Key Points
Introduction
By the end of this workshop, you should be able to:
- Investigate a file format and find patterns
- Express patterns in PRONOM syntax
- Create a signature file
- Use your signature file locally
- Contribute signatures to PRONOM
It isn’t just the beginning of your PRONOM journey, it’s the
beginning of your digital forensics journey!
Enjoy!
Talking with Computers
- Computers store everything as bits: switches that are either on or off.
- 8 bits make a byte, and a byte holds one of 256 values.
- Binary, hexadecimal and encodings such as UTF-8 or ASCII are three ways of writing the same thing.
- Hexadecimal is the one we work with in file format analysis.
Hexadecimal
- Hexadecimal is a number system.
- Hexadecimal makes it easier to understand “binary”.
- Hexadecimal is mapped to signals and characters that have meaning to a computer.
- Hexadecimal can take on arbitrary meaning through “encodings”.
- Hexadecimal is the foundation for a PRONOM signature!
Using a hex editor
- HexEd.it is an online Hex Editor. HxD is a popular desktop alternative
- Hex Editors display a byte-level representation of file - both Hexadecimal and ‘ASCII’
- The ASCII view can be limiting because not every byte translates directly to a human-meaningful character. E.g. 0x00-1F control characters are usually represented as periods (dots) or spaces
- Hex Editors are used in File Forensics, reverse engineering, understanding file formats at a low-level
- Remember Safety First - it’s called an ‘editor’ for a reason, so to avoid the risk of corrupting your own originals, always work with a copy of your original files
Looking for patterns
- The more samples from different versions of the format can ensure better identification.
- Not all formats have available specifications
- The more variations in samples, patterns emerge.
Introducing PRONOM syntax
- A PRONOM file format (PUID) can be associated with more than one signature, but only needs to match one full signature to return a positive hit
- A signature can consist of multiple sequences, and all sequences must match to return a positive hit
- PRONOM syntax is a form of regular expression (regex), although distinct from regex implementations in Java, Python etc.
- PRONOM sequences can be anchored relative to the beginning of the file (BOF), the end of the file (EOF), or anywhere within the file (Variable), however it is best practice to include at least one BOF or EOF anchor to avoid unnecessary full scans of files
- PRONOM syntax can be combined in multiple ways
- Sometimes there is more than one way to write a signature
Reversing PRONOM syntax
- A file you have created by reversing a PRONOM signature is called a skeleton file
- You can reverse engineer PRONOM signatures to investigate existing patterns and existing files
- By comparing sequences in skeleton files and seeing how they align with known files in the hex editor you can understand if a pattern should match if it is not always obvious, e.g. due to complexity
- Reversing PRONOM syntax has other uses, e.g. creating skeleton files.
Creating signature files
- A signature file is a set of instructions for DROID.
- You can create signature files using the Signature Development Utility.
- A signature file is separated into sections.
- One section is used for metadata about identification results.
- Another section is used to store the instructions for identification.
Plugging it in
- You can use any tool!
- There are different merits to each.
Doing it for yourself
- You’ve all the tools needed to write file format signatures.
- It might not always work.
- It will certainly take trial and error.
- Persevere and keep working on it.
- Practice makes perfect!
Teaching us how to do it!
- Seeing one, doing one, teaching one allows you to reinforce what you’ve learned.
- Teaching one helps you to externalize and formalize your language around this work making it easier to articulate in future in other forums.
Advanced PRONOM
- Much of this effort is researching files and writing a signature, but another big part is testing, calibration, AND documentation.
- The Just Solve It and COPTR wikis are complimentary resources that can be used as landing zones as we collect information early on about file format signatures or as we develop them.
- The FAQ and Glossary are available for quick reference whenever you need them in your signature development journey.
Final thoughts
- It might look scary at first, but take your time, explore, and enjoy!
- There’s help out there.
- Keep in touch!