Chapter 9 - Recovering Graphics Files
Chapter 9 - Recovering Graphics Files
and Investigations
Fourth Edition
Chapter 9
Recovering Graphics Files
Objectives
• Characteristics
– Lines and curves instead of dots
– Store only the calculations for drawing lines and
shapes
– Smaller size
– Preserve quality when image is enlarged
• CorelDraw, Adobe Illustrator
Understanding Metafile Graphics
• Carving or salvaging
– Recovering all file fragments
• Computer forensics tools
– Carve from slack and free space
– Help identify image files fragments and put them
together
Searching for and Carving Data from
Unallocated Space
• Steps
– Planning your examination
– Searching for and recovering digital photograph
evidence
• Use ProDiscover to search for and extract (recover)
possible evidence of JPEG files
• False hits are referred to as false positives
Rebuilding File Headers
• Try to open the file first and follow steps if you can’t
see its content
• Steps
– Recover more pieces of file if needed
– Examine file header
• Compare with a good header sample
• Manually insert correct hexadecimal values
– Test corrected file
Reconstructing File Fragments
• Substitution
– Replaces bits of the host file with bits of data
– Usually change the last two LSBs
– Detected with steganalysis tools
• Usually used with image files
– Audio and video options
• Hard to detect
Using Steganalysis Tools