{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T21:47:22Z","timestamp":1769636842051,"version":"3.49.0"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319462783","type":"print"},{"value":"9783319462790","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-46279-0_17","type":"book-chapter","created":{"date-parts":[[2016,9,19]],"date-time":"2016-09-19T02:24:39Z","timestamp":1474251879000},"page":"325-343","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Data Type Classification: Hierarchical Class-to-Type Modeling"],"prefix":"10.1007","author":[{"given":"Nicole","family":"Beebe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lishu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minghe","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,9,20]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"Ahmed, I., Lhee, K., Shin, H., Hong, M.: On improving the accuracy and performance of content-based file type identification. In: Proceedings of the Fourteenth Australasian Conference on Information Security and Privacy, pp. 44\u201359 (2009)","DOI":"10.1007\/978-3-642-02620-1_4"},{"key":"17_CR2","doi-asserted-by":"crossref","unstructured":"Ahmed, I., Lhee, K., Shin, H., Hong, M.: Fast file type identification. In: Proceedings of the ACM Symposium on Applied Computing, pp. 1601\u20131602 (2010)","DOI":"10.1145\/1774088.1774431"},{"key":"17_CR3","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-642-24212-0_5","volume-title":"Advances in Digital Forensics VII","author":"I Ahmed","year":"2011","unstructured":"Ahmed, I., Lhee, K.-S., Shin, H.-J., Hong, M.-P.: Fast content-based file type identification. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2011. IAICT, vol. 361, pp. 65\u201375. Springer, Heidelberg (2011). doi: 10.1007\/978-3-642-24212-0_5"},{"key":"17_CR4","doi-asserted-by":"crossref","unstructured":"Amirani, M., Toorani, M., Beheshti, A.: A new approach to content-based file type detection. In: Proceedings of the IEEE Symposium on Computers and Communications, pp. 1103\u20131108 (2008)","DOI":"10.1109\/ISCC.2008.4625611"},{"issue":"1","key":"17_CR5","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1002\/sec.553","volume":"6","author":"M Amirani","year":"2013","unstructured":"Amirani, M., Toorani, M., Mihandoost, S.: Feature-based type identification of file fragments. Security and Communication Networks 6(1), 115\u2013128 (2013)","journal-title":"Security and Communication Networks"},{"key":"17_CR6","doi-asserted-by":"crossref","unstructured":"Axelsson, S.: Using normalized compression distance for classifying file fragments. In: Proceedings of the International Conference on Availability, Reliability and Security, pp. 641\u2013646 (2010)","DOI":"10.1109\/ARES.2010.100"},{"key":"17_CR7","unstructured":"Beebe, N.: UTSA Filetypes 1 Data Set. Department of Information Systems and Cyber Security, University of Texas at San Antonio, San Antonio, Texas (2016). digitalcorpora.org\/corp\/files\/filetypes1"},{"issue":"S2","key":"17_CR8","doi-asserted-by":"publisher","first-page":"S124","DOI":"10.1016\/j.diin.2014.05.007","volume":"11","author":"N Beebe","year":"2014","unstructured":"Beebe, N., Liu, L.: Ranking algorithms for digital forensic string search hits. Digital Investigation 11(S2), S124\u2013S132 (2014)","journal-title":"Digital Investigation"},{"issue":"9","key":"17_CR9","doi-asserted-by":"publisher","first-page":"1519","DOI":"10.1109\/TIFS.2013.2274728","volume":"8","author":"N Beebe","year":"2013","unstructured":"Beebe, N., Maddox, L., Liu, L., Sun, M.: Sceadan: Using concatenated $$n$$-gram vectors for improved file and data type classification. IEEE Transactions on Information Forensics and Security 8(9), 1519\u20131530 (2013)","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"S","key":"17_CR10","doi-asserted-by":"publisher","first-page":"S14","DOI":"10.1016\/j.diin.2008.05.005","volume":"5","author":"W Calhoun","year":"2008","unstructured":"Calhoun, W., Coles, D.: Predicting the types of file fragments. Digital Investigation 5(S), S14\u2013S20 (2008)","journal-title":"Digital Investigation"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Cao, D., Luo, J., Yin, M., Yang, H.: Feature-selection-based file type identification algorithm. In: Proceedings of the IEEE International Conference on Intelligent Computing and Intelligent Systems, vol. 3, pp. 58\u201362 (2010)","DOI":"10.1109\/ICICISYS.2010.5658559"},{"issue":"S","key":"17_CR12","doi-asserted-by":"publisher","first-page":"S3","DOI":"10.1016\/j.diin.2010.05.002","volume":"7","author":"G Conti","year":"2010","unstructured":"Conti, G., Bratus, S., Shubina, A., Sangster, B., Ragsdale, R., Supan, M., Lichtenberg, A., Perez-Alemany, R.: Automated mapping of large binary objects using primitive fragment type classification. Digital Investigation 7(S), S3\u2013S12 (2010)","journal-title":"Digital Investigation"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Erbacher, R., Mulholland, J.: Identification and localization of data types within large-scale filesystems. In: Proceedings of the Second International Workshop on Systematic Approaches to Digital Forensic Engineering, pp. 55\u201370 (2007)","DOI":"10.1109\/SADFE.2007.12"},{"issue":"S","key":"17_CR14","doi-asserted-by":"publisher","first-page":"S44","DOI":"10.1016\/j.diin.2012.05.008","volume":"9","author":"S Fitzgerald","year":"2012","unstructured":"Fitzgerald, S., Mathews, G., Morris, C., Zhulyn, O.: Using NLP techniques for file fragment classification. Digital Investigation 9(S), S44\u2013S49 (2012)","journal-title":"Digital Investigation"},{"issue":"S","key":"17_CR15","doi-asserted-by":"publisher","first-page":"S2","DOI":"10.1016\/j.diin.2009.06.016","volume":"6","author":"S Garfinkel","year":"2009","unstructured":"Garfinkel, S., Farrell, P., Roussev, V., Dinolt, G.: Bringing science to digital forensics with standardized forensic corpora. Digital Investigation 6(S), S2\u2013S11 (2009)","journal-title":"Digital Investigation"},{"key":"17_CR16","doi-asserted-by":"crossref","unstructured":"Gopal, S., Yang, Y., Salomatin, K., Carbonell, J.: Statistical learning for file type identification. In: Proceedings of the Tenth International Conference on Machine Learning and Applications, vol. 1, pp. 68\u201373 (2011)","DOI":"10.1109\/ICMLA.2011.135"},{"key":"17_CR17","unstructured":"Hall, G., Davis, W.: Sliding Window Measurement for File Type Identification, Technical Report, Department of Computer Science, Texas State University-San Marcos, San Marcos, Texas (2006)"},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Karresand, M., Shahmehri, N.: File type identification of data fragments by their binary structure. In: Proceedings of the IEEE Information Assurance Workshop, pp. 140\u2013147 (2006)","DOI":"10.1109\/IAW.2006.1652088"},{"key":"17_CR19","doi-asserted-by":"crossref","first-page":"413","DOI":"10.1007\/0-387-33406-8_35","volume-title":"Security and Privacy in Dynamic Environments","author":"Martin Karresand","year":"2006","unstructured":"Karresand, M., Shahmehri, N.: Oscar - File type identification of binary data in disk clusters and RAM pages. In: Proceedings of the Twenty-First IFIP TC-11 International Conference on Information Security, pp. 413\u2013424 (2006)"},{"key":"17_CR20","unstructured":"Li, Q., Ong, A., Suganthan, P., Thing, V.: A novel support vector machine approach to high-entropy data fragment classification. In: Proceedings of the South African Information Security Multi-Conference (2011)"},{"key":"17_CR21","unstructured":"Li, W., Wang, K., Stolfo, S., Herzog, B.: Fileprints: identifying file types by $$n$$-gram analysis. In: Proceedings of the Sixth Annual IEEE SMC Information Assurance Workshop, pp. 64\u201371 (2005)"},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"McDaniel, M., Heydari, M.: Content-based file type detection algorithms. In: Proceedings of the Thirty-Sixth Annual Hawaii International Conference on System Sciences (2003)","DOI":"10.1109\/HICSS.2003.1174905"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Moody, S., Erbacher, R.: SADI - statistical analysis for data type identification. In: Proceedings of the Third International Workshop on Systematic Approaches to Digital Forensic Engineering, pp. 41\u201354 (2008)","DOI":"10.1109\/SADFE.2008.13"},{"key":"17_CR24","doi-asserted-by":"crossref","unstructured":"Roussev, V., Garfinkel, S.: File fragment classification - the case for specialized approaches. In: Proceedings of the Fourth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering, pp. 3\u201314 (2009)","DOI":"10.1109\/SADFE.2009.21"},{"key":"17_CR25","doi-asserted-by":"crossref","unstructured":"Veenman, C.: Statistical disk cluster classification for file carving. In: Proceedings of the Third International Symposium on Information Assurance and Security, pp. 393\u2013398 (2007)","DOI":"10.1109\/IAS.2007.75"},{"key":"17_CR26","doi-asserted-by":"crossref","unstructured":"Zhang, L., White, G.: An approach to detect executable content for anomaly-based network intrusion detection. In: Proceedings of the IEEE International Symposium on Parallel and Distributed Processing (2007)","DOI":"10.1109\/IPDPS.2007.370614"}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics XII"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-46279-0_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,10]],"date-time":"2025-06-10T19:48:46Z","timestamp":1749584926000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-46279-0_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319462783","9783319462790"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-46279-0_17","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]},"assertion":[{"value":"20 September 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DigitalForensics","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Digital Forensics","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New Delhi","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2016","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 January 2016","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 January 2016","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"digitalforensics2016","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}