Difference between pages "Main Page" and "Compression"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (WIKI NEWS)
 
(Deflate/Inflate)
 
Line 1: Line 1:
<div style="margin-top:0.5em; padding:0.5em 0.5em 0.5em 0.5em; background-color:#faf0ff; align:right; border:1px solid #ddccff;">
+
{{Expand}}
This is the '''Forensics Wiki''', a [http://creativecommons.org/licenses/by-sa/2.5/ Creative Commons]-licensed [http://en.wikipedia.org/wiki/Wiki wiki] devoted to information about [[digital forensics]] (also known as computer forensics). We currently list a total of [[Special:Allpages|{{NUMBEROFARTICLES}}]] pages.
+
 
+
Much of [[computer forensics]] is focused on the [[tools]] and [[techniques]] used by [[investigator]]s, but there are also a number of important [[papers]], [[people]], and [[organizations]] involved. Many of those organizations sponsor [[Upcoming_events|conferences]] throughout the year and around the world. You may also wish to examine the popular [[journals]] and some special [[reports]].
+
</div> 
+
  
 +
== LZ-based ==
  
==WIKI NEWS==
+
=== Deflate/Inflate ===
2014-06-14: The Wiki has been migrated to the most up-to-date MediaWiki and moved from HostGator to Pair. The previous bugs with the AccountCreation problem should be fixed. Please let us know if there are any problems.
+
Used in:
 +
* [[Gzip|gzip]]
  
2013-05-15: You can now subscribe to Forensics Wiki Recent Changes with the [[ForensicsWiki FeedBurner Feed]]
+
=== LZNT1 ===
 +
Used in:
 +
* [[NTFS]]
 +
* [[Windows SuperFetch Format]]
  
{| width="100%"
+
=== LZXPRESS ===
|-
+
Used in:
| width="60%" style="vertical-align:top" |
+
* [[Extensible Storage Engine (ESE) Database File (EDB) format]]
<!-- Selected Forensics Research --> 
+
<div style="margin-top:0.5em; border:2px solid #ff0000; padding:0.5em 0.5em 0.5em 0.5em; background-color:#ffff99; align:center; border:1px solid #ddccff;">
+
<h2 style="margin:0; background-color:#ffff33; font-size:120%; font-weight:bold; border:1px solid #afa3bf; text-align:left; color:#000; padding-left:0.4em; padding-top:0.2em; padding-bottom:0.2em;"> Featured Forensic Research </h2>
+
  
<small>May 2014</small>
+
=== LZXPRESS Huffman ===
<bibtex>
+
Used in:
@inproceedings{Hurley:2013:MAC:2488388.2488444,
+
* [[Windows SuperFetch Format]]
author = {Sven Ka ̈lber, Andreas Dewald, Steffen Idler},
+
title = {Forensic Zero-Knowledge Event Reconstruction on Filesystem Metadata},
+
booktitle = {Lecture Notes in Informatics},
+
volume="P-228",
+
year=2014,
+
url = {http://subs.emis.de/LNI/Proceedings/Proceedings228/331.pdf},
+
}
+
</bibtex>
+
  
Abstract: Criminal investigations today can hardly be imagined without the forensic analysis of digital devices, regardless of whether it is a desktop computer, a mobile phone, or a navigation system. This not only holds true for cases of cybercrime, but also for traditional delicts such as murder or blackmail, and also private corporate investigations rely on digital forensics. This leads to an increasing number of cases with an ever-growing amount of data, that exceeds the capacity of the forensic experts. To support investigators to work more efficiently, we introduce a novel approach to automatically reconstruct events that previously occurred on the examined system and to provide a quick overview to the investigator as a starting point for further investigation. In contrast to the few existing approaches, our solution does not rely on any previously profiled system behavior or knowledge about specific applications, log files, or file formats. We further present a prototype implementation of our so-called zero knowledge event reconstruction approach, that solely tries to make sense of characteristic structures in file system metadata such as file- and folder-names and timestamps.
+
== External Links ==
 +
* [http://en.wikipedia.org/wiki/Lempel-Ziv Wikipedia: Lempel-Ziv]
 +
* [http://www.coderforlife.com/microsoft-compression-formats/ Microsoft Compression Formats]
  
