topic 11 - forensic analysis of JPEG files Flashcards
what is metadata of exchangeable image file format aka EXIF?
camera make and model
camera settings at time picture was taken
gps coordinates for smart phones (e.g. Second gen iPhones).
what is the forensic value of EXIF?
Contains a wealth of information that relates photograph to make and model and possibly owner.
Easily accessible – Windows file explorer.
Downside: Relatively easy to alter or remove.
Often overwritten by
photo-editing software
Transfer process (e.g. Mobile phone, social networking).
what is the value of DQT to forensics? (Discrete quantisation table)
Indicator of make and model.
All JPEG files headers have one (even when Exif metadata has been deliberately removed).
DQT may be overwritten when
Image tampering has taken place (compare with metadata – if still present).
File is transferred – social networking, mobile phone.
In some cases primary DQT may be inferred from the histograms of discrete cosine transformation coefficients even if the image has been compressed twice…