首页> 外文期刊>Digital investigation >A metadata-based method for recovering files and file traces from YAFFS2
【24h】

A metadata-based method for recovering files and file traces from YAFFS2

机译:从YAFFS2恢复文件和文件跟踪的基于元数据的方法

获取原文
获取原文并翻译 | 示例
           

摘要

Nowadays, flash memory has drawn much attention of digital investigators, however most of them try to recover the content from logical aspect and few of them pay attention to how those files were created or modified. The deleted and edited contents of a file on the flash chips are commonly related to user behaviors which can be used as digital evidence. In this paper, a method using YAFFS2 metadata to recover files, reconstruct file system, and recover their previous history versions is proposed. The experimental results under Linux operating system show that the proposed method can correctly reconstruct file system, recover file and file traces from YAFFS2; and experiments conducted on physical images of Android phones show that our method can be applied to real scenarios.
机译:如今,闪存已经引起了数字调查人员的广泛关注,但是大多数调查人员都试图从逻辑方面恢复内容,并且很少有人关注这些文件的创建或修改方式。闪存芯片上文件的已删除和已编辑内容通常与可用作数字证据的用户行为有关。本文提出了一种使用YAFFS2元数据恢复文件,重建文件系统以及恢复其以前的历史版本的方法。在Linux操作系统下的实验结果表明,该方法可以正确地重建文件系统,从YAFFS2恢复文件和文件痕迹。在Android手机的物理图像上进行的实验表明,我们的方法可以应用于真实场景。

著录项

  • 来源
    《Digital investigation》 |2013年第1期|62-72|共11页
  • 作者单位

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

    College of Computer, Hangzhou Dianzi University, Hangzhou 310018, China;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    NAND flash chips; YAFFS2; File traces; Android; Reconstructing; Recovering;

    机译:NAND闪存芯片;YAFFS2;文件痕迹;Android;重建;正在恢复;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号