A kind of abnormal Stego-detection analytical approach and system of Facing Digital evidence obtaining
Technical field
The invention belongs to digital evidence obtaining technical field, relate in particular to a kind of abnormal Stego-detection analytical approach and system of Facing Digital evidence obtaining.
Background technology
The analytic process of digital evidence obtaining is the committed step of evidence obtaining, the abnormal Stego-detection analytic process for the treatment of forensics analysis data is individual's judgement and the experience accumulation by evidence obtaining personnel as a rule, some appraiser is selected to collect evidence with two or more steganalysis instruments, yet evidence obtaining personnel's subjective judgement and the lack of standard of analysis tool are difficult to ensure the objective reality of digital evidence obtaining process.So, the availability of evidence obtaining qualification result and the dispute that accuracy easily causes various aspects.
As the countermeasure techniques of Steganography, the task of steganalysis is existence, the identification hidden algorithm of detection of concealed information, even extracts and recovers hiding information.Hidden to write the final goal of minute praying be to using as produce (shenglvehao)in court evidence in order to extract secret information, and along with the development of infotech, the technology of Steganography is also progressively obtaining significant progress in development and progress.Existing Stego-detection analytical approach has much comparative maturity, and as flag sign analytic approach and statistics characteristic analysis method etc., some evidence obtaining personnel have been applied to digital evidence obtaining field.Some steganography software leaves identification characteristics in concealed image, can by analyzing in object to be detected whether occur that this identification characteristics realizes detection.Steganography has changed a part for carrier data stream when hiding Info, although do not change sensory effect, but often changed the statistical property of initial carrier data, whether the statistical property that therefore, the judgement of Information hiding situation is based upon to the fixed given carrier of official under county magistrate who administers lawsuit, etc. belongs under the prerequisite of abnormal condition.
When carrying out digital evidence obtaining, evidence obtaining personnel need to use multiple abnormal Stego-detection analytical approach, and it is also uncertain in most cases detecting analytic target, and therefore how efficiently realizing accurately digital evidence obtaining analysis becomes a problem demanding prompt solution.Abnormal Stego-detection analytical technology is very general in the application of information security research field.But, along with increasing severely with day of personal computer and portable mobile termianl, utilize caseload that associated electronic device directly carries out electronics crime or involve above electronic equipment as computing machine or mobile phone also straight line rise.
In sum, how to propose effectively, meet the abnormal Stego-detection analytical plan of digital evidence obtaining requirement, there is important Research Significance aspect the precision of the detection analysis result in improving digital evidence obtaining.
Summary of the invention
The object of the present invention is to provide a kind of effectively, meet abnormal Stego-detection analytical approach and the system of digital evidence obtaining requirement.
The technical scheme that method of the present invention adopts is: a kind of abnormal Stego-detection analytical approach of Facing Digital evidence obtaining, it is characterized in that, and comprise the following steps:
Step 1: obtain and treat forensics analysis data object from image file;
Step 2: the forensics analysis data object for the treatment of to described image file carries out anomaly analysis, obtains anomaly analysis result;
Step 3: judge and treat that whether forensics analysis data object is abnormal according to described anomaly analysis result;
If exist extremely, generate abnormality detection report, and order is carried out following step 4;
If do not exist extremely, following step 5 is carried out in redirect;
Step 4: by existing the abnormal forensics analysis data object for the treatment of to be labeled as object of suspicion, object of suspicion is moved to observation area simultaneously and isolate;
Step 5: the object of suspicion that forensics analysis data object or step 4 obtain for the treatment of to the described image file obtaining in step 1 carries out Stego-detection analysis, obtains steganalysis result;
Step 6: judge according to described steganalysis result whether the abnormal hidden possibility of writing is 0;
If hidden, writing possibility is 0, and described step 1 is carried out in revolution;
If hidden, writing possibility is not 0, and order is carried out following step 7;
Step 7: generate the report of abnormal Stego-detection, represent the abnormal Stego-detection report generating in the anomaly analysis result that obtains in step 2 and step 7.
As preferably, the forensics analysis data object for the treatment of to described image file described in step 2 carries out anomaly analysis, its specific implementation process is, first according to digital evidence obtaining rule, to described, treat that forensics analysis data object carries out local flag sign anomaly analysis, to described, treat that the principal character of forensics analysis data object identifies and sort according to the significance level playing a role in abnormality detection analysis; Then to described, treat that each local feature of forensics analysis data object detects successively, certain feature existence detected and extremely stop detecting; Otherwise, continue to detect, to the last a feature detection is complete.
As preferably, the object of suspicion that forensics analysis data object or step 4 obtain for the treatment of to the described image file obtaining in step 1 described in step 5 carries out Stego-detection analysis, and its specific implementation process is with reference to abnormal hidden in training set and feature database, to write that model is treated forensics analysis data object or object under a cloud carries out Stego-detection analysis by statistics characteristic analysis method.
