30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Results by<br />

assertion:<br />

FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />

Source data size: 76319 MB<br />

Sector count: 156301488<br />

[Computed Hashes]<br />

MD5 checksum: 3170cec7e6720af973cc37a946c32ae3<br />

SHA1 checksum: 6366ad8cd563c05f086dfe7b7884b08fd9795069<br />

Image In<strong>for</strong>mation:<br />

Acquisition started: Wed Sep 08 13:08:19 2010<br />

Acquisition finished: Wed Sep 08 14:24:42 2010<br />

Segment list:<br />

E:\Image\FTK-OverlapPartition.001<br />

E:\Image\FTK-OverlapPartition.002<br />

………………..<br />

E:\Image\FTK-OverlapPartition.051<br />

Image Verification Results:<br />

Verification started: Wed Sep 08 14:24:42 2010<br />

Verification finished: Wed Sep 08 14:42:36 2010<br />

MD5 checksum: 3170cec7e6720af973cc37a946c32ae3 : verified<br />

SHA1 checksum: 6366ad8cd563c05f086dfe7b7884b08fd9795069 :<br />

verified<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-02 PASSED<br />

AFR-03 PASSED AIC-11 FAILED<br />

AFR-04 PASSED ALOG-01 PASSED<br />

AFR-05 PASSED ALOG-02 PASSED<br />

AFR-07 PASSED ALOG-03 PASSED<br />

Analysis: Test FAILED to achieve the expected Result. FTK Imager is able to recover<br />

the overlapped partition table. However, irregularity <strong>of</strong> the partition table is<br />

not reported to the user.<br />

1.29 TC-14 Partition out <strong>of</strong> boundary<br />

Test Case TC-14 Partition out <strong>of</strong> boundary (FTK Imager 2.9.0.1385)<br />

Test &<br />

Case<br />

Summary:<br />

Acquire a hard disk with a partition‟s end address ended outside the physical<br />

boundary<br />

Notes: Partitions ended out <strong>of</strong> the physical boundary <strong>of</strong> the disk. The last partition end<br />

sector changed from 72,331,264 to 72,380,000.<br />

Assertions: AFR-01 The tool accesses the digital source with a supported access interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital source<br />

AFR-07 All data sectors acquired from the digital source are acquired accurately.<br />

AIC-01<br />

The data represented by an image file is the same as the data acquired by the<br />

tool<br />

AIC-02 The tool creates an image file according to the file <strong>for</strong>mat the user specified.<br />

AIC-11 The tool reports to the user if any irregularities found in the digital source.<br />

ALOG- If the tool logs any in<strong>for</strong>mation regarding to the acquisition, the in<strong>for</strong>mation is<br />

01 accurately logged in the log file.<br />

ALOG- The tool display correct in<strong>for</strong>mation about the acquisition to the user. The<br />

202

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!