Skip to content

Sociedade Brasileira de Telecomunicações

A comparative analysis about similarity search strategies for digital forensics investigations

Known File Filtering method separates relevant from non-relevant information in forensics investigations using white or black lists. Due to limitations on hash functions (inability to detect similar data), approximate matching tools have gained focus recently. However, comparing two sets of approximate matching digests using brute force can be too time-consuming. Strategies to efficiently perform lookups in digests databases have been proposed as a form of similarity search. In this paper, we compare some strategies based on ssdeep and sdhash tools concerning to precision, memory requirement, and lookup complexity. We show that none of these strategies address these requirements satisfactorily.

Autores :

Estatatísticas de Acesso


Total de visitas: 2

Downloads do artigo: 0