Back to results

University of New Orleans

Bloom Filters for Filesystem Forensics

Abstract

dc:description.abstract

Digital forensics investigations become more time consuming as the amount of data to be investigated grows. Secular growth trends between hard drive and memory capacity just exacerbate the problem. Bloom filters are space-efficient, probabilistic data structures that can represent data sets with quantifiable false positive rates that have the potential to alleviate the problem by reducing space requirements. We provide a framework using Bloom filters to allow fine-grained content identification to detect similarity, instead of equality. We also provide a method to compare filters directly and a statistical means of interpreting the results. We developed a tool--md5bloom--that uses Bloom filters for standard queries and direct comparisons. We provide a performance comparison with a commonly used tool, md5deep, and achieved a 50% performance gain that only increases with larger hash sets. We compared filters generated from different versions of KNOPPIX and detected similarities and relationships between the versions.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Computer Science
Year
2006

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Bourg, Rachel
Contributors dc:contributor
  • Roussev, Vassil
  • Richard, Golden
  • Deng, Jing

Subjects

dc:subject × 2

Identifiers

dc:identifier.*
Repository record dc:identifier
https://scholarworks.uno.edu/td/1288
OAI identifier oai:identifier
oai:scholarworks.uno.edu:td-2271

Chain of custody

source
Harvested from
University of New Orleans
Base URL
scholarworks.uno.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Bourg, Rachel. Bloom Filters for Filesystem Forensics. Thesis thesis, 2006. https://scholarworks.uno.edu/td/1288