Skip to main navigation Skip to search Skip to main content

NULL Byte Injection: Anti-Forensic Technique for Data Hiding in FAT32 File System

    • Korea Military Academy
    • Hongik University

    Research output: Contribution to conferenceConference paperpeer-review

    Abstract

    In the FAT32 file system, a null byte in the metadata means that there is no file or folder. Since the metadata are stored consecutively, if the first byte of a metadata field is null, the operating system does not read data anymore. In this study, we propose an anti-forensic technique referred to as "NULL Byte injection", which hides files or folders by injecting null bytes into the metadata field of the FAT32 file system. We presented 3 injection methods for hiding, and we evaluated the effectiveness and limitations of each injection method through experiments. As a result, we confirmed that our technique can hide files or folders in Windows OS. Based on the injection method, different effects were observed. We also confirmed that our methods can hide files or folders and bypass the detection of several forensic tools. Our technique can contribute to preventing such anti-forensic attacks by exploiting the mechanism of the file system to hide data.

    Original languageEnglish
    Title of host publicationMobiHoc 2022 - Proceedings of the 2022 23rd International Symposium on Theory, Algorithmic Foundations, and Protocol Design for Mobile Networks and Mobile Computing
    PublisherAssociation for Computing Machinery
    Pages265-270
    Number of pages6
    ISBN (Electronic)9781450391658
    DOIs
    StatePublished - 2022.10.3
    Event23rd ACM International Symposium on Mobile Ad Hoc Networking and Computing, MobiHoc 2022 - Seoul, Korea, Republic of
    Duration: 2022.10.172022.10.20

    Publication series

    NameProceedings of the International Symposium on Mobile Ad Hoc Networking and Computing (MobiHoc)

    Conference

    Conference23rd ACM International Symposium on Mobile Ad Hoc Networking and Computing, MobiHoc 2022
    Country/TerritoryKorea, Republic of
    CitySeoul
    Period22.10.1722.10.20

    Keywords

    • anti-forensics
    • data hiding
    • digital forensics
    • directory entry
    • FAT32
    • file system

    Quacquarelli Symonds(QS) Subject Topics

    • Computer Science & Information Systems

    Fingerprint

    Dive into the research topics of 'NULL Byte Injection: Anti-Forensic Technique for Data Hiding in FAT32 File System'. Together they form a unique fingerprint.

    Cite this