30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

inconsistent with what is stated in the user manual. FTK Imager cannot handle hidden<br />

areas (either HPA or DCO or the combination <strong>of</strong> both) when acquiring the entire test<br />

drive. FTK Imager provides no notification to the user about whether hidden areas are<br />

present or not. When the FTK Imager acquires a partition that has been partially<br />

hidden, it displays and logs that the error “Block Indexes Out <strong>of</strong> Bounds” instead <strong>of</strong><br />

detecting and disclosing hidden areas. However, the acquisition <strong>of</strong> completely hidden<br />

partition is not successful and the s<strong>of</strong>tware freezes at the stage “Preparing to Image”.<br />

The program crashes as well when it attempts to create the directory listings <strong>for</strong> the<br />

hidden partition. Irregular configurations are not detected and notified by the FTK<br />

Imager.<br />

Helix 3 Pro presents some noteworthy problems during the testing. The amount<br />

<strong>of</strong> data it has acquired is not reported as defined in the research specifications. Users<br />

must manually calculate the number and size <strong>of</strong> the generated image files. The tool<br />

should have captured at in<strong>for</strong>mation during the testing. The size <strong>of</strong> the total acquired<br />

data is considered significant <strong>for</strong> disk imaging tools. Helix 3 Pro does not clearly state<br />

whether the image files have been verified when the test drive is trans<strong>for</strong>med into<br />

EnCase image <strong>for</strong>mat. Extra verification measures may be required to verify the<br />

integrity <strong>of</strong> the image files again. Similarly to FTK Imager, Helix 3 Pro cannot handle<br />

HPA and/or DCO hidden areas. When acquiring partially and completely hidden<br />

partitions, Helix 3 Pro per<strong>for</strong>ms inconsistently. The disk imaging proceeds at a<br />

remarkably slow speed and the process has to be terminated because it does not finish<br />

within a reasonable timeframe. In the test case where UNC errors exist, Helix 3 Pro<br />

does not record types and locations <strong>of</strong> the errors and the inaccessible sectors are<br />

replaced by a pre-configured value without details being disclosed clearly in the log<br />

file and in the user manual. The network acquisition function <strong>of</strong> Helix 3 Pro is<br />

unstable in Windows environments. Unhandled s<strong>of</strong>tware exceptions and program<br />

crashes are observed during the testing. Some usability problems <strong>of</strong> the program are<br />

also discerned, such as lethargic progress bar, no indication <strong>of</strong> overall imaging<br />

progress and <strong>of</strong> overall progress on the sender side <strong>of</strong> network acquisition. Finally,<br />

GUID partition type is not supported by the s<strong>of</strong>tware.<br />

116

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!