Forensic analysis of residual information in adobe PDF files

2Citations
Citations of this article
13Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In recent years, as electronic files include personal records and business activities, these files can be used as important evidences in a digital forensic investigation process. In general, the data that can be verified using its own application programs is largely used in the investigation of document files. However, in the case of the PDF file that has been largely used at the present time, certain data, which include the data before some modifications, exist in electronic document files unintentionally. Because such residual information may present the writing process of a file, it can be usefully used in a forensic viewpoint. This paper introduces why the residual information is stored inside the PDF file and explains a way to extract the information. In addition, we demonstrate the attributes of PDF files can be used to hide data. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Chung, H., Park, J., & Lee, S. (2011). Forensic analysis of residual information in adobe PDF files. In Communications in Computer and Information Science (Vol. 185 CCIS, pp. 100–109). https://doi.org/10.1007/978-3-642-22309-9_12

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free