信息网络安全 ›› 2019, Vol. 19 ›› Issue (9): 26-30.doi: 10.3969/j.issn.1671-1122.2019.09.006

• • 上一篇    下一篇

一种Office文件数据分片识别、排序、重组及修复方法

徐国天   

  1. 中国刑事警察学院网络犯罪侦查系,辽宁沈阳 110854
  • 收稿日期:2019-07-15 出版日期:2019-09-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:徐国天(1978—),男,辽宁,副教授,硕士,主要研究方向为网络安全。

  • 基金资助:
    辽宁省自然科学基金[20180550841,2015020091];中央高校基本科研业务费[3242017013];公安部理论及软科学研究计划[2016LLYJXJXY013];公安部技术研究计划[2016JSYJB06];辽宁省社会科学规划基金[L16BFX012]

A Method of Office Data Fragmentation Recognition, Sorting, Reorganization and Repair

Guotian XU   

  1. Cyber Crime Investigation Department, Criminal Investigation Police University of China,Shenyang Liaoning 110854, China
  • Received:2019-07-15 Online:2019-09-10 Published:2020-05-11

摘要:

恢复被删除的涉案Office文档对调查取证工作有重要意义。当被删除的Office文件数据分为多段存储在磁盘内,且MFT记录被覆盖时,现有数据恢复工具无法有效恢复被删除的数据。针对这一问题,文章提出一种Office文件数据分片识别、排序、重组及修复方法。根据Office文件尾部目录区数据定位全部数据分片,确定分片排列次序,重组Office文件,并对受损数据分片进行修复。实践证明,该方法可有效恢复2007以上版本Office文档,在Office文件数据恢复方面优于X-way等恢复工具采用的首尾特征值恢复方法,可以达到更优的恢复效果。

关键词: Office数据分片, 识别, 排序, 重组, 修复

Abstract:

Restoring deleted office documents is of great significance to the investigation and evidence collection. When the deleted office file data is stored on disk in multiple segments and MFT records are overwritten, the existing data recovery tools can not effectively recover the deleted data. In order to solve this problem, this paper proposes a method of office data fragmentation recognition, sorting, reorganization and repair. According to the data in the catalog area at the end of the Office file, locate all data fragments, determine the order of fragmentation, reorganize the Office file, and repair the damaged data fragments. Practice has proved that the method proposed in this paper can effectively restore the version of Office documents above 2007.

Key words: Office data fragmentation, recognition, sorting, reorganization, repair

中图分类号: