论文标题
Adobe PDF文件中残留信息的法医分析
Forensic Analysis of Residual Information in Adobe PDF Files
论文作者
论文摘要
近年来,由于电子文件包括个人记录和业务活动,这些文件可以用作数字法医调查过程中的重要证据。通常,可以使用其自己的应用程序程序进行验证的数据主要用于文档文件的调查。但是,对于当前主要使用的PDF文件的情况,某些数据(包括一些修改之前的数据)无意中存在于电子文档文件中。由于此类残留信息可能会呈现文件的写作过程,因此可以在法医角度有效地使用它。本文介绍了为什么残留信息存储在PDF文件中,并解释了一种提取信息的方法。此外,我们演示了PDF文件的属性可用于隐藏数据。
In recent years, as electronic files include personal records and business activities, these files can be used as important evidences in a digital forensic investigation process. In general, the data that can be verified using its own application programs is largely used in the investigation of document files. However, in the case of the PDF file that has been largely used at the present time, certain data, which include the data before some modifications, exist in electronic document files unintentionally. Because such residual information may present the writing process of a file, it can be usefully used in a forensic viewpoint. This paper introduces why the residual information is stored inside the PDF file and explains a way to extract the information. In addition, we demonstrate the attributes of PDF files can be used to hide data.