0


在虚拟磁盘映像中隐藏大量数据

Hiding large amounts of data in virtual disk images
课程网址: http://videolectures.net/lawandethics2017_fele_zorz_disk_images/  
主讲教师: Gašper Fele-Žorž
开课单位: 卢布尔雅那大学
开课时间: 2017-07-24
课程语种: 英语
中文简介:
在过去的几十年里,人们设计了多种方法来隐藏硬盘上的数据。其中大多数依赖于文件系统之间或文件系统内部未分配的空间。由于罪犯也可能使用隐藏数据的方法,因此数字法医调查人员对这些方法感兴趣。因此,调查人员使用的工具通常支持一些功能,这些功能可用于检查可能隐藏数据的位置内的数据,例如删除的文件、未分配的扇区或备用数据流。在个人计算机上广泛使用的虚拟化可以用来支持旧软件,否则这些软件可能无法在现代硬件上运行。虚拟化在开发底层软件(如操作系统)时也是必不可少的,也是所有云计算解决方案的重要组成部分。因此,虚拟化技术得到了广泛的应用,在可预见的未来很可能仍然很流行。使用虚拟计算机时,将文件用作虚拟硬盘而不是物理磁盘通常更方便。这些文件通常很大,因此数据可能隐藏在其中,具体取决于虚拟磁盘映像格式。我们分析了最流行的虚拟磁盘映像文件格式,并设计了三种在此类文件中隐藏数据的通用方法。其中两种方法允许隐藏大量数据。目前的数字取证工具不太可能检测到隐藏的数据。必须开发新的技术和程序来检测此类数据。我们已经实现了其中一种方法,可以用来在免费提供的图书馆中存储几乎无限量的数据
课程简介: Over the past few decades, multiple methods for hiding data in on hard drives have been devised. Most of these depend on unallocated space either between or within filesystems. Since methods for hiding data may also be used by criminals, they are of interest to digital forensic investigators. Tools used by investigators therefore usually support features which can be used to inspect data within places where data may be hidden, such as deleted files, unallocated sectors or alternate data streams. Widely available virtualization of and on personal computers can be used to support old software which might otherwise not run on modern hardware. Virtualization is also essential in developing low-level software, such as operating systems, and is an essential component of all solutions for cloud computing. Virtualization technologies are therefore widely used and will likely remain popular in the foreseeable future. With virtual computers it is often more convenient to use files as virtual hard drives instead of physical disks. These files are typically large, so data could potentially be hidden within them, depending on the virtual disk image format. We have analyzed the most popular virtual disk image file formats and devised three general approaches for hiding data within such files. Two of these approaches allow large amounts of data to be hidden. The hidden data is unlikely to be detected by current digital forensics tools. New techniques and procedures will have to be developed to detect such data. We have implemented one of the approaches which can be used to store practically unlimited amounts of data in a library which is freely available
关 键 词: 隐藏数据; 虚拟磁盘映像格式; 虚拟化技术
课程来源: 视频讲座网
数据采集: 2022-02-14:zkj
最后编审: 2022-02-14:zkj
阅读次数: 49