30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Log<br />

highlights:<br />

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />

Starting Sector: 12,595,023<br />

Sector Count: 2,104,452<br />

Source data size: 1027 MB<br />

Sector count: 2104452<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed<br />

Acquisition started: Wed Aug 11 03:37:58 2010<br />

Acquisition finished: Wed Aug 11 03:38:41 2010<br />

Verification started: Wed Aug 11 03:38:41 2010<br />

Verification finished: Wed Aug 11 03:38:58 2010<br />

MD5 checksum: f7c2c38630b0c995732a87cce003dcca : verified<br />

SHA1 checksum: 2043d334ef1ee9c1749427b249b3c983d4fcc8ed :<br />

verified<br />

AFR-01 PASSED<br />

AFR-02 PASSED<br />

AFR-03 PASSED<br />

AFR-04 PASSED<br />

AFR-05 PASSED<br />

AFR-07 PASSED<br />

AIC-01 PASSED<br />

AIC-02 PASSED<br />

ALOG-01 PASSED<br />

ALOG-02 PASSED<br />

ALOG-03 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification<br />

hashes and the hash <strong>of</strong> the original DD image.<br />

1.15 TC-05-E01<br />

Test Case TC-05-E01 (FTK Imager 2.9.0.1385)<br />

Test &<br />

Case<br />

Summary:<br />

Acquire a digital source to an image file in an alternate supported <strong>for</strong>mat<br />

Notes: Acquire image to E01 <strong>for</strong>mat image <strong>for</strong>mat<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access<br />

interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital<br />

source<br />

AFR-07 All data sectors acquired from the digital source are acquired<br />

accurately.<br />

AIC-01 The data represented by an image file is the same as the data<br />

acquired by the tool.<br />

AIC-02 The tool creates an image file according to the file <strong>for</strong>mat the<br />

user specified.<br />

ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />

the in<strong>for</strong>mation is accurately logged in the log file.<br />

ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />

the user.<br />

179

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!