The technical scheme that system of the present invention adopts is: the abnormal Stego-detection analytic system of a kind of Facing Digital evidence obtaining, is characterized in that: comprise evidence obtaining data acquisition module, abnormality detection analysis module, abnormality juding module, abnormality processing module, Stego-detection analysis module, hiddenly write determination module and the abnormal hidden forensics analysis of writing represents module;
Described evidence obtaining data acquisition module, treats forensics analysis data object for obtaining from image file;
Described abnormality detection analysis module, carries out anomaly analysis for the forensics analysis data object for the treatment of to described image file by local flag method for feature analysis, obtains anomaly analysis result;
Described abnormality juding module, for judging and treat that whether forensics analysis data object is abnormal according to described anomaly analysis result, if exist extremely, generates abnormality detection report, execute exception processing module; If do not exist extremely, carry out Stego-detection analysis module;
Described abnormality processing module, for by existing the abnormal forensics analysis data object for the treatment of to be labeled as object of suspicion, moves to observation area by object of suspicion simultaneously and isolates;
Described Stego-detection analysis module, the object of suspicion that forensics analysis data object or abnormality processing module obtain for the treatment of for to the described image file of abnormality detection analysis module acquisition, carries out Stego-detection analysis by statistics characteristic analysis method with reference to the data in training set and feature database;
The described hidden determination module of writing, for judging according to described Stego-detection analysis result whether the abnormal hidden possibility of writing is 0, and writing possibility if hidden is 0, controls and carries out the data acquisition module of collecting evidence; If hidden, writing possibility is not 0, controls the hidden forensics analysis of writing of execute exception and represents module;
The described abnormal hidden forensics analysis of writing represents module, for generating abnormal Stego-detection report, and represents anomaly analysis result and abnormal Stego-detection report.
As preferably, described abnormality detection analysis module, for treating that to described forensics analysis data object carries out local flag sign anomaly analysis according to digital evidence obtaining rule, to described, treat that the principal character of forensics analysis data object identifies and sort according to the significance level playing a role in abnormality detection analysis; Then to described, treat that each local feature of forensics analysis data object detects successively, certain feature existence detected and extremely stop detecting; Otherwise, continue to detect, to the last a feature detection is complete.
As preferably, described Stego-detection analysis module, abnormal hidden the treat object of suspicion that forensics analysis data object or abnormality processing module obtain of model to the described image file of abnormality detection analysis module acquisition of writing for reference to training set and feature database, carries out Stego-detection analysis by statistics characteristic analysis method with reference to the data in training set and feature database.
Beneficial effect of the present invention is:
Abnormal Stego-detection analytical approach and the system of Facing Digital evidence obtaining of the present invention, it is combined and has used method for feature analysis and statistical analysis method to carry out abnormal Stego-detection analysis to evidence obtaining data, can effectively meet the abnormal Stego-detection analytical plan of digital evidence obtaining, improve the steganalysis speed in digital evidence obtaining process, and promoted the precision of steganalysis.
Accompanying drawing explanation
Fig. 1: be method flow diagram of the present invention;
Fig. 2: be the systematic schematic diagram of the embodiment of the present invention.
?
Embodiment
For the ease of those of ordinary skills, understand and enforcement the present invention, below in conjunction with drawings and Examples, the present invention is described in further detail, should be appreciated that exemplifying embodiment described herein, only for description and interpretation the present invention, is not intended to limit the present invention.
Some steganography software leaves identification characteristics in concealed image, can, by analyzing in object to be detected whether occur that this sign is special, levy to realize detection.The local feature detection method of Facing Digital evidence obtaining can be understood as: the principal character to evidence obtaining data object is identified and sorts according to the significance level playing a role in abnormality detection analysis.Successively each local feature of this data object is detected, certain feature existence detected and extremely stop detecting; Otherwise, continue to detect, to the last a feature detection is complete.
Statistics detection method is mainly effectively analyzed according to the variation of some statistical property of carrier information, by judging that whether the statistical property of given carrier belongs to abnormal condition, just can judge whether to contain to hide Info.The statistics detection method of Facing Digital evidence obtaining can be understood as: statistical study need to obtain the theoretical expectation frequency distribution of initial carrier data, and the model and the testing data object that refer again in training set and feature database contrast.
Local feature detection method is combined to the abnormal Stego-detection analysis that applies to digital evidence obtaining with statistics detection method, utilize two kinds of detection methods separately different advantage carry out complementation, guaranteed to a certain extent Stego-detection precision of analysis in digital evidence obtaining process.As the countermeasure techniques of Steganography, the task of steganalysis is existence, the identification hidden algorithm of detection of concealed information, even extracts and recovers hiding information.To write the final goal of minute praying be to using as produce (shenglvehao)in court evidence in order to extract secret information due to hidden, therefore, in digital evidence obtaining process, when treating forensics analysis data object and analyzing, if the degree of analyzing not thoroughly or the selection mistake of analytical approach tend to the accuracy of evidence obtaining result to have a negative impact.In order to address this problem, local feature detection method is combined to the abnormal Stego-detection analytic process that applies to digital evidence obtaining with statistics detection method, the mode of two kinds of method Conjoint Analysis evidence obtaining data has been avoided the generation of above-mentioned mistake to a certain extent, thereby promotes the recoverability of evidence obtaining evidence.
