{"id":{"repo_id":"wvu","oai_identifier":"oai:researchrepository.wvu.edu:etd-1340"},"canonical_url":"https://search.dev.ndltd.org/etd/wvu/oai:researchrepository.wvu.edu:etd-1340","repository":{"repo_id":"wvu","name":"West Virginia University","base_url":"https://researchrepository.wvu.edu/do/oai/"},"display":{"title":"Detection and Identification of Software Encryption Solutions in NT-based Microsoft Windows Operating Systems","abstract":"As encrypted information is very difficult or impossible to reconstruct, there are many situations in which it is critical to detect the presence of encryption software before a computer is shut down. Currently there is no solution that reliably identifies installed encryption software.;For this investigation, thirty encryption software products for Microsoft Windows based on the NT-kernel have been identified and investigated. Operating system dependent factors such as registry, file attributes, operating system attributes, process list analysis and independent factors such as file headers, keyword search, Master Boot Record analysis as well as hashing of software components were investigated and allow the identification of these programs. The most reliable detection rate is achieved through a combination of the aforementioned factors.","abstract_html":"As encrypted information is very difficult or impossible to reconstruct, there are many situations in which it is critical to detect the presence of encryption software before a computer is shut down. Currently there is no solution that reliably identifies installed encryption software.;For this investigation, thirty encryption software products for Microsoft Windows based on the NT-kernel have been identified and investigated. Operating system dependent factors such as registry, file attributes, operating system attributes, process list analysis and independent factors such as file headers, keyword search, Master Boot Record analysis as well as hashing of software components were investigated and allow the identification of these programs. The most reliable detection rate is achieved through a combination of the aforementioned factors.","abstract_has_math":false,"creators":["Breyer, Julian"],"institution":null,"degree_name":"MS","degree_level":"Thesis","degree_discipline":"Lane Department of Computer Science and Electrical Engineering","degree_department":null,"school":null,"contributors":["Roy Nutter","Katerina Goseva-Popstojanova","James Mooney"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2013,"date_issued":"2013-05-01T07:00:00Z","date_published":"2013-05-01T07:00:00Z","updated_at":"2026-07-24T06:14:24Z","subjects":["Computer science"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["https://researchrepository.wvu.edu/etd/337"],"render_values":[{"text":"https://researchrepository.wvu.edu/etd/337","href":"https://researchrepository.wvu.edu/etd/337","code":true}]}]},"links":{"outbound_url":"https://doi.org/10.33915/etd.337","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Roy Nutter","Katerina Goseva-Popstojanova","James Mooney"]},{"key":"dc:creator","label":"Author","values":["Breyer, Julian"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2018-10-29T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Lane Department of Computer Science and Electrical Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["MS"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer science"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://doi.org/10.33915/etd.337","https://researchrepository.wvu.edu/etd/337"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["As encrypted information is very difficult or impossible to reconstruct, there are many situations in which it is critical to detect the presence of encryption software before a computer is shut down. Currently there is no solution that reliably identifies installed encryption software.;For this investigation, thirty encryption software products for Microsoft Windows based on the NT-kernel have been identified and investigated. Operating system dependent factors such as registry, file attributes, operating system attributes, process list analysis and independent factors such as file headers, keyword search, Master Boot Record analysis as well as hashing of software components were investigated and allow the identification of these programs. The most reliable detection rate is achieved through a combination of the aforementioned factors."]},{"key":"dc:title","label":"Title","values":["Detection and Identification of Software Encryption Solutions in NT-based Microsoft Windows Operating Systems"]}]}],"canonical_facts":{"dc:contributor":["Roy Nutter","Katerina Goseva-Popstojanova","James Mooney"],"dc:creator":["Breyer, Julian"],"dc:date.available":["2018-10-29T07:00:00Z"],"dc:description.abstract":["As encrypted information is very difficult or impossible to reconstruct, there are many situations in which it is critical to detect the presence of encryption software before a computer is shut down. Currently there is no solution that reliably identifies installed encryption software.;For this investigation, thirty encryption software products for Microsoft Windows based on the NT-kernel have been identified and investigated. Operating system dependent factors such as registry, file attributes, operating system attributes, process list analysis and independent factors such as file headers, keyword search, Master Boot Record analysis as well as hashing of software components were investigated and allow the identification of these programs. The most reliable detection rate is achieved through a combination of the aforementioned factors."],"dc:identifier":["https://doi.org/10.33915/etd.337","https://researchrepository.wvu.edu/etd/337"],"dc:subject":["Computer science"],"dc:title":["Detection and Identification of Software Encryption Solutions in NT-based Microsoft Windows Operating Systems"],"thesis:degree_discipline":["Lane Department of Computer Science and Electrical Engineering"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["MS"]},"updated_at":"2026-07-24T06:14:24Z"}