30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Starting Sector: 14,683,473<br />

Sector Count: 2,104,452<br />

Source data size: 1027 MB<br />

MD5 checksum: b446594538d0f400fb80f54f6c78c481<br />

SHA1 checksum: 1a647d852f8ae609111a601b88091596ab2e8d92<br />

Acquisition started: Tue Jul 27 01:58:03 2010<br />

Acquisition finished: Tue Jul 27 01:58:43 2010<br />

Verification started: Tue Jul 27 01:58:43 2010<br />

Verification finished: Tue Jul 27 01:58:50 2010<br />

MD5 checksum: b446594538d0f400fb80f54f6c78c481 : verified<br />

SHA1 checksum: 1a647d852f8ae609111a601b88091596ab2e8d92 :<br />

verified<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes.<br />

1.7 TC-02-FAT32<br />

Test Case TC-02-FAT32 (FTK Imager 2.9.0.1385)<br />

Test & TC-02 Acquire a digital source that supported by the tools to an image file<br />

Case<br />

Summary: Notes: Acquire FAT32 only in a multi-partitioned HD (with WriteBlocker,<br />

Partition size 1027MB)<br />

Sector first from 4193028 to 6297479. total: 2104452<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access<br />

interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital<br />

source<br />

AFR-07 All data sectors acquired from the digital source are acquired<br />

accurately.<br />

AIC-01 The data represented by an image file is the same as the data<br />

acquired by the tool<br />

AIC-05 If multi-file image creation and the image file size is selected,<br />

the tool creates a multi-file image except that one file may be<br />

smaller<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

165

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!