30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

eleased as a utility <strong>of</strong> UNIX. DD is one <strong>of</strong> the oldest imaging tools and it produces<br />

raw image <strong>for</strong>mat.<br />

Table 2.5<br />

List <strong>of</strong> Example Hardware-based <strong>Disk</strong> Imaging <strong>Tools</strong><br />

Product<br />

Name<br />

Talon® Logicube<br />

HardCopy 3<br />

<strong>Data</strong> Copy<br />

King<br />

Tableau<br />

TD1<br />

Make Description<br />

Voom<br />

Technology<br />

Salvation<strong>Data</strong><br />

Guidance<br />

S<strong>of</strong>tware<br />

Talon® simultaneously images and verifies data at up to 4<br />

GB/min. The handheld system captures IDE/UDMA/SATA<br />

drives, and can capture SCSI drives via USB cable. Capture<br />

directly from desktop/laptop PCs and MAC computers (via PC<br />

interface) using the <strong>Forensic</strong> cloning s<strong>of</strong>tware included with the<br />

Talon.<br />

Duplicate to 1 or 2 destination drives at up to 7.1 GB/min. with no<br />

slow down. Clone entire drive or select Image option to chunk<br />

data into a file or files. Purchase preloaded with MD5 and<br />

SHA256 verification; select 1 or 2 passes. Minimal training<br />

required. Field upgradable.<br />

Access to unstable drives with a lot <strong>of</strong> bad sectors and copy data<br />

fast. Automatically resets/reboots drives that get stuck to continue<br />

the data duplication process. Sector by sector copy and<br />

synchronous CRC checking.<br />

<strong>Disk</strong>-to-<strong>Disk</strong> and <strong>Disk</strong>-to-File Duplication, Format <strong>Disk</strong>, Wipe<br />

<strong>Disk</strong>, Hash <strong>Disk</strong> (MD5 and SHA-1), HPA