@inproceedings{0263cb91dab54b27bfb1a21025a8f57a,
title = "NULL Byte Injection: Anti-Forensic Technique for Data Hiding in FAT32 File System",
abstract = "In the FAT32 file system, a null byte in the metadata means that there is no file or folder. Since the metadata are stored consecutively, if the first byte of a metadata field is null, the operating system does not read data anymore. In this study, we propose an anti-forensic technique referred to as {"}NULL Byte injection{"}, which hides files or folders by injecting null bytes into the metadata field of the FAT32 file system. We presented 3 injection methods for hiding, and we evaluated the effectiveness and limitations of each injection method through experiments. As a result, we confirmed that our technique can hide files or folders in Windows OS. Based on the injection method, different effects were observed. We also confirmed that our methods can hide files or folders and bypass the detection of several forensic tools. Our technique can contribute to preventing such anti-forensic attacks by exploiting the mechanism of the file system to hide data.",
keywords = "anti-forensics, data hiding, digital forensics, directory entry, FAT32, file system",
author = "Donghyun Kim and Lee, \{Youn Kyu\} and Jongwook Jeong",
note = "Publisher Copyright: {\textcopyright} 2022 ACM.; 23rd ACM International Symposium on Mobile Ad Hoc Networking and Computing, MobiHoc 2022 ; Conference date: 17-10-2022 Through 20-10-2022",
year = "2022",
month = oct,
day = "3",
doi = "10.1145/3492866.3558587",
language = "English",
series = "Proceedings of the International Symposium on Mobile Ad Hoc Networking and Computing (MobiHoc)",
publisher = "Association for Computing Machinery",
pages = "265--270",
booktitle = "MobiHoc 2022 - Proceedings of the 2022 23rd International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing",
}