Multi-version Data recovery for Cluster Identifier Forensics Filesystem with Identifier Integrity

Mohammed Alhussein, Duminda Wijesekera · International Journal of Intelligent Computing Research · 2013

Recovering deleted information from a hard disk has been a long standing problem.The computer forensics community has addressed information recovery through the development of file carving techniques.Two issues, however, still present significant challenges to their on-going efforts -1) Prior knowledge of file types is required for building file carvers including file headers and footers, and 2) fragmentation prevents file carvers from successful recovery.As a solution, we propose a forensics file system that embeds a special identifier in every cluster that is either currently allocated or was in the past.The identifier keeps track of every cluster mapping the clusters to a single file irrespective of the file statusexisting or deleted.We modified an exFAT implementation on FUSE to implement our forensics file system.We also propose a hashing mechanism that can detect malicious or accidental manipulation of a cluster's identifier.In addition, we introduce the concept of multi-version recovery, where multiple instances of a file can be recovered based on a cluster specific timestamps inserted during the write operation.Finally, using controlled experiments we have been able to verify that our proposed file system successfully recovers all deleted files in our test environment.

Read the paper · More papers on PaperTik