30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Helix 3 Pro was not able to read the partition table in<strong>for</strong>mation from the test drive.<br />

However, all the data acquired were correct and complete. The source hash values<br />

matched the verification hash values. AIR achieved the expected result in this test<br />

case. AIR acquired the GPT disk successfully and produced accurate and complete<br />

image files.<br />

4.2.2.16 TC-17: Acquiring a partially hidden GPT Partition<br />

Test case TC-17 was involved testing whether the disk imaging tools were able to<br />

acquire a single GUID partition that was partially hidden through using HPA<br />

configuration. The result summary is shown in Table 4.18. The results were similar to<br />

those in the test case TC-12(1). All three evaluated tools failed to detect and acquire<br />

hidden sectors that existed in the test drive. However, the visible data sectors were all<br />

acquired completely and accurately.<br />

Table 4.18<br />

TC-17 Result Summary<br />

Tested<br />

Assertions<br />

Failed<br />

Assertions<br />

Pass Rate<br />

(%)<br />

FTK Imager Helix 3 Pro AIR<br />

AFR01-06,AFR07, AIC01-02, AIC05-08, ALOG01-03, AHS01-03<br />

AFR-06, AHS01-03<br />

AFR-06, AHS01-03<br />

ALOG02<br />

86<br />

AFR-06, AHS01-03<br />

78.95% 73.68% 78.95%<br />

FTK Imager reported that the block index was out <strong>of</strong> bound instead <strong>of</strong> the partition<br />

was partially hidden. Helix 3 Pro was not able to recognise the GUID partition. AIR<br />

was able to acquire all the visible data sectors completely and accurately.<br />

4.2.2.17 TC-18: Acquiring Single Partition Using Local Network Connection<br />

Test case TC-18 involved testing if the tools were able to produce complete and<br />

accurate images and to transfer them over a locally connected network. Table 4.19<br />

shows a summary <strong>of</strong> the per<strong>for</strong>mance <strong>of</strong> the three tested tools. This test case only

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!