Using the HFS plus journal for deleted file recovery

被引:4
|
作者
Burghardt, Aaron [1 ]
Feldman, Adam J. [1 ]
机构
[1] Booz Allen & Hamilton Inc, Herndon, VA 20171 USA
关键词
Mac OS X; HFS; Journal; Deleted; File; Recovery;
D O I
10.1016/j.diin.2008.05.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper describes research and analysis that were performed to identify a robust and accurate method for identifying and extracting the residual contents of deleted files stored within an HFS+ file system. A survey performed during 2005 of existing tools and techniques for HFS+ deleted file recovery reinforced the need for newer, more accurate techniques. Our research and analysis were based on the premise that a transactional history of file I/O operations is maintained in a Journal on HFS+ file systems, and that this history could be used to reconstruct recent deletions of active files from the file system. Such an approach offered a distinct advantage over other current techniques, including recovery of free/unallocated blocks and "file carving'' techniques. If the journal entries contained or referenced file attributes such as the extents that specify which file system blocks were occupied by each file, then a much more accurate identification and recovery of deleted file data would be possible. (c) 2008 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S76 / S82
页数:7
相关论文
共 50 条
  • [31] ExtSFR: scalable file recovery framework based on an Ext file system
    Lee, Seokjun
    Jo, Wooyeon
    Eo, Soowoong
    Shon, Taeshik
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (23-24) : 16093 - 16111
  • [32] ExtSFR: scalable file recovery framework based on an Ext file system
    Seokjun Lee
    Wooyeon Jo
    Soowoong Eo
    Taeshik Shon
    Multimedia Tools and Applications, 2020, 79 : 16093 - 16111
  • [33] Standardization of file recovery classification and authentication
    Casey, Eoghan
    Nelson, Alex
    Hyde, Jessica
    DIGITAL INVESTIGATION, 2019, 31
  • [34] HARD DISK UTILITY FILE RECOVERY
    DOLAK, FJ
    LIBRARY SOFTWARE REVIEW, 1989, 8 (05): : 301 - 306
  • [35] Forensic analysis of android phone using Ext4 file system journal log
    Center for Information Security Technologies, Korea University, Seoul, Korea, Republic of
    Lect. Notes Electr. Eng., VOL. 1 (435-446):
  • [36] Recovery of deleted record for SQLite3 database
    Liu, Xipeng
    Fu, Xiao
    Sun, Guozi
    2016 8TH INTERNATIONAL CONFERENCE ON INTELLIGENT HUMAN-MACHINE SYSTEMS AND CYBERNETICS (IHMSC), VOL. 2, 2016, : 183 - 187
  • [37] RECOVERY OF FORENSIC ARTIFACTS FROM DELETED JUMP LISTS
    Singh, Bhupendra
    Singh, Upasna
    Sharma, Pankaj
    Nath, Rajender
    ADVANCES IN DIGITAL FORENSICS XIV, 2018, 532 : 51 - 65
  • [38] Recovery Method for Ransomware Encryption Attacks with File Extension Changing on File Server
    Nagano, Rintaro
    Hisasue, Ryuku
    Inamura, Hiroshi
    Ishida, Shigemi
    2023 FOURTEENTH INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND UBIQUITOUS NETWORK, ICMU, 2023,
  • [39] Protocol of Information Recovery in Solid Hard Drives - SSD Using File Carving Techniques
    Ninahualpa, Geovanni
    Yoo, Sang
    Guarda, Teresa
    Diaz, Javier
    Piccirilli, Dario
    2019 14TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2019,
  • [40] PRODUCING A MULTIACCESS ORDER FILE NEW BOOKS PROGRAM USING DBASE-III PLUS
    LAZINGER, SS
    LIBRARY SOFTWARE REVIEW, 1990, 9 (05): : 295 - 295