首页 | 本学科首页   官方微博 | 高级检索  
     


A novel file carving algorithm for National Marine Electronics Association (NMEA) logs in GPS forensics
Affiliation:1. School of Computer Science and Technology, Hangzhou Dianzi University, HangZhou, China;2. School of Cyberspace, Hangzhou Dianzi University, HangZhou, China;3. Department of Information Systems and Cyber Security, The University of Texas at San Antonio, San Antonio, TX 78249, USA;1. Department of Aquaculture, Estonian University of Life Sciences, Tartu 51006, Estonia;2. Estonian Marine Institute, University of Tartu, Tartu 51014, Estonia;3. Department of Biology, University of Turku, Turku 20520, Finland;1. Blekinge Institute of Technology, Sweden;2. Hasso-Plattner-Institute, University of Potsdam, Germany
Abstract:Globe positioning system (GPS) devices are an increasing importance source of evidence, as more of our devices have built-in GPS capabilities. In this paper, we propose a novel framework to efficiently recover National Marine Electronics Association (NMEA) logs and reconstruct GPS trajectories. Unlike existing approaches that require file system metadata, our proposed algorithm is designed based on the file carving technique without relying on system metadata. By understanding the characteristics and intrinsic structure of trajectory data in NMEA logs, we demonstrate how to pinpoint all data blocks belonging to the NMEA logs from the acquired forensic image of GPS device. Then, a discriminator is presented to determine whether two data blocks can be merged. And based on the discriminator, we design a reassembly algorithm to re-order and merge the obtained data blocks into new logs. In this context, deleted trajectories can be reconstructed by analyzing the recovered logs. Empirical experiments demonstrate that our proposed algorithm performs well when the system metadata is available/unavailable, log files are heavily fragmented, one or more parts of the log files are overwritten, and for different file systems of variable cluster sizes.
Keywords:GPS forensics  NMEA  Metadata-based recovery  File carving  Trajectory reconstruction
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号