首页> 外文期刊>Jurnal RESTI: Rekayasa Sistem dan Teknologi Informasi >Investigasi Bukti Digital Optical Drive Menggunakan Metode National Institute of Standard and Technology (NIST)
【24h】

Investigasi Bukti Digital Optical Drive Menggunakan Metode National Institute of Standard and Technology (NIST)

机译:使用国家标准技术研究所(NIST)方法进行数字光驱证明

获取原文
           

摘要

DVD-R is a type of optical drive that can store data in one burning process. However, there is a feature that allows erasing data in a read-only type, namely multisession. The research was conducted to implement the data acquisition process which was deleted from a DVD-R using Autopsy forensic tools and FTK Imager. The National Institute of Standards and Technology (NIST) is a method commonly used in digital forensics in scope storage with stages, namely collection, examination, analysis, and reporting. The acquisition results from Autopsy and FTK-Imager show the same results as the original file before being deleted, validated by matching the hash value. Based on the results obtained from the analysis and presentation stages, it can be concluded from the ten files resulting from data acquisition using the FTK Imager and Autopsy tools on DVD-R. FTK Imager detects two file systems, namely ISO9660 and Joliet, while the Autopsy tool only has one file system, namely UDF. The findings on the FTK Imager tool successfully acquired ten files with matching hash values and Autopsy Tools detected seven files with did not find three files with extensions, *.MOV, *.exe, *.rar. Based on the results of the comparative analysis of the performance test carried out on the FTK Imager, it got a value of 100% because it managed to find all deleted files and Autopsy got a value of 70% because 3 files were not detected because 3 files were not detected and the hash values ??were empty with the extensions * .exe, * .rar and *.MOV. This is because the Autopsy tool cannot detect the three file extensions. 
机译:DVD-R是一种光驱,可在一个刻录过程中存储数据。但是,存在一个功能,允许以只读类型擦除数据,即多种次数。进行了研究以实现使用尸检法医工具和FTK成像器从DVD-R中删除的数据采集过程。国家标准和技术研究所(NIST)是一种常用于数字取证的方法,包括阶段,即收集,检查,分析和报告。来自尸检和FTK-Imager的采集结果显示与删除之前的原始文件相同的结果,通过匹配散列值验证。基于从分析和演示阶段获得的结果,可以从使用FTK成像器和DVD-R上的尸检工具从数据采集产生的十个文件中得出结论。 FTK成像器检测到两个文件系统,即ISO9660和Joliet,而尸检工具只有一个文件系统,即UDF。 FTK成像器工具上的调查结果成功获取了具有匹配哈希值的十个文件,并且尸检工具检测到七个文件,未找到具有扩展名的三个文件,* .mov,* .exe,* .rar。基于FTK成像仪进行的性能测试的比较分析结果,它得到了100%的价值,因为它设法找到所有删除的文件和尸检的值为70%,因为没有检测到3个文件,因为3未检测到文件,哈希值是空的,扩展* .exe,* .rar和* .mov。这是因为尸检工具无法检测到三个文件扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号