Ext4 and XFS File System Forensic Framework Based on TSK

被引:8
|
作者
Kim, Hyungchan [1 ,2 ]
Kim, Sungbum [1 ]
Shin, Yeonghun [1 ]
Jo, Wooyeon [3 ]
Lee, Seokjun [4 ]
Shon, Taeshik [1 ,5 ]
机构
[1] Ajou Univ, Dept Artificial Intelligence Convergence Network, Suwon 16499, South Korea
[2] WINS Co Ltd, Platform Tech Team, Seongnam Si 13487, South Korea
[3] Ajou Univ, Dept Comp Engn, Suwon 16499, South Korea
[4] Kennesaw State Univ, Dept Comp Sci, Marietta, GA 30060 USA
[5] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
file system; digital forensic; file recovery; digital investigation; The Sleuth Kit;
D O I
10.3390/electronics10182310
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the number of Internet of Things (IoT) devices, such as artificial intelligence (AI) speakers and smartwatches, using a Linux-based file system has increased. Moreover, these devices are connected to the Internet and generate vast amounts of data. To efficiently manage these generated data and improve the processing speed, the function is improved by updating the file system version or using new file systems, such as an Extended File System (XFS), B-tree file system (Btrfs), or Flash-Friendly File System (F2FS). However, in the process of updating the existing file system, the metadata structure may be changed or the analysis of the newly released file system may be insufficient, making it impossible for existing commercial tools to extract and restore deleted files. In an actual forensic investigation, when deleted files become unrecoverable, important clues may be missed, making it difficult to identify the culprit. Accordingly, a framework for extracting and recovering files based on The Sleuth Kit (TSK) is proposed by deriving the metadata changed in Ext4 file system journal checksum v3 and XFS file system v5. Thereafter, by comparing the accuracy and recovery rate of the proposed framework with existing commercial tools using the experimental dataset, we conclude that sustained research on file systems should be conducted from the perspective of forensics.
引用
收藏
页数:12
相关论文
共 50 条
  • [1] Block and Inode Based Analysis on EXT4 File System
    Yudha, Fietyata
    Prayudi, Yudi
    [J]. ADVANCED SCIENCE LETTERS, 2018, 24 (01) : 652 - 655
  • [2] Guaranteeing the Metadata Update Atomicity in EXT4 File system
    Son, Seongbae
    Yoo, Jinsoo
    Won, Youjip
    [J]. PROCEEDINGS OF THE 8TH ASIA-PACIFIC WORKSHOP ON SYSTEMS (APSYS '17), 2017,
  • [3] Facilitating the Efficiency of Secure File Data and Metadata Deletion on SMR-based Ext4 File System
    Chen, Ping-Xiang
    Chen, Shuo-Han
    Chang, Yuan-Hao
    Liang, Yu-Pei
    Shih, Wei-Kuan
    [J]. 2021 26TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2021, : 728 - 733
  • [4] Adaptive Data Wiping Scheme with Adjustable Parameters for Ext4 File System
    Zhang Peng
    Niu Shaozhang
    Huang Zhenpeng
    Qin Xiaohua
    [J]. CHINESE JOURNAL OF ELECTRONICS, 2017, 26 (02) : 392 - 398
  • [5] AFEIC: Advanced forensic Ext4 inode carving
    Dewald, Andreas
    Seufert, Sabine
    [J]. DIGITAL INVESTIGATION, 2017, 20 : S83 - S91
  • [6] A Technique for Measuring Data Persistence using the Ext4 File System Journal
    Fairbanks, Kevin D.
    [J]. IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3, 2015, : 18 - 23
  • [7] Adaptive Data Wiping Scheme with Adjustable Parameters for Ext4 File System
    ZHANG Peng
    NIU Shaozhang
    HUANG Zhenpeng
    QIN Xiaohua
    [J]. Chinese Journal of Electronics, 2017, 26 (02) : 392 - 398
  • [8] APEX: Adaptive Ext4 File System for Enhanced Data Recoverability in Edge Devices
    Tuli, Shreshth
    Tuli, Shikhar
    Jain, Udit
    Buyya, Rajkumar
    [J]. 11TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2019), 2019, : 191 - 198
  • [9] Competition of Virtualized Ext4, Xfs and Btrfs Filesystems Under Type-2 Hypervisor
    Pesic, Dj
    Djordjevic, B.
    Timcenko, V.
    [J]. 2016 24TH TELECOMMUNICATIONS FORUM (TELFOR), 2016, : 774 - 777
  • [10] ExtSFR: scalable file recovery framework based on an Ext file system
    Seokjun Lee
    Wooyeon Jo
    Soowoong Eo
    Taeshik Shon
    [J]. Multimedia Tools and Applications, 2020, 79 : 16093 - 16111