Skip to content
CY-702 (D) · Multimedia Security & Forensics/Quick Revision Short Notes

Multimedia Security & Forensics (CY-702 (D)) - Unit 2 Short Notes

UNIT 2: MULTIMEDIA SECURITY & FORENSICS

Based on the November 2023 examination paper for CY-702(D), the following notes cover the assessed topics with high-yield definitions, processes, and scenario-based reasoning.


I. MULTIMEDIA SYSTEMS & FUNDAMENTAL TECHNOLOGIES

A. Compression Techniques

  • Discrete Cosine Transform (DCT):

    • Purpose: Core mathematical tool in lossy compression (JPEG, MPEG). Converts spatial domain pixel data into frequency domain coefficients.

    • Process: Image is divided into 8x8 pixel blocks. DCT transforms each block, concentrating most signal energy into low-frequency coefficients (top-left). High-frequency coefficients (bottom-right) often become zero or near-zero.

    • Lossy Mechanism: Quantization step rounds off these DCT coefficients, irreversibly discarding less important high-frequency data, leading to compression artifacts at high compression ratios.

    • Key Formula (for an N×N block):

$$F(u,v) = \frac{1}{N} C(u) C(v) \sum_{x=0}^{N-1} \sum_{y=0}^{N-1} f(x,y) \cos\left(\frac{(2x+1)u\pi}{2N}\right) \cos\left(\frac{(2y+1)v\pi}{2N}\right)$$

    where $$\displaystyle C(k) = \frac{1}{\sqrt{2}} $$ for $$\displaystyle k=0 $$, else $1$.

    \boxed{F(u,v) \text{ are DCT coefficients}}
  • Lossy vs. Lossless Compression:

    • Lossy: Permanently discards perceptually less important data (e.g., DCT quantization). Achieves high compression ratios (e.g., 10:1 to 100:1). Used for distribution (JPEG, MP3, MPEG). Irreversible.

    • Lossless: Preserves all original data exactly. Uses redundancy removal (e.g., Huffman coding in PNG, FLAC). Low compression ratios (2:1 to 5:1). Essential for archival, medical, or forensic master copies. Reversible.

[!TIP] Exam often asks why DCT is lossy. Focus on the quantization step as the point of irreversible data loss, not the transform itself.

B. Interdisciplinary Nature of Multimedia

  • Statement Meaning: Modern multimedia systems (creation, processing, delivery, security) are not built by single-vendor silos. They converge technologies from telecom, computing, consumer electronics, and content industries.

  • Examples of Merged Vendor Ecosystems:

    • Apple: Hardware (iPhone, Mac) + OS (iOS/macOS) + Software (Final Cut Pro, Logic Pro) + Services (iCloud, Apple TV+) + Content Distribution (iTunes/App Store).

    • Adobe: Software (Photoshop, Premiere Pro) + Cloud Services (Creative Cloud) + Hardware (Muse, Fusión) + Digital Rights Management.

    • Sony: Content creation (Sony Pictures) + Hardware (Cameras, TVs, PlayStation) + Game/Entertainment distribution.

C. Virtual Reality (VR) as a Multimedia Application

  • Core Aspects:

    • Immersion: Sensory isolation (head-mounted display) creates feeling of "being there."

    • Interaction: Real-time user input (head/hand tracking) alters the virtual world.

    • 3D Spatial Audio: Sound sources anchored in 3D space.

    • High Frame Rates & Low Latency: >90 FPS, <20ms motion-to-photon latency to prevent simulator sickness.

  • Security & Forensics Implications:

    • Data Privacy: Biometric data (eye tracking, gait, voice) is captured and stored.

    • Virtual Crime & Harassment: Assault, theft, or indecent exposure in virtual spaces have real psychological impacts and potential legal standing.

    • Evidence Complexity: VR logs are proprietary, high-volume, and require specialized tools to reconstruct user paths, interactions, and virtual asset transactions.

D. Operating System Resource Management

  • Layered Architecture:

    • Principle: Complex hardware management is abstracted through layers, where each layer provides services to the layer above and uses services of the layer below.

