IEEJ Transactions on Electronics, Information and Systems
Online ISSN : 1348-8155
Print ISSN : 0385-4221
ISSN-L : 0385-4221
<Information Processing, Software>
Detection Method of the Remaining Files Based on Logs Regarding Changed Directory and Hash Values
Chikako IshizawaYuu AndohMakoto Nishida
Author information
JOURNAL FREE ACCESS

2010 Volume 130 Issue 11 Pages 2074-2083

Details
Abstract

There are a lot of information leakages because the files are copied from the removable storage medium and are left in the storage unit of personal computer without deleting. In order to prevent human mistakes, this paper proposes a method for detecting the remaining files copied from the removable storage medium. The proposed method records logs regarding changed information registering in a directory that is management list of files in storage unit and the hash values of file contents. The remaining files are detected when the removable storage medium removes from the personal computer, and they are displayed on the monitor. The detection processing works in five steps. First, copy operation toward file is detected by tracing the sequence of logs. Secondly, files copied from the removable storage medium are distinguished based on hash values. Thirdly, file operation and folder operation to copied files are distinguished. Fourthly, the deletion operation against the copied file is detected by using file name and path matching. Finally, file name and path using for tracing are changed according to folder operation. In case of the deletion operation is not found, it is judged that copied files are remaining. Our experimental result suggests that the proposed method can accurately detect remaining files left on the storage unit.

Content from these authors
© 2010 by the Institute of Electrical Engineers of Japan
Previous article Next article
feedback
Top