信息网络安全 ›› 2014, Vol. 14 ›› Issue (9): 220-222.doi: 10.3969/j.issn.1671-1122.2014.09.052
• Orginal Article • Previous Articles Next Articles
SHEN Chang-da, YOU Jun-sheng, QIAN Jing-jie
Received:
Online:
Abstract: TrueCrypt as one of the popular free open source encryption software has been widely applied on different platforms. Forensics process often to detected encrypted file for further decrypt and analysis, but TrueCrypt container has no signature and structure, so it is a difficult to detect TrueCrypt container. In view of the TrueCrypt container file, there is no accurate detection method, the available technology is signature rule out combined file size limit to detect TrueCrypt container. In this paper, on the basis of the existing detection technology, combined with chi-square test and information entropy theory, we came up with a fast TrueCrypt container detection technology. This method not only can quickly detect TrueCrypt container, but higher precision compared with the existing detection methods.
Key words: file signature, sector size, chi-square, significance level, information entropy
SHEN Chang-da, YOU Jun-sheng, QIAN Jing-jie. TrueCrypt Container Fast Detection Technology[J]. 信息网络安全, 2014, 14(9): 220-222.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://netinfo-security.org/EN/10.3969/j.issn.1671-1122.2014.09.052
http://netinfo-security.org/EN/Y2014/V14/I9/220