Ask for an interview Fig. 1, the scheme that method of the present invention adopts is: a kind of abnormal Stego-detection analytical approach of Facing Digital evidence obtaining, comprises the following steps:
Step 1: obtain and treat forensics analysis data object from image file.
Step 2: the forensics analysis data object for the treatment of to image file carries out anomaly analysis, obtains anomaly analysis result; The forensics analysis data object for the treatment of to image file carries out anomaly analysis, its specific implementation process is, first according to digital evidence obtaining rule, treat forensics analysis data object and carry out local flag sign anomaly analysis, treat the principal character of forensics analysis data object and identify and sort according to the significance level playing a role in abnormality detection analysis; Then each local feature for the treatment of successively forensics analysis data object detects, and certain feature existence detected and extremely stops detecting; Otherwise, continue to detect, to the last a feature detection is complete.
Step 3: judge and treat that whether forensics analysis data object is abnormal according to anomaly analysis result;
If exist extremely, generate abnormality detection report, and order is carried out following step 4;
If do not exist extremely, following step 5 is carried out in redirect;
Step 4: by existing the abnormal forensics analysis data object for the treatment of to be labeled as object of suspicion, object of suspicion is moved to observation area simultaneously and isolate.
Step 5: the object of suspicion that forensics analysis data object or step 4 obtain for the treatment of to the image file obtaining in step 1 carries out Stego-detection analysis, obtains steganalysis result; The object of suspicion that forensics analysis data object or step 4 obtain for the treatment of to the image file obtaining in step 1 carries out Stego-detection analysis, and its specific implementation process is with reference to abnormal hidden in training set and feature database, to write that model is treated forensics analysis data object or object under a cloud carries out Stego-detection analysis by statistics characteristic analysis method.
Step 6: judge according to steganalysis result whether the abnormal hidden possibility of writing is 0;
If hidden, writing possibility is 0, revolution execution step 1;
If hidden, writing possibility is not 0, and order is carried out following step 7;
Step 7: generate the report of abnormal Stego-detection, represent the abnormal Stego-detection report generating in the anomaly analysis result that obtains in step 2 and step 7.
Ask for an interview Fig. 2, the system that is the present embodiment is the Android digital evidence obtaining analytic system based on interlock synergistic principle, comprises evidence obtaining data acquisition module, abnormality detection analysis module, abnormality juding module, abnormality processing module, Stego-detection analysis module, hiddenly writes determination module and the abnormal hidden forensics analysis of writing represents module;
Evidence obtaining data acquisition module, treats forensics analysis data object for obtaining from image file;
Abnormality detection analysis module, for treating forensics analysis data object according to digital evidence obtaining rule, carry out local flag sign anomaly analysis, treat the principal character of forensics analysis data object and identify and sort according to the significance level playing a role in abnormality detection analysis; Then each local feature for the treatment of successively forensics analysis data object detects, and certain feature existence detected and extremely stops detecting; Otherwise, continue to detect, to the last a feature detection is complete.
Abnormality juding module, for judging and treat that whether forensics analysis data object is abnormal according to anomaly analysis result, if exist extremely, generates abnormality detection report, execute exception processing module; If do not exist extremely, carry out Stego-detection analysis module;
Abnormality processing module, for by existing the abnormal forensics analysis data object for the treatment of to be labeled as object of suspicion, moves to observation area by object of suspicion simultaneously and isolates;
Stego-detection analysis module, abnormal hidden the treat object of suspicion that forensics analysis data object or abnormality processing module obtain of model to the image file of abnormality detection analysis module acquisition of writing for reference to training set and feature database, carries out Stego-detection analysis by statistics characteristic analysis method with reference to the data in training set and feature database;
The hidden determination module of writing, for judging according to Stego-detection analysis result whether the abnormal hidden possibility of writing is 0, and writing possibility if hidden is 0, controls and carries out the data acquisition module of collecting evidence; If hidden, writing possibility is not 0, controls the hidden forensics analysis of writing of execute exception and represents module;
The abnormal hidden forensics analysis of writing represents module, for generating abnormal Stego-detection report, and represents anomaly analysis result and abnormal Stego-detection report.
Should be understood that, the part not elaborating herein all belongs to prior art.
Should be understood that; the above-mentioned description for preferred embodiment is comparatively detailed; can not therefore think the restriction to scope of patent protection of the present invention; those of ordinary skill in the art is under enlightenment of the present invention; do not departing from the scope situation that the claims in the present invention protect; can also make and replacing or distortion, within all falling into protection scope of the present invention, the scope of asking for protection of the present invention should be as the criterion with claims.