손상된 OOXML 파일에서의 데이터 추출 고도화 방안 연구

Vol. 34, No. 2, pp. 193-206, 4월. 2024
10.13089/JKIISC.2024.34.2.193, Full Text:
Keywords: Digital Forensics, OOXML, PK ZIP, Data Extraction
Abstract

In tandem with the advancements in the digital era, the significance of digital data has escalated, necessitating an increased focus on digital forensics investigations. However, the process of collecting and analyzing digital evidence faces significant challenges, such as the unidentifiability of damaged files due to issues like media corruption and anti-forensic techniques. Moreover, the technological limitations of existing tools hinder the recovery of damaged files, posing difficulties in the evidence collection process. This paper aims to propose solutions for the recovery of corrupted MS Office files commonly used in digital data creation. To achieve this, we analyze the structure of MS Office files in the OOXML format and present a novel approach to overcome the limitations of current recovery tools. Through these efforts, we aim to contribute to enhancing the quality of evidence collection in the field of digital forensics by efficiently recovering and identifying damaged data.

Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
김지윤, 김민수, 박우빈, 정두원, "Research on Advanced Methods for Data Extraction from Corrupted OOXML Files," Journal of The Korea Institute of Information Security and Cryptology, vol. 34, no. 2, pp. 193-206, 2024. DOI: 10.13089/JKIISC.2024.34.2.193.

[ACM Style]
김지윤, 김민수, 박우빈, and 정두원. 2024. Research on Advanced Methods for Data Extraction from Corrupted OOXML Files. Journal of The Korea Institute of Information Security and Cryptology, 34, 2, (2024), 193-206. DOI: 10.13089/JKIISC.2024.34.2.193.