Forensic analysis of JPEG files Flashcards
When the scaling value is small…
The quality factor is high and storage requirements are larger.
What metadata can you get from a photo?
- Camera make and model
- Camera settings at the time picture was taken
- GPS coordinates for smartphones (e.g. Second gen iPhones).
What is the forensic value of Exif?
- Contains a wealth of information that relates photograph to make and model and possibly owner.
- Easily accessible – Windows file explorer.
What are the drawbacks of Exif?
- Relatively easy to alter or remove.
- Often overwritten by photo-editing software
- Transfer process (e.g. Mobile phone, social networking).
What is Exif?
Exchangeable image file format
What is the forensic value of DQT?
-Indicator of make and model.
- All JPEG file headers have one (even when Exif metadata has been deliberately removed).
What are the drawbacks of DQT?
DQT may be overwritten when:
- Image tampering has taken place (compare with metadata – if still present).
- File is transferred – social networking, mobile phone.
- In some cases primary DQT may be inferred from the histograms of discrete cosine transformation coefficients even if the image has been compressed twice
What is DQT?
Discrete quantization table