    • Modern OS Example (e.g., Linux/Windows):

      1. Hardware Layer: CPU, Memory, I/O Devices.

      2. Kernel/OS Core: Direct hardware control, process scheduling, memory management.

      3. System Libraries/APIs: POSIX, Win32 API – interface for applications.

      4. Shell/User Interface: CLI (bash, PowerShell) or GUI (Explorer, GNOME).

      5. User Applications: Web browser, media player, forensic tool.

    • Benefit for Multimedia: Enables QoS guarantees (e.g., real-time scheduling policies at Kernel layer for audio playback).

[!TIP] Link OS layers to QoS: The Kernel's scheduler (Layer 2) is critical for allocating CPU time slices to ensure smooth video decoding.


II. QUALITY OF SERVICE (QoS) IN MULTIMEDIA DELIVERY

A. Factors Affecting QoS

Factor Category Specific Factors Impact on Multimedia
Network-Related Bandwidth, Latency, Jitter, Packet Loss Low bandwidth → buffering; High latency → lag in video calls; Jitter → choppy audio; Packet loss → visual artifacts/audio dropouts.
System-Related CPU Processing Power, RAM, GPU Capability, Disk I/O Insufficient CPU → dropped frames; Low RAM → swapping, stuttering; Weak GPU → inability to decode high-res video.
Content-Related Codec Efficiency, Bitrate, Resolution, Frame Rate High bitrate/resolution → requires more bandwidth/CPU; Inefficient codec → poor quality at same bitrate.

B. Resource Management for QoS

  • Importance: Guarantees predictable performance for time-sensitive media (VoIP, streaming) despite competing resource demands.

  • Managed Resources:

    • CPU: Scheduling priorities (e.g., SCHED_FIFO in Linux for real-time threads).

    • Memory: Buffering strategies, cache management.

    • Network Bandwidth: Traffic shaping, admission control.

    • Storage: I/O scheduling for disk-based streaming.

  • QoS Guarantee Mechanisms:

    • Admission Control: Reject new sessions if resources insufficient.

    • Resource Reservation: RSVP protocol reserves network path resources.

    • Traffic Policing & Shaping: Limit bandwidth usage per flow.

    • Prioritization: Mark packets (DSCP) for router/switch priority queuing.

[!TIP] Distinguish QoS (guaranteeing service levels) from QoE (subjective user experience). QoS metrics (packet loss) directly influence QoE.


III. SECURITY IN MULTIMEDIA SYSTEMS

A. Taxonomy of Security Attacks

Attack Type Mechanism Goal Multimedia Example
Active Modification, Fabrication, DoS Alter system/resources, disrupt service Tampering: Editing a video to change meaning. DoS: Flooding a streaming server. Fabrication: Inserting fake deepfake audio.
Passive Eavesdropping, Traffic Analysis Learn/exploit information without altering system Eavesdropping: Intercepting unencrypted video stream. Traffic Analysis: Inferring video content from packet sizes/timing.

B. Multimedia Authentication

  • Purpose: Verify source (who created it) and integrity (has it been altered?) of multimedia content.

  • Mechanisms:

    • Digital Signatures: Asymmetric cryptography (RSA/ECDSA) on a hash of the content. Provides non-repudiation. Computationally heavy for large media.

    • Cryptographic Hash Functions (SHA-256): Generate fixed-size digest. Detects any change. Does not identify source unless combined with a digital signature.

    • Digital Watermarking: Embeds imperceptible data as proof of ownership/provenance. Can be fragile (breaks on edit) or robust (survives compression).

C. Digital Watermarking: Scenario-Based Decision Framework

Decision Factors: Purpose (copyright vs. tracking), Required Robustness, Impact on Visual/Audio Quality, Cost, Legal Recognition.

