首页> 外文会议>2012 International Conferece For Internet Technology And Secured Transactions. >Forensics filesystem with cluster-level identifiers for efficient data recovery
【24h】

Forensics filesystem with cluster-level identifiers for efficient data recovery

机译:具有群集级标识符的取证文件系统,可实现高效的数据恢复

获取原文
获取原文并翻译 | 示例

摘要

Recovering deleted information from a hard disk has been a long standing problem. The computer forensics community has tackled information recovery through the development of file carving techniques. Two issues, however, still present significant challenges to their on-going efforts - 1) Prior knowledge of file types is required for building file carvers including file headers and footers, and 2) fragmentation prevents file carvers from successful recovery. In the research work that we present in this paper, we propose a forensics file system that embeds a special identifier in every cluster that is either currently allocated or was in the past. The identifier keeps track of every cluster mapping the clusters to a single file irrespective of the file status - existing or deleted. We modified an exFAT implementation on FUSE to implement our forensics file system. Finally, we have been able to verify via controlled experiments that our proposed file system successfully recovers all deleted files in our test environment.
机译:从硬盘恢复已删除的信息是一个长期存在的问题。计算机取证界已经通过文件雕刻技术的发展解决了信息恢复问题。但是,有两个问题仍然对其持续的工作提出了严峻的挑战-1)构建文件雕刻器(包括文件头和页脚)需要文件类型的先验知识,以及2)碎片化会阻止文件雕刻器成功恢复。在本文提出的研究工作中,我们提出了一个取证文件系统,该系统在当前分配的或过去分配的每个群集中嵌入一个特殊的标识符。标识符会跟踪将群集映射到单个文件的每个群集,而不管文件状态是存在还是已删除。我们修改了FUSE上的exFAT实现,以实现我们的取证文件系统。最后,我们已经能够通过受控实验验证我们提出的文件系统成功恢复了我们测试环境中所有已删除的文件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号