30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

sector size: 512 (assumed)<br />

md5 TOTAL: b446594538d0f400fb80f54f6c78c481<br />

sha512 TOTAL:<br />

e54e842dbeccc3af83d1d81f8f8cca8c37947473bf41a5fd13d2dd5222d6ca6c0<br />

a14cff1a0a0c6426637cc50e19df84c8efa4fa3f937b49c32ab7e4d5075b932<br />

2104452+0 sectors in<br />

2104452+0 sectors out<br />

Command completed: Tue Jul 27 03:27:54 NZST 2010<br />

Start VERIFY: Tue Jul 27 03:27:54 NZST 2010<br />

Command-line: cat /mnt/new/new/Test002/Test002_AIR_FAT16.* | aircounter<br />

2>> /usr/local/share/air/logs/air.buffer.data | dc3dd<br />

hash=md5,sha512 hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: b446594538d0f400fb80f54f6c78c481<br />

sha512 TOTAL:<br />

e54e842dbeccc3af83d1d81f8f8cca8c37947473bf41a5fd13d2dd5222d6ca6c0<br />

a14cff1a0a0c6426637cc50e19df84c8efa4fa3f937b49c32ab7e4d5075b932<br />

Copy = md5 TOTAL: b446594538d0f400fb80f54f6c78c481<br />

sha512 TOTAL:<br />

e54e842dbeccc3af83d1d81f8f8cca8c37947473bf41a5fd13d2dd5222d6ca6c0<br />

a14cff1a0a0c6426637cc50e19df84c8efa4fa3f937b49c32ab7e4d5075b932<br />

Command completed: Tue Jul 27 03:29:39 NZST 2010<br />

AFR-01 PASSED AIC-01 PASSED<br />

AFR-02 PASSED AIC-05 PASSED<br />

AFR-03 PASSED ALOG-01 PASSED<br />

AFR-04 PASSED ALOG-02 PASSED<br />

AFR-05 PASSED ALOG-03 PASSED<br />

AFR-07 PASSED<br />

Analysis: Test achieved the expected Result. Source hashes match verification hashes.<br />

3.7. TC-02-SWAP<br />

Test Case TC-02-SWAP (AIR 2.0.0)<br />

Test &<br />

Case<br />

Summary:<br />

Acquire a digital source that supported by the tools to an image file<br />

Notes: Acquire Linux SWAP partition only<br />

Assertion: AFR-01 The tool accesses the digital source with a supported access<br />

interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital<br />

source<br />

AFR-07 All data sectors acquired from the digital source are acquired<br />

accurately.<br />

AIC-01 The data represented by an image file is the same as the data<br />

acquired by the tool<br />

263

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!