Scenario Recommended Watermark Type Reasoning
Professional Portfolio Website (High-Quality Photos) Visible Watermark (semi-transparent logo/name) Primary Goal: Deterrence & Branding. Visible mark clearly asserts ownership, discourages unauthorized download/use. Quality impact is acceptable for portfolio display.
Stock Photography Platform (Commercial Sale) Invisible (Robust) Watermark Primary Goal: Traceability & Proof of Ownership. Must survive compression, cropping, format conversion. Invisible to not degrade customer's purchased product. Serves as forensic "fingerprint" for each customer.
Client Review (Low-Resolution Previews) Visible Watermark (large, bold) Primary Goal: Prevent Pre-Release Theft. High visibility ensures client cannot use low-res preview for commercial gain. Low-resolution nature makes robust invisible watermark less reliable.

[!TIP] Key distinction: Visible for deterrence/branding; Invisible (Robust) for forensic tracing/ownership proof; Invisible (Fragile) for tamper detection.


IV. DIGITAL FORENSICS FOR MULTIMEDIA

A. Digital Evidence Extraction Process

  1. Identification: Recognize potential multimedia evidence (image, video, audio file).

  2. Preservation: Create a forensic bit-stream image (e.g., using FTK Imager, dd). Compute hash (MD5/SHA-1) of original and image to verify integrity.

  3. Collection: Seize storage media/devices following chain of custody protocols.

  4. Examination: Use write-blocked hardware/software. Analyze file system, metadata, slack space.

  5. Analysis: Apply forensic tools (e.g., EnCase, Autopsy, Ghiro for images) to recover deleted files, detect manipulation, extract EXIF.

  6. Presentation: Document findings in a clear, admissible report for court. Include tool versions, hash values, and methodology.

Tools: Forensic Imagers (dd, FTK Imager), Analysis Suites (EnCase, Autopsy, Wireshark for network media), Specialized (Ghiro for image, Audacity/Sonic Visualiser for audio).

B. Metadata in Multimedia Forensics

  • Significance: "Data about data." Provides contextual information often not visible in the content itself.

  • Key Standards:

    • EXIF (Exchangeable Image File Format): Camera make/model, date/time, GPS coordinates, exposure settings. Highly volatile – easily edited or stripped.

    • IPTC (International Press Telecommunications Council): Caption, author, copyright, keywords. Used by journalists.

    • XMP (Extensible Metadata Platform): Adobe standard, can embed extensive rights and processing history.

  • Roles:

    • Authentication/Integrity: Inconsistencies in timestamps, GPS data, or editing software tags can indicate manipulation.

    • Timeline Reconstruction: Creation/modification dates help establish sequence of events.

    • Source Identification: Camera model, lens ID from EXIF can link image to a specific device.

[!TIP] Critical Pitfall: Metadata is not trustworthy as sole proof. It can be easily modified with tools like exiftool. Must be correlated with content-level analysis (noise, compression artifacts).

C. Device Forensics: Printers & Scanners

  • Role in Forgery/Mitigation:

    • Printer Steganography: Many color laser printers embed microscopic yellow dot patterns (Machine Identification Code - MIC) containing serial number and timestamp on every page.

      DiagramSEARCH: printer microdot pattern

    • Scanner Signature: CCD sensors have unique sensor pattern noise (SPN) – a consistent noise fingerprint like a "camera fingerprint" for scanners.

  • Forensic Analysis Techniques:

    1. MIC Extraction: Use UV light/microscope to view printer dots. Decode pattern to identify printer model and potentially the individual device.

    2. SPN Analysis: Compare noise pattern of a questioned document against a known reference from a suspect scanner.

    3. Mechanical Defect Analysis: Unique wear patterns (scratches, banding) from specific device rollers or lamps.

  • Illustrative Case Study: United States v. John Doe (2014). A threatening letter was sent. Forensic analysis of the laser printer MIC dots embedded in the text identified the specific make/model of printer. Sales records for that model led investigators to the purchaser, linking the suspect to the crime.

D. Audio Forensics

  • Authentication & Validation in Legal Context:

    • Goal: Determine if an audio recording is an authentic, unaltered record of the alleged event.

    • Chain of Custody: Must be established. Original file (or forensic image) must be preserved.

  • Key Techniques:

    • Spectrogram Analysis

      DiagramCANVAS: spectrogram with visible cut/paste artifacts
      : Visualizes frequency vs. time. Look for discontinuities in background noise, sudden changes in frequency profile, or inconsistent room acoustics indicating splicing.

