The application provides a file aggregation identification method and
system, and belongs to the technical field of
electronic data forensics, and aims to solve the problems of traditional forensics tools relying on file extensions, complicated operation, mixed
system analysis
confusion and weak non-standard file analysis capability. The core of the method is a four-stage linkage analysis engine: through double checking of file suffix and binary header characteristics, initial screening of file type is realized; through detecting
file system identification and verifying
system specific path / configuration file, deep identification of
image type is realized; through analyzing special
metadata structure and storage format, intelligent analysis of
backup files is realized; through entropy weighting
algorithm, dynamic
weight analysis and conflict arbitration are realized. The corresponding system includes four function modules. The application can automatically identify smartphone images, backups and non-standard data files, reduce the misjudgment rate, improve the analysis efficiency by 3.8 times, has strong anti-interference ability, high
automation degree and excellent compatibility, and is suitable for complex
electronic data forensics scenes.