly.<br />

Page<br />

286

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!