论文标题

高效率图像文件格式(HEIF)的法医考虑因素

Forensic Considerations for the High Efficiency Image File Format (HEIF)

论文作者

McKeown, Sean, Russell, Gordon

论文摘要

高效文件格式(HEIF)在2017年被Apple采用,作为他们从相机应用程序中捕获图像的偏爱手段,而Android设备(例如Galaxy S10)最近提供了支持。该格式定位为替换JPEG作为事实上的图像压缩文件类型,在衰老标准上吹捧许多现代功能和更好的压缩比。但是,尽管世界各地数百万个设备已经能够生成HEIF文件,但数字取证研究并没有给予格式的很多关注。由于HEIF是一种复杂的集装箱格式,与传统的静止图片格式有很大不同,因此这使得法医从业者面临着潜在不当证据的风险。本文介绍了HEIF格式的法律相关功能,包括可以用来隐藏数据或在调查中引起问题的特征,同时还提供了有关该格式软件支持状态的评论。最后,在讨论法证性强大的HEIF分析工具的要求之前,提供了当前最佳实践的建议。

The High Efficiency File Format (HEIF) was adopted by Apple in 2017 as their favoured means of capturing images from their camera application, with Android devices such as the Galaxy S10 providing support more recently. The format is positioned to replace JPEG as the de facto image compression file type, touting many modern features and better compression ratios over the aging standard. However, while millions of devices across the world are already able to produce HEIF files, digital forensics research has not given the format much attention. As HEIF is a complex container format, much different from traditional still picture formats, this leaves forensics practitioners exposed to risks of potentially mishandling evidence. This paper describes the forensically relevant features of the HEIF format, including those which could be used to hide data, or cause issues in an investigation, while also providing commentary on the state of software support for the format. Finally, suggestions for current best-practice are provided, before discussing the requirements of a forensically robust HEIF analysis tool.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源