Practical Applications of Bloom filters to the NIST RDS and hard drive triage
Garfinkel, Simson L.
MetadataShow full item record
Much effort has been expended in recent years to create large sets of hash codes from known files. Distributing these sets has become more difficult as these sets grow larger. Meanwhile the value of these sets for eliminating the need to analyze "known goods" has decreased as hard drives have dramatically increased in storage capacity. This paper evaluates the use of Bloom filters (BFs) to distribute the National Software Reference Library's (NSRL) Reference Data Set (RDS) version 2.19, with 13 million SHA-1 hashes. We present an open source reference BF implementation and validate it against a large collection of disk images. We discuss the tuning of the filters, discuss how they can be used to enable new forensic functionality, and present a novel attack against bloom filters.
Annual Computer Security Applications Conference 2008, Anaheim, California, December 2008.Refereed Conference Paper
RightsThis publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.
Showing items related by title, author, creator and subject.
Lynn, Freddie Leroy, Jr. (Monterey, California ; Naval Postgraduate School, 1970-06);This manuscript is a collection of many of the known results in the theory of generalized filters (ß-filters) as well as an extension of some of the work in this area. The relation of ß-filters to compactifications and ...
Using Local Optimality Criteria for Efficient Information Retrieval with Redundant Information Filters Rowe, Neil C. (Monterey, California: Naval Postgraduate School., 1998);We consider information retrieval when the data, for instance multimedia, is coputationally expensive to fetch. Our approach uses "information filters" to considerably narrow the universe of possiblities before retrieval. ...
Using local optimality criteria for efficient information retrieval with redundant information filters Rowe, Neil C. (Monterey, California. Naval Postgraduate School, 1994); NPS-CS-94-004We consider information retrieval when the data, for instance multimedia, is computationally expensive to fetch. Our approach uses information filters to considerably narrow the universe of possibilities before retrieval. ...