電気学会論文誌C(電子・情報・システム部門誌)
Online ISSN : 1348-8155
Print ISSN : 0385-4221
<情報処理・ソフトウェア>
ディレクトリの変更履歴およびハッシュ値に基づいた残留ファイルの検出手法
石沢 千佳子安藤 優西田 眞
著者情報
ジャーナル 認証あり

130 巻 (2010) 11 号 p. 2074-2083

詳細
PDFをダウンロード (476K) 発行機関連絡先
抄録

There are a lot of information leakages because the files are copied from the removable storage medium and are left in the storage unit of personal computer without deleting. In order to prevent human mistakes, this paper proposes a method for detecting the remaining files copied from the removable storage medium. The proposed method records logs regarding changed information registering in a directory that is management list of files in storage unit and the hash values of file contents. The remaining files are detected when the removable storage medium removes from the personal computer, and they are displayed on the monitor. The detection processing works in five steps. First, copy operation toward file is detected by tracing the sequence of logs. Secondly, files copied from the removable storage medium are distinguished based on hash values. Thirdly, file operation and folder operation to copied files are distinguished. Fourthly, the deletion operation against the copied file is detected by using file name and path matching. Finally, file name and path using for tracing are changed according to folder operation. In case of the deletion operation is not found, it is judged that copied files are remaining. Our experimental result suggests that the proposed method can accurately detect remaining files left on the storage unit.

著者関連情報
© 電気学会 2010
前の記事 次の記事

閲覧履歴
ジャーナルのニュースとお知らせ
  • 【電気学会会員の方】購読している論文誌を無料でご覧いただけます(会員ご本人のみの個人としての利用に限ります)。購読者番号欄にMyページへのログインIDを,パスワード欄に生年月日8ケタ(西暦,半角数字。例:19800303)を入力して下さい。
ダウンロード
  • 論文(PDF)の閲覧方法はこちら
    閲覧方法 (389.7K)
関連情報

J-STAGEがリニューアルされました!  https://www.jstage.jst.go.jp/browse/-char/ja/

feedback
Top