Using the HFS plus journal for deleted file recovery

被引:4
|
作者
Burghardt, Aaron [1 ]
Feldman, Adam J. [1 ]
机构
[1] Booz Allen & Hamilton Inc, Herndon, VA 20171 USA
关键词
Mac OS X; HFS; Journal; Deleted; File; Recovery;
D O I
10.1016/j.diin.2008.05.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper describes research and analysis that were performed to identify a robust and accurate method for identifying and extracting the residual contents of deleted files stored within an HFS+ file system. A survey performed during 2005 of existing tools and techniques for HFS+ deleted file recovery reinforced the need for newer, more accurate techniques. Our research and analysis were based on the premise that a transactional history of file I/O operations is maintained in a Journal on HFS+ file systems, and that this history could be used to reconstruct recent deletions of active files from the file system. Such an approach offered a distinct advantage over other current techniques, including recovery of free/unallocated blocks and "file carving'' techniques. If the journal entries contained or referenced file attributes such as the extents that specify which file system blocks were occupied by each file, then a much more accurate identification and recovery of deleted file data would be possible. (c) 2008 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S76 / S82
页数:7
相关论文
共 50 条
  • [41] DeLink: Source File Information Recovery in Binaries
    Lang, Zhe
    Xu, Zhengzi
    Chen, Xiaohui
    Lv, Shichao
    Song, Zhanwei
    Shi, Zhiqiang
    Sun, Limin
    PROCEEDINGS OF THE 33RD ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2024, 2024, : 1009 - 1021
  • [42] AUTOMATIC RECOVERY OF A PARALLEL STABLE FILE SYSTEM
    SUN, CZ
    HERTZBERGER, LO
    LECTURE NOTES IN COMPUTER SCIENCE, 1991, 503 : 345 - 353
  • [43] The research of Excel file fragmentation data recovery
    Zhao ZhenZhou
    Fu ZhongYong
    FRONTIERS OF MANUFACTURING AND DESIGN SCIENCE IV, PTS 1-5, 2014, 496-500 : 2274 - 2278
  • [44] WHATS THE DIFF - A FILE COMPARATOR FOR CP/M PLUS
    CORTESI, DE
    DR DOBBS JOURNAL, 1984, 9 (08): : 30 - 31
  • [45] Recovery Techniques for Deleted Email Items in Digital Forensic Context
    Jeong, Chorong
    Lee, Keun-gi
    Lee, Sangjin
    FUTURE INFORMATION TECHNOLOGY, PT II, 2011, 185 : 115 - 122
  • [46] Recovery method of deleted records and tables from ESE database
    Kim, Jeonghyeon
    Park, Aran
    Lee, Sangjin
    Digital Investigation, 2016, 18 : S118 - S124
  • [47] An Improved B plus Tree for Flash File Systems
    Havasi, Ferenc
    SOFSEM 2011: THEORY AND PRACTICE OF COMPUTER SCIENCE, 2011, 6543 : 297 - 307
  • [48] NUTSHELL PLUS - THE RELATIONAL FILE MANAGER (VERSION 1.0)
    DEDIU, MM
    COMPUTER, 1988, 21 (06) : 96 - 96
  • [49] PRIMARY JOURNAL DATA-BASE - AN ONLINE TEST FILE
    COHEN, SM
    GARSON, LR
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 1980, 180 (AUG): : 18 - CINF
  • [50] Binary Index and Journal Embedding in The Linear Tape File System
    Jensen, Klaus Birkelund
    Vinter, Brian
    2017 INTERNATIONAL CONFERENCE ON NETWORKING, ARCHITECTURE, AND STORAGE (NAS), 2017, : 195 - 201