首页> 外文会议>IEEE Annual Computer Software and Applications Conference Workshops >A Technique for Measuring Data Persistence Using the Ext4 File System Journal
【24h】

A Technique for Measuring Data Persistence Using the Ext4 File System Journal

机译:一种使用ext4文件系统期刊测量数据持久性的技术

获取原文

摘要

In this paper, we propose a method of measuring data persistence using the Ext4 journal. Digital Forensic tools and techniques are commonly used to extract data from media. A great deal of research has been dedicated to the recovery of deleted data, however, there is a lack of information on quantifying the chance that an investigator will be successful in this endeavor. To that end, we suggest the file system journal be used as a source to gather empirical evidence of data persistence, which can later be used to formulate the probability of recovering deleted data under various conditions. Knowing this probability can help investigators decide where to best invest their resources. We have implemented a proof of concept system that interrogates the Ext4 file system journal and logs relevant data. We then detail how this information can be used to track the reuse of data blocks from the examination of file system metadata structures. This preliminary design contributes a novel method of tracking deleted data persistence that can be used to generate the information necessary to formulate probability models regarding the full and/or partial recovery of deleted data.
机译:在本文中,我们提出了一种使用EXT4 Journal测量数据持久性的方法。数字法医工具和技术通常用于从媒体中提取数据。大量的研究已经致力于恢复删除数据,但是,缺乏有关量化调查员在这项努力中取得成功的机会的信息。为此,我们建议将文件系统期刊用作收集数据持久性的经验证据,以后可以用于制定在各种条件下恢复已删除数据的概率。了解这种概率可以帮助调查人员决定最佳投资资源的地方。我们已经实施了概念系统的证据,用于询问ext4文件系统日志并记录相关数据。然后,我们详细介绍了如何使用该信息来跟踪文件系统元数据结构的检查中的数据块重用。这种初步设计有助于跟踪删除数据持久性的新方法,该数据持久性可用于生成制定关于删除数据的完整和/或部分恢复的概率模型所需的信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号