HOTSEC'08 Proceedings of the 3rd conference on Hot topics in security
Forensic analysis of the Windows registry in memory
Digital Investigation: The International Journal of Digital Forensics & Incident Response
Recovering deleted data from the Windows registry
Digital Investigation: The International Journal of Digital Forensics & Incident Response
A framework for avoiding steganography usage over HTTP
Journal of Network and Computer Applications
Windows Mobile LiveSD Forensics
Journal of Network and Computer Applications
Hi-index | 0.00 |
Images and data, such as child pornography and credit card numbers, can be hidden in files through the use of steganography. Many steganography programs are freely available on the Internet. Searching data files for hidden, embedded content through steganalysis is a time-consuming process. Often steganography programs leave traces behind, such as files, directories, or registry keys, even after they have been removed or uninstalled from the system. An alternative to steganalysis is for a forensic investigator to perform a quick search for these telltale indications that steganography has been used. In this paper, we present the results of a study to detect traces left behind after a number of freely available steganography tools were installed, run, and uninstalled.