Ext4 and XFS File System Forensic Framework Based on TSK

被引:8
|
作者
Kim, Hyungchan [1 ,2 ]
Kim, Sungbum [1 ]
Shin, Yeonghun [1 ]
Jo, Wooyeon [3 ]
Lee, Seokjun [4 ]
Shon, Taeshik [1 ,5 ]
机构
[1] Ajou Univ, Dept Artificial Intelligence Convergence Network, Suwon 16499, South Korea
[2] WINS Co Ltd, Platform Tech Team, Seongnam Si 13487, South Korea
[3] Ajou Univ, Dept Comp Engn, Suwon 16499, South Korea
[4] Kennesaw State Univ, Dept Comp Sci, Marietta, GA 30060 USA
[5] Ajou Univ, Dept Cyber Secur, Suwon 16499, South Korea
基金
新加坡国家研究基金会;
关键词
file system; digital forensic; file recovery; digital investigation; The Sleuth Kit;
D O I
10.3390/electronics10182310
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the number of Internet of Things (IoT) devices, such as artificial intelligence (AI) speakers and smartwatches, using a Linux-based file system has increased. Moreover, these devices are connected to the Internet and generate vast amounts of data. To efficiently manage these generated data and improve the processing speed, the function is improved by updating the file system version or using new file systems, such as an Extended File System (XFS), B-tree file system (Btrfs), or Flash-Friendly File System (F2FS). However, in the process of updating the existing file system, the metadata structure may be changed or the analysis of the newly released file system may be insufficient, making it impossible for existing commercial tools to extract and restore deleted files. In an actual forensic investigation, when deleted files become unrecoverable, important clues may be missed, making it difficult to identify the culprit. Accordingly, a framework for extracting and recovering files based on The Sleuth Kit (TSK) is proposed by deriving the metadata changed in Ext4 file system journal checksum v3 and XFS file system v5. Thereafter, by comparing the accuracy and recovery rate of the proposed framework with existing commercial tools using the experimental dataset, we conclude that sustained research on file systems should be conducted from the perspective of forensics.
引用
收藏
页数:12
相关论文
共 50 条
  • [41] Extending Geant4 Based Particle Therapy System Simulation Framework to Medical Imaging Applications
    Aso, T.
    Mastushita, K.
    Nishio, T.
    Kabuki, S.
    Sasaki, T.
    [J]. 2015 IEEE NUCLEAR SCIENCE SYMPOSIUM AND MEDICAL IMAGING CONFERENCE (NSS/MIC), 2015,
  • [42] MBF4CR: A Model-Based Framework for Supporting an Automated Cancer Registry System
    Wang, Shuai
    Lu, Hong
    Yue, Tao
    Ali, Shaukat
    Nygard, Jan
    [J]. MODELLING FOUNDATIONS AND APPLICATIONS, ECMFA 2016, 2016, 9764 : 191 - 204
  • [43] A novel low-power RF4CE-based communication framework for multimedia system control
    Koo, Bonhyun
    Choi, Wook
    Park, James J.
    Shon, Taeshik
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2011, 24 (10) : 1340 - 1353
  • [44] 3DTV system using depth image-based video in the MPEG-4 multimedia framework
    Kim, Sung-Yeol
    Cha, Jongeun
    Lee, Seung Yun
    Ryu, Jeha
    Ho, Yo-Sung
    [J]. 2007 3DTV CONFERENCE, 2007, : 97 - +
  • [45] Proposal of Framework Based on 4W1H and Properties of Robots and Objects for Development of Physical Service System
    Nakamura, Yukihiro
    Muto, Shin-yo
    Maeda, Yoshio
    Mizukawa, Makoto
    Motegi, Manabu
    Takashima, Youichi
    [J]. JOURNAL OF ROBOTICS AND MECHATRONICS, 2014, 26 (06) : 758 - 771
  • [46] The SPRINTARS version 3.80/4D-Var data assimilation system: development and inversion experiments based on the observing system simulation experiment framework
    Yumimoto, K.
    Takemura, T.
    [J]. GEOSCIENTIFIC MODEL DEVELOPMENT, 2013, 6 (06) : 2005 - 2022
  • [47] Deep4MalDroid: A Deep Learning Framework for Android Malware Detection Based on Linux Kernel System Call Graphs
    Hou, Shifu
    Saas, Aaron
    Chen, Lifei
    Ye, Yanfang
    [J]. 2016 IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE WORKSHOPS (WIW 2016), 2016, : 104 - 111
  • [48] A Novel Performance Framework and Methodology to Analyze the Impact of 4D Trajectory Based Operations in the Future Air Traffic Management System
    Ruiz, Sergio
    Lopez Leones, Javier
    Ranieri, Andrea
    [J]. JOURNAL OF ADVANCED TRANSPORTATION, 2018,
  • [49] Log file-based dose reconstruction and accumulation for 4D adaptive pencil beam scanned proton therapy in a clinical treatment planning system: Implementation and proof-of-concept
    Meijers, A.
    Jakobi, A.
    Stuetzer, K.
    Guterres Marmitt, G.
    Both, S.
    Langendijk, J. A.
    Richter, C.
    Knopf, A.
    [J]. MEDICAL PHYSICS, 2019, 46 (03) : 1140 - 1149
  • [50] Efficient Biocatalytic System for Biosensing by Combining Metal- Organic Framework (MOF)-Based Nanozymes and G-Quadruplex (G4)-DNAzymes
    Mao, Xuanxiang
    He, Fangni
    Qu, Dehui
    Wei, Shijiong
    Luo, Rengan
    Chen, Yun
    Zhang, Xiaobo
    Lei, Jianping
    Monchaud, David
    Mergny, Jean-Louis
    Ju, Huangxian
    Zhou, Jun
    [J]. ANALYTICAL CHEMISTRY, 2022, 94 (20) : 7295 - 7302