Ext4 and XFS File System Forensic Framework Based on TSK

被引:8
|
作者
Kim, Hyungchan [1 ,2 ]
Kim, Sungbum [1 ]
Shin, Yeonghun [1 ]
Jo, Wooyeon [3 ]
Lee, Seokjun [4 ]
Shon, Taeshik [1 ,5 ]
机构
[1] Ajou Univ, Dept Artificial Intelligence Convergence Network, Suwon 16499, South Korea
[2] WINS Co Ltd, Platform Tech Team, Seongnam Si 13487, South Korea
[3] Ajou Univ, Dept Comp Engn, Suwon 16499, South Korea
[4] Kennesaw State Univ, Dept Comp Sci, Marietta, GA 30060 USA
[5] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
file system; digital forensic; file recovery; digital investigation; The Sleuth Kit;
D O I
10.3390/electronics10182310
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the number of Internet of Things (IoT) devices, such as artificial intelligence (AI) speakers and smartwatches, using a Linux-based file system has increased. Moreover, these devices are connected to the Internet and generate vast amounts of data. To efficiently manage these generated data and improve the processing speed, the function is improved by updating the file system version or using new file systems, such as an Extended File System (XFS), B-tree file system (Btrfs), or Flash-Friendly File System (F2FS). However, in the process of updating the existing file system, the metadata structure may be changed or the analysis of the newly released file system may be insufficient, making it impossible for existing commercial tools to extract and restore deleted files. In an actual forensic investigation, when deleted files become unrecoverable, important clues may be missed, making it difficult to identify the culprit. Accordingly, a framework for extracting and recovering files based on The Sleuth Kit (TSK) is proposed by deriving the metadata changed in Ext4 file system journal checksum v3 and XFS file system v5. Thereafter, by comparing the accuracy and recovery rate of the proposed framework with existing commercial tools using the experimental dataset, we conclude that sustained research on file systems should be conducted from the perspective of forensics.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] MISS-D: A fast and scalable framework of medical image storage service based on distributed file system
    Li, Wei
    Feng, Chaolu
    Yu, Kun
    Zhao, Dazhe
    [J]. COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2020, 186
  • [32] Semantic web service-based messaging framework for prediction of fitness data using Hadoop distributed file system
    Sethurannan, R.
    Sasiprabha, T.
    [J]. AUTOMATIKA, 2019, 60 (03) : 349 - 359
  • [33] GEANT4 based simulation framework for particle therapy system
    Aso, Tsukasa
    Kimura, Akinori
    Kameoka, Satoru
    Murakami, Kouichi
    Sasaki, Takashi
    Yamashita, Tomohiro
    [J]. 2007 IEEE NUCLEAR SCIENCE SYMPOSIUM CONFERENCE RECORD, VOLS 1-11, 2007, : 2564 - +
  • [34] VIRGO_DFS: a Framework of Large Scalable Distributed File System based on Virtual Hierarchical P2P network
    Huang, Lican
    [J]. 2009 WRI WORLD CONGRESS ON SOFTWARE ENGINEERING, VOL 1, PROCEEDINGS, 2009, : 114 - 118
  • [35] The Framework of Risk-based Decision Support System (DSS plus R) for Forensic Investigation in Detecting Human Cadaver of Clandestine Graves
    Noor, Noor Maizura Mohamad
    Nubli, Amirul Harfirie Ahmad
    Mohemad, Rosmayati
    Abu Bakar, Zuriana
    [J]. INTERNATIONAL CONFERENCE ON DESIGN, ENGINEERING AND COMPUTER SCIENCES, 2018, 453
  • [36] A file server optimization using scatter/gather IPC on L4 based multi-server operating system
    Hidaka, S
    Kodama, K
    Ji, YS
    Maruyama, K
    [J]. 6TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL I, PROCEEDINGS: INFORMATION SYSTEMS DEVELOPMENT I, 2002, : 184 - 189
  • [37] Blockchain-based privacy-preserving data-sharing framework using proxy re-encryption scheme and interplanetary file system
    Jhong-Ting Lou
    Showkat Ahmad Bhat
    Nen-Fu Huang
    [J]. Peer-to-Peer Networking and Applications, 2023, 16 : 2415 - 2437
  • [38] Blockchain-based privacy-preserving data-sharing framework using proxy re-encryption scheme and interplanetary file system
    Lou, Jhong-Ting
    Bhat, Showkat Ahmad
    Huang, Nen-Fu
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (05) : 2415 - 2437
  • [39] Recent Updates and Plan in Geant4 Based Particle Therapy System Simulation Framework
    Aso, T.
    Akagi, T.
    Iwai, G.
    Kimura, A.
    Maeda, Y.
    Matsufuji, N.
    Nishio, T.
    Omachi, C.
    Sasaki, T.
    Takase, W.
    Toshito, T.
    Yamashita, T.
    Watase, Y.
    [J]. 2013 IEEE NUCLEAR SCIENCE SYMPOSIUM AND MEDICAL IMAGING CONFERENCE (NSS/MIC), 2013,
  • [40] Extending Geant4 Based Particle Therapy System Simulation Framework to Medical Imaging Applications
    Aso, T.
    Mastushita, K.
    Nishio, T.
    Kabuki, S.
    Sasaki, T.
    [J]. 2015 IEEE NUCLEAR SCIENCE SYMPOSIUM AND MEDICAL IMAGING CONFERENCE (NSS/MIC), 2015,