Earticle

현재 위치 Home

Other IT related Technology

Development of a Forensic Analyzing Tool based on Cluster Information of HFS+ filesystem

첫 페이지 보기
  • 발행기관
    국제인공지능학회(구 한국인터넷방송통신학회) 바로가기
  • 간행물
    International Journal of Internet, Broadcasting and Communication 바로가기
  • 통권
    Vol.13 No.3 (2021.08)바로가기
  • 페이지
    pp.178-192
  • 저자
    Gyu-Sang Cho
  • 언어
    영어(ENG)
  • URL
    https://www.earticle.net/Article/A399226

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

원문정보

초록

영어
File system forensics typically focus on the contents or timestamps of a file, and it is common to work around file/directory centers. But to recover a deleted file on the disk or use a carving technique to find and connect partial missing content, the evidence must be analyzed using cluster-centered analysis. Forensics tools such as EnCase, TSK, and X-ways, provide a basic ability to get information about disk clusters, but these are not the core functions of the tools. Alternatively, Sysinternals' DiskView tool provides a more intuitive visualization function, which makes it easier to obtain information around disk clusters. In addition, most current tools are for Windows. There are very few forensic analysis tools for MacOS, and furthermore, cluster analysis tools are very rare. In this paper, we developed a tool named FACT (Forensic Analyzer based Cluster Information Tool) for analyzing the state of clusters in a HFS+ file system, for digital forensics. The FACT consists of three features, a Cluster based analysis, B-tree based analysis, and Directory based analysis. The Cluster based analysis is the main feature, and was basically developed for cluster analysis. The FACT tool’s cluster visualization feature plays a central role. The FACT tool was programmed in two programming languages, C/C++ and Python. The core part for analyzing the HFS+ filesystem was programmed in C/C++ and the visualization part is implemented using the Python Tkinter library. The features in this study will evolve into key forensics tools for use in MacOS, and by providing additional GUI capabilities can be very important for cluster-centric forensics analysis.

목차

Abstract
1. Introduction
2. Retrieval of Cluster Information in the HFS+ filesystem
2.1 HFS+ Filesystem Basic
2.2 Catalog File
2.3 Volume Header
2.4 Allocation File
3. Features of FACT(Forensic Analyzer based Cluster Information Tool)
3.1 Overview
3.2 Cluster based Analysis
3.3 B-tree based Analysis
4. Functions for Implementation of FACT
4.1 Overview
4.2 Development Environments
4.3 Implemented functions for FACT core features
4.4 Implemented functions for Cluster Based Analysis
4.5 Implemented functions for B-tree Based Analysis
4.6 Implemented Functions for Directory Based Analysis
4.7 Implemented functions for Display
5. Conclusions
Acknowledgement
References

저자

  • Gyu-Sang Cho [ Professor, Dept. of Computer Software, Dongyang University, Korea ] Corresponding Author

참고문헌

자료제공 : 네이버학술정보

간행물 정보

발행기관

  • 발행기관명
    국제인공지능학회(구 한국인터넷방송통신학회) [The International Association for Artificial Intelligence]
  • 설립연도
    2000
  • 분야
    공학>전자/정보통신공학
  • 소개
    인터넷방송, 인터넷 TV , 방송 통신 네트워크 및 관련 분야에 대한 국내는 물론 국제적인 학술, 기술의 진흥발전에 공헌하고 지식 정보화 사회에 기여하고자 한다.

간행물

  • 간행물명
    International Journal of Internet, Broadcasting and Communication
  • 간기
    계간
  • pISSN
    2288-4920
  • eISSN
    2288-4939
  • 수록기간
    2009~2025
  • 십진분류
    KDC 326 DDC 380

이 권호 내 다른 논문 / International Journal of Internet, Broadcasting and Communication Vol.13 No.3

    피인용수 : 0(자료제공 : 네이버학술정보)

    함께 이용한 논문 이 논문을 다운로드한 분들이 이용한 다른 논문입니다.

      페이지 저장