Identifying forensically uninteresting files in a large corpus
Neil C. Rowe · ICST Transactions on Security and Safety · 2016
For digital forensics, eliminating the uninteresting is often more critical than finding the interesting. We discuss methods exploiting the metadata of a large corpus. Tests were done with an international corpus of 262.7 million files obtained from 4018 drives. For malware investigations, we sho