Using the HFS plus journal for deleted file recovery

被引:4
|
作者
Burghardt, Aaron [1 ]
Feldman, Adam J. [1 ]
机构
[1] Booz Allen & Hamilton Inc, Herndon, VA 20171 USA
关键词
Mac OS X; HFS; Journal; Deleted; File; Recovery;
D O I
10.1016/j.diin.2008.05.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper describes research and analysis that were performed to identify a robust and accurate method for identifying and extracting the residual contents of deleted files stored within an HFS+ file system. A survey performed during 2005 of existing tools and techniques for HFS+ deleted file recovery reinforced the need for newer, more accurate techniques. Our research and analysis were based on the premise that a transactional history of file I/O operations is maintained in a Journal on HFS+ file systems, and that this history could be used to reconstruct recent deletions of active files from the file system. Such an approach offered a distinct advantage over other current techniques, including recovery of free/unallocated blocks and "file carving'' techniques. If the journal entries contained or referenced file attributes such as the extents that specify which file system blocks were occupied by each file, then a much more accurate identification and recovery of deleted file data would be possible. (c) 2008 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S76 / S82
页数:7
相关论文
共 50 条
  • [21] Recovery in the Calypso file system
    Devarakonda, M
    Kish, B
    Mohindra, A
    ACM TRANSACTIONS ON COMPUTER SYSTEMS, 1996, 14 (03): : 287 - 310
  • [22] Classification and Recovery of Fragmented Multimedia Files using the File Carving Approach
    Poisel, Rainer
    Rybnicek, Marlies
    Schildendorfer, Bernhard
    Tjoa, Simon
    INTERNATIONAL JOURNAL OF MOBILE COMPUTING AND MULTIMEDIA COMMUNICATIONS, 2013, 5 (03) : 50 - 67
  • [23] A File Undelete with Aho-Corasick Algorithm In File Recovery
    Sitompul, Opim Salim
    Handoko, Andrew
    Rahmat, Romi Fadillah
    2016 INTERNATIONAL CONFERENCE ON INFORMATICS AND COMPUTING (ICIC), 2016, : 427 - 431
  • [24] A recovery method of deleted record for SQLite database
    Jeon, Sangjun
    Bang, Jewan
    Byun, Keunduck
    Lee, Sangjin
    PERSONAL AND UBIQUITOUS COMPUTING, 2012, 16 (06) : 707 - 715
  • [25] A recovery method of deleted record for SQLite database
    Sangjun Jeon
    Jewan Bang
    Keunduck Byun
    Sangjin Lee
    Personal and Ubiquitous Computing, 2012, 16 : 707 - 715
  • [26] A Technique for Measuring Data Persistence using the Ext4 File System Journal
    Fairbanks, Kevin D.
    IEEE 39TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC 2015), VOL 3, 2015, : 18 - 23
  • [27] HFS: A performance-oriented flexible file system based on building-block compositions
    Krieger, O
    Stumm, M
    ACM TRANSACTIONS ON COMPUTER SYSTEMS, 1997, 15 (03): : 286 - 321
  • [28] A METHOD AND IMPLEMENTATION FOR THE EMPIRICAL STUDY OF DELETED FILE PERSISTENCE IN DIGITAL DEVICES AND MEDIA
    Jones, James H., Jr.
    Khan, Tahir M.
    2017 IEEE 7TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE IEEE CCWC-2017, 2017,
  • [29] The Distributed Digital Body Farm: Enabling the Analysis of Deleted File Decay Patterns
    Agada, Omoche Cheche
    Jones, James H. Jr
    Fairbanks, Kevin D.
    THE PROCEEDINGS OF 15TH WORKSHOP ON CYBER SECURITY EXPERIMENTATION AND TEST, CSET 2022, 2022, : 111 - 119
  • [30] File Distribution Preparation with File Retrieval and Error Recovery in Cloud Environment
    Mehta, Shital
    Panchal, Gaurang
    INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS (ICTIS 2017) - VOL 1, 2018, 83 : 301 - 307