计算机应用 ›› 2011, Vol. 31 ›› Issue (02): 527-529.

• 信息安全 • 上一篇    下一篇

Windows下基于文件特征的数据恢复算法

胡敏1,杨吉云2,姜维2   

  1. 1. 重庆大学计算机学院
    2.
  • 收稿日期:2010-07-30 修回日期:2010-09-14 发布日期:2011-02-01 出版日期:2011-02-01
  • 通讯作者: 胡敏
  • 基金资助:
    中央高校基本科研业务费

Data recovery algorithm based on file feature on Windows platform

  • Received:2010-07-30 Revised:2010-09-14 Online:2011-02-01 Published:2011-02-01

摘要: 针对Windows系统下的数据丢失,尤其是在文件系统目录信息丢失的情况下,提出一种基于文件特征的数据恢复算法。该算法通过全盘深粒度扫描磁盘扇区并根据各种类型文件的头部和尾部特征码在磁盘中匹配确定文件的起始和结束扇区,从而根据文件起始、结束扇区之间数据重建恢复此类型文件。并针对由于数据被部分覆盖或其他原因而使恢复出的Word文档无法显示其内容的情况,根据Word文档结构及字符数据在其中的编码特点提取用户最感兴趣的字符信息。实验表明该算法具有良好的性能。

关键词: 数据恢复, 文件系统, 文件特征, 字符信息提取

Abstract: In order to solve the problem of data recovery in Windows system, a recovery algorithm based on file feature, especially when the directory data of the file system was lost, was presented in this paper. The algorithm identified the start and end sector of the lost file by scanning all sectors of the disk and matched them according to the head and foot feature codes of the lost files, then recovered the files by restoring the data between the start and the end sector. Concerning that the restored word documents could not be displayed as a result of their partial data being covered or some other reasons, the users most interested characters in terms of the word document structure and coding rules of the characters were extracted. The experimental results show that the proposed algorithm has good performance.

Key words: data recovery, file system, file feature, character information extraction