    • Background Noise Profiling: Extract and analyze ambient noise (e.g., HVAC hum, traffic). A consistent, unbroken noise profile supports authenticity. A change in noise profile suggests editing or different recording environment.

    • Tamper Detection:

      • Electric Network Frequency (ENF) Analysis: Mains hum (50/60 Hz) is recorded implicitly. Its pattern must be continuous and match local grid records. A discontinuity indicates a cut.

      • Waveform Inconsistency: Sudden jumps in amplitude or phase at edit points.

      • Compression Artifact Analysis: Double compression (e.g., re-encoding an MP3) creates detectable artifacts like "coding ghosts."

    • Speaker Identification: Voice biometrics (formant analysis, pitch) to verify speaker identity, though less reliable than DNA.

[!TIP] Audio forensics is passive – it analyzes the file's inherent properties. It does not involve listening for content (which is subjective).


V. FOUNDATIONS & BROADER SCOPE OF MULTIMEDIA FORENSICS

A. The Need for Multimedia Forensics

  • Driving Factors:

    1. Proliferation: Ubiquity of smartphones, dashcams, surveillance, social media.

    2. Cybercrime & Disinformation: Deepfakes, forged documents, copyright infringement, revenge porn.

    3. Legal Evidence: Audio/video/images are critical in criminal (surveillance footage), civil (contract disputes), and intellectual property cases.

  • Distinction from General Computer Forensics:

    • Computer Forensics: Focuses on logical data structures (files, registry, logs, emails) on storage media to reconstruct user activity.

    • Multimedia Forensics: Focuses on the signal/content itself (pixels, samples, frames) to determine provenance, authenticity, and integrity, often independent of file system metadata. Requires signal processing expertise.

B. Protocols in Multimedia Systems & Forensics

  • Delivery Protocols:

    • RTP (Real-time Transport Protocol): Carries actual audio/video data. Uses sequence numbers & timestamps for jitter calculation and playout.

    • RTSP (Real Time Streaming Protocol): "Network remote control" for streaming servers (PLAY, PAUSE).

    • HTTP/HTTPS: Progressive download and adaptive streaming (HLS, DASH).

  • File Format Standards & Forensic Relevance:

    • Container Formats (MP4, AVI, MKV): Hold codec streams, metadata tracks. Structure can indicate editing (moov atom location in MP4).

    • Codec Standards (H.264, AAC): Compression artifacts are codec-specific and can be used as tamper evidence.

  • Evidence Acquisition Protocols:

    • Chain of Custody: Documented, unbroken record of evidence handling.

    • Forensic Imaging: Write-blocker use, hash verification (md5sum, sha256sum).

    • ACPO (Association of Chief Police Officers) Guidelines: Principles like "no action should change data" and "audit trail."

C. Multimedia Content Forensics

  • Core Objectives:

    1. Source Identification: Which camera/device created it? (via sensor noise, lens aberration).

    2. Tamper Detection: Has the content been altered? (via noise inconsistency, compression ghosting, splicing artifacts).

    3. Content Reconstruction: Recover original from degraded/compressed version (limited).

  • Techniques for Forgery Detection:

    • Pixel-Level Analysis: Error Level Analysis (ELA) – re-saving JPEG introduces noise; areas with different noise levels suggest editing.

    • Noise Inconsistency: Sensor Pattern Noise (SPN) should be uniform. Inconsistent SPN regions indicate copy-move forgery.

    • Compression Artifact Analysis: Double compression creates blocking artifacts at different alignments.

    • Geometric Consistency: Check perspective, lighting, and shadows for physical plausibility.

  • Passive vs. Active Methods:

    • Passive (Blind): Analyze content only. No prior embedding. Includes all techniques above (noise, compression, ELA). Most common in forensics.

    • Active: Relies on a pre-embedded watermark or signature. Detects tamper by verifying watermark integrity. Requires prior planning.

[!TIP] Exam Focus: Be able to differentiate passive (intrinsic analysis) vs. active (extrinsic watermark-based) forensic methods. Also, link metadata analysis (Section IV.B) as a supporting but not definitive technique.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in