Motorola Rees Scientific Wiping Surfaces Clean - The Definitive Guide Promega Bode Technology Advertise with us
  Wednesday, February 7, 2007
Weekly Newsletter Feature
Caliper Life Sciences
Click to refer a collague!

Steganography: Ticket to Hide

By Douglas Page
Last of three parts
Part one
Part two

In the aftermath of September 11, 2001, several attempts were made to determine whether and to what extent steganographic images were present on the Internet.

One well-publicized University of Michigan study searched over two million eBay images using special detection programs, but was unable to find a single hidden message. Another group examined several hundred thousand random images from various websites with similar negative results.

Although these projects provide a framework for searching a website for steganography images, experts say no conclusions should be drawn from them. Absence of evidence is not evidence of absence.

"One problem is, programs like 'stegdetect' only look at JPEG images," Kessler says. "Other image types-Tiff, PDF, GIF-were never examined. In the other study, only a limited number of websites were examined-far too few to make any definitive statements about the Internet as a whole."

In the event steganography abuse is far more pervasive than anyone is presently aware, federal law enforcement agencies remain eager to develop solid steganographic detection techniques.

"One reason for federal interest is that stego tools have been found in the forensic analysis of computers belonging to some criminals and terrorists," says Hany Farid, a computer science professor at Dartmouth College.

There are few hard statistics, however, about the frequency with which steganography software or media are discovered by law enforcement officials in the course of computer forensics analysis.

"Anecdotal evidence suggests that many computer forensics examiners do not routinely search for steganography software, and many might not recognize such tools if they found it," Kessler says.

One reason is computer forensic examinations can be a lengthy process. A thorough search for evidence of steganography on a suspect hard drive that might contain thousands of images, audio files, and video clips could take several days.

Finding steganographic messages has been equated to finding a needle in a county of haystacks. eBay, for instance, contains millions of images. Farid believes, however, that disabling steganography in a controlled environment like eBay could be easy.

"Forget trying to find the needle in the haystack-just turn the needle into a piece of straw by adding to each image a low-level noise pattern," he says. "The noise will be imperceptible to the user but will destroy the stego message, which, unlike digital watermarks, are highly sensitive to even the simplest attack."

Farid's Dartmouth lab has developed a steganographic tool (www.cs.dartmouth.edu/farid/research/steganography.html) for use in less controlled environments, although he admits that while tools like these will become increasingly more necessary in the future, it will always be possible to hide messages in images in ways that are imperceptible.

"As detection algorithms get better, stego embedding programs will respond by simply embedding smaller amounts of information. At some point it will be nearly impossible to detect small amounts of hidden data," Farid says.

Still, a growing number of digital forensics examiners now consider the search for steganographic tools and/or steganographic media to be a routine part of every examination, although no standards and few protocols have yet to emerge.

"What appears to be lacking is a set of guidelines providing a systematic approach to steganography detection," Kessler says.

Indeed, the 2002 U.S. Department of Justice's "Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations" guidelines does not mention steganography.

Kessler says searching for steganography is not only necessary in criminal investigations and intelligence gathering operations, but forensic accounting investigators are realizing the need to search for steganography as this has also become a viable way to hide financial records.

While it is impossible to know how widespread the current use of steganography is by criminals and terrorists, it may not matter. Kessler believes it is safe to assume the worst.

The use of steganography is certain to increase and will be a growing hurdle for law enforcement and counterterrorism activities, Kessler predicts.

"Ignoring the significance of steganography because of the lack of statistics is security through denial-not a very good strategy," he says.

Part one: When it comes to digital photos, what you see may not be what you get

Part two: Steganography: Flying under the radar

Untitled Document
 

Free Product Info | Free Magazine Subscription | Article Index | Digital Issues | Ad Services

 
Author Guidelines |Shows Conferences, and Events | Contact Forensic Magazine
 
| About Web Feeds| Home

Copyright 2006 by
Vicon Publishing, Inc. All Rights Reserved BPA Worldwide Membership Applied For | Terms of Use | Privacy Policy
Design & Maintenance by S. La Palme Designs®