30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Results by<br />

assertion:<br />

AIR 2.0.0 (Release Date: 17th, Feb 2010)<br />

md5 TOTAL: 7a84a94aae46d34ac61dc26800f6dd19<br />

sha1 TOTAL: f913fd6832de537c78dc4da881281984daed37f5<br />

156301488+0 sectors in<br />

156301488+0 sectors out<br />

Command completed: Fri Sep 17 19:09:48 NZST 2010<br />

Start VERIFY: Fri Sep 17 19:09:48 NZST 2010<br />

Command-line: cat /mnt/Image/AIR_GUID_Whole.* | air-counter 2>><br />

/usr/local/share/air/logs/air.buffer.data | dc3dd hash=md5,sha1<br />

hashlog=/tmp/verify_hash.log status=noxfer <strong>of</strong>=/dev/null<br />

VERIFY SUCCESSFUL: Hashes match<br />

Orig = md5 TOTAL: 7a84a94aae46d34ac61dc26800f6dd19<br />

sha1 TOTAL: f913fd6832de537c78dc4da881281984daed37f5<br />

Copy = md5 TOTAL: 7a84a94aae46d34ac61dc26800f6dd19<br />

sha1 TOTAL: f913fd6832de537c78dc4da881281984daed37f5<br />

Command completed: Fri Sep 17 20:10:02 NZST 2010<br />

AFR-01 PASSED AIC-01 PASSED ALOG-01 PASSED<br />

AFR-02 PASSED AIC-02 PASSED ALOG-02 PASSED<br />

AFR-03 PASSED AIC-05 PASSED ALOG-03 PASSED<br />

AFR-04 PASSED AIC-06 PASSED<br />

AFR-05 PASSED AIC-07 PASSED<br />

AFR-07 PASSED AIC-08 PASSED<br />

Analysis: Test achieved expected result.<br />

3.22. TC-17 Acquire a partially hidden GPT Partition<br />

Test Case TC-17 Acquire a partially hidden GPT Partition (AIR 2.0.0)<br />

Test & Acquire a partially hidden GPT Partition<br />

Case<br />

Summary:<br />

Assertions: AFR-01 The tool accesses the digital source with a supported access interface<br />

AFR-02 The tool acquires a digital source<br />

AFR-03 The tool operates in an execution environment<br />

AFR-04 The tool creates an image file <strong>of</strong> the digital source<br />

AFR-05 The tool acquires all the visible data sectors from the digital source<br />

AFR-06 The tool acquires all the hidden data sectors from the digital source<br />

AFR-07 All data sectors acquired from the digital source are acquired accurately.<br />

AIC-01<br />

The data represented by an image file is the same as the data acquired by the<br />

tool<br />

AIC-02 The tool creates an image file according to the file <strong>for</strong>mat the user specified.<br />

AIC-05<br />

If multi-file image creation and the image file size is selected, the tool creates<br />

a multi-file image except that one file may be smaller<br />

AIC-06<br />

If the image file integrity check is selected, the tool shall report to the user the<br />

image file has not been changed if the image file has not been changed.<br />

AIC-07<br />

If the image file integrity check is selected, the tool shall report to the user the<br />

image file has been changed if the image file has been changed.<br />

If the image file integrity check is selected, the tool shall report to the user the<br />

AIC-08 image file has been changed and the involved location if the image file has<br />

been changed.<br />

ALOG- If the tool logs any in<strong>for</strong>mation regarding to the acquisition, the in<strong>for</strong>mation is<br />

01 accurately logged in the log file.<br />

ALOG- The tool display correct in<strong>for</strong>mation about the acquisition to the user. The<br />

289

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!