(See also [[Past Selected Articles]])
+
=== Deflate/Inflate ===
 +
* [http://en.wikipedia.org/wiki/DEFLATE Wikipedia: DEFLATE]
 +
* [https://tools.ietf.org/html/rfc1950 IETF: RFC1950 - ZLIB Compressed Data Format Specification]
 +
* [https://tools.ietf.org/html/rfc1951 IETF: RFC1951 - DEFLATE Compressed Data Format Specification]
  
| width="40%" style="vertical-align:top" |
+
=== LZ1 ===
 
+
* [http://andyh.org/LZ1.html LZ1]
<div style="margin-top:0.5em; border:2px solid #00ff00; padding:0.5em 0.5em 0.5em 0.5em; background-color:#ffeeff; align:center; border:1px solid #ffccff;">
+
<h2 style="margin:0; background-color:#ffff33; font-size:120%; font-weight:bold; border:1px solid #afa3bf; text-align:left; color:#000; padding-left:0.4em; padding-top:0.2em; padding-bottom:0.2em;">  Featured Article </h2>
+
;[[Forensic Linux Live CD issues]]
+
:Forensic Linux Live CD distributions are widely used during computer forensic investigations. Currently, many vendors of such Live CD distributions state that their Linux do not modify the contents of hard drives or employ "write protection." Testing indicates that this may not always be the case. [[Forensic Linux Live CD issues|Read More...]]
+
 
+
|}
+
 
+
 
+
<!-- This begins the two-column section -->
+
 
+
{| width="100%"
+
|-
+
| width="60%" style="vertical-align:top" |
+
 
+
<div style="margin-top:0.5em; padding:0.5em 0.5em 0.5em 0.5em; background-color:#eeeeff; align:right; border:1px solid #ddccff;">
+
 
+
<h2 style="margin:0; background-color:#ccccff; font-size:120%; font-weight:bold; border:1px solid #afa3bf; text-align:left; color:#000; padding-left:0.4em; padding-top:0.2em; padding-bottom:0.2em;">Topics</h2>
+
 
+
* '''[[File Analysis]]''':
+
** '''[[:Category:File Formats|File Formats]]''': [[PDF]], [[DOC]], [[DOCX]], [[JPEG]], [[GIF]], [[BMP]], [[LNK]], [[MP3]], [[AAC]], [[Thumbs.db]], ...
+
** '''[[Forensic file formats]]''': [[AFF]], [[gfzip]], [[sgzip]], ...
+
* '''[[File Systems]]''': [[FAT]], [[NTFS]], [[ext2]]/[[ext3]], [[ufs]], [[ffs]], [[reiserfs]], ...
+
** '''[[File Systems#Cryptographic_File_Systems|Cryptographic File Systems]]''': [[File Vault]], [[EFS]], [[CFS]], [[NCryptfs]], [[TCFS]], [[SFS]], ...
+
* '''[[Hardware]]''':
+
** '''[[Bus]]ses''': [[IDE]], [[SCSI]], [[Firewire]], [[USB]], ...
+
** '''[[Data storage media|Media]]''': [[RAM]], [[Hard Drive]]s, [[Memory Card]]s, [[SmartCard]]s, [[RFID]] Tags...
+
** '''[[Personal Digital Devices]]''': [[PDAs]], [[Cellphones]], [[SmartPhones]], [[Audio Devices]], ...
+
** '''[[Other Devices]]''': [[Printers]], [[Scanners]], ...
+
** '''[[Write Blockers]]''': ...
+
* '''Recovering data''': [[Recovering bad data|bad data]], [[Recovering deleted data|deleted data]], [[Recovering Overwritten Data|overwritten data]], [[Sanitization Standards]]
+
* [[Encryption]]
+
* [[GPS]]
+
* [[Forensic_corpora|Forensic Corpora]]
+
* [[Network forensics]]: [[OS fingerprinting]], [[Hidden channels]], [[Proxy server|Proxy servers]]
+
* [[Steganography]], [[Steganalysis]]
+
* '''[[Metadata]]:''' [[MAC times]], [[ACLs]], [[Email Headers]], [[Exif]], [[ID3]], [[OLE-2]], ...
+
* '''[[Legal issues]]:''' [[Caselaw|Case law]]
+
* '''Further information:''' [[Books]], [[Papers]], [[Reports]], [[Journals]], [[Websites]], [[Blogs]], [[Mailing lists]], [[Organizations]], [[Vendors]], [[Conferences]]
+
</div>
+
 
+
 
+
 
+
| width="40%" style="vertical-align:top" |
+
 
+
<!-- Tools -->
+
<div style="margin-top:0.5em; padding:0.5em 0.5em 0.5em 0.5em; background-color:#e0ffe0; align:right; border:1px solid #ddccff;">
+
 
+
<h2 style="margin:0; background-color:#ccffcc; font-size:120%; font-weight:bold; border:1px solid #afa3bf; text-align:left; color:#000000; padding-left:0.4em; padding-top:0.2em; padding-bottom:0.2em;">[[Tools]]</h2>
+
 
+
* '''[[:Category:Disk Imaging|Disk Imaging]]''': [[dd]], [[dc3dd]], [[dcfldd]], [[dd_rescue]], [[sdd]], [[aimage]], [[Blackbag]], ...
+
* '''[[Tools:Data Recovery|Data Recovery]]''': ...
+
* '''[[Tools#Disk_Analysis_Tools|Disk Analysis]]''': [[EnCase]], [[SMART]], [[Sleuthkit]], [[foremost]], [[Scalpel]], [[frag_find]]...
+
* '''[[Tools#Forensics_Live_CDs|Live CDs]]''': [[DEFT Linux]], [[Helix]] ([[Helix3 Pro|Pro]]), [[FCCU Gnu/Linux Boot CD]], [[Knoppix STD]], ...
+
* '''[[Tools:Document Metadata Extraction|Metadata Extraction]]''': [[wvWare]], [[jhead]], [[Hachoir | hachoir-metadata]], [[Photo Investigator]]...
+
* '''[[Tools:File Analysis|File Analysis]]''': [[file]], [[ldd]], [[ltrace]], [[strace]], [[strings]], ...
+
* '''[[Tools:Network_Forensics|Network Forensics]]''': [[Snort]],  [[Wireshark]], [[Kismet]],  [[NetworkMiner]]...
+
* '''[[:Category:Anti-forensics tools|Anti-Forensics]]''': [[Slacker]], [[Timestomp]], [[wipe]], [[shred]], ...
+
* '''[[Tools#Other_Tools|Other Tools]]''': [[biew]], [[hexdump]], ...
+
</div>
+
 
+
<div style="margin-top:0.5em; padding:0.5em 0.5em 0.5em 0.5em; background-color:#c0ffff; align:right; border:1px solid #ddccff;">
+
 
+
<h2 style="margin:0; background-color:#99ffff; font-size:120%; font-weight:bold; border:1px solid #afa3bf; text-align:left; color:#000000; padding-left:0.4em; padding-top:0.2em; padding-bottom:0.2em;">[[:Category:Top-Level|Categories]]</h2>
+
 
+
The contents of this wiki are organized into various [[:Category:Top-Level|categories]]:
+
 
+
* [[:Category:Tools|Tools]]
+
* [[:Category:Disk file systems|Disk file systems]]
+
* [[:Category:File Formats|File Formats]]
+
* [[:Category:Howtos|Howtos]]
+
* [[:Category:Licenses|Licenses]]
+
* [[:Category:Operating systems|Operating systems]]
+
* [[:Category:People|People]]
+
* [[:Category:Bibliographies|Bibliographies]]
+
 
+
</div>
+
 
+
 
+
|}
+
 
+
<div style="margin-top:0.5em; padding:0.5em 0.5em 0.5em 0.5em; background-color:#faf0ff; align:right; border:1px solid #ddccff;">
+
'''You can help!'''  We have a list of [[:Category:Articles_that_need_to_be_expanded|articles that need to be expanded]]. If you know anything about any of these topics, please feel free to chip in.
+
</div>
+
+
 
+
 
+
 
+
__NOTOC__
+

Revision as of 08:56, 21 June 2014

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

LZ-based

Deflate/Inflate

Used in:

LZNT1

Used in:

LZXPRESS

Used in:

LZXPRESS Huffman

Used in:

External Links

Deflate/Inflate

LZ1