首页> 外文学位 >A Comparative Analysis of Forensic Methods Used on a Microsoft Surface Book Computer
【24h】

A Comparative Analysis of Forensic Methods Used on a Microsoft Surface Book Computer

机译:Microsoft Surface Book计算机上使用的取证方法的比较分析

获取原文
获取原文并翻译 | 示例

摘要

The research question being asked by this project is which tool is the most effective at dead forensics and which is the most effective at live forensics when working on time-sensitive cases that involve a Microsoft Surface Book? The Microsoft Surface series of products is an example of one of the new products containing a non-removable solid-state storage drive. These laptop computers are becoming very popular and offer something that most other tablets do not, a full size USB port capable of transferring data on and off the device. This port can allow connectivity of many different device and most simultaneously with the help of a hub. This port can finally allow investigators access to the internal storage of the device. Many techniques were attempted in order to recover data, however due to time constraints this project only tested a few open source techniques along with some commercially developed software. This project examined multiple tools, along with the knowledge and resources needed to perform data recovery. It was found that the Microsoft Surface Book has some form of encryption being utilized at all times even if the user has not enabled BitLocker. The only way this project was able to successfully recover data from the computer was by utilizing FTK Imager on a live system while logged into a profile. This new knowledge will help digital investigators to more effectively gather data both on-scene and in a lab environment.
机译:该项目提出的研究问题是,在处理涉及Microsoft Surface Book的时间敏感案例时,哪种工具对死刑取证最有效,哪种工具对现场取证最有效? Microsoft Surface系列产品是包含不可移动固态存储驱动器的新产品之一的示例。这些便携式计算机正变得非常流行,并提供了大多数其他平板电脑所不具备的功能,即能够在设备内外传输数据的全尺寸USB端口。此端口可以在集线器的帮助下同时连接许多不同的设备。该端口最终可以允许调查人员访问设备的内部存储。为了恢复数据,尝试了许多技术,但是由于时间限制,该项目仅测试了一些开源技术以及一些商业开发的软件。该项目研究了多种工具,以及执行数据恢复所需的知识和资源。已经发现,即使用户未启用BitLocker,Microsoft Surface Book仍会始终采用某种形式的加密。该项目能够从计算机成功恢复数据的唯一方法是,在登录到配置文件的同时,在实时系统上利用FTK Imager。这些新知识将帮助数字研究人员在现场和实验室环境中更有效地收集数据。

著录项

  • 作者

    Graham, Michael.;

  • 作者单位

    Purdue University.;

  • 授予单位 Purdue University.;
  • 学科 Computer science.
  • 学位 M.S.
  • 年度 2017
  • 页码 69 p.
  • 总页数 69
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号