Monday, March 23, 2009

Photoshop Forensics

New application JPeg Snoop 1.3 promises to be able to analyze open and attempt to decode any file that contains an embedded JPEG image, such as:

.JPG - JPEG Still Photo
.THM - Thumbnail for RAW Photo / Movie Files
.AVI* - AVI Movies
.DNG - Digital Negative RAW Photo
.CRW, .CR2, .NEF, .ORF, .PEF - RAW Photo
.MOV* - QuickTime Movies, QTVR (Virtual Reality / 360 Panoramic)
.PDF - Adobe PDF Documents

and lets the user know if the JPeg has been tampered with. It looks at quantization table matrix (chrominance and luminance), chroma subsampling, estimates JPEG Quality setting, JPEG resolution settings, Huffman tables, EXIF metadata, Makernotes, RGB histograms, and returns a classifiaction for th target image ranging from:

Class 1 - Image is processed/edited
Class 2 - Image has high probability of being processed/edited
Class 3 - Image has high probability of being original -- NOTE: Please see description below!
Class 4 - Uncertain if processed or original

Once JPEGsnoop has determined a match, it will list out several known editors that use this particular scale, as they are all candidates and can produce the same signature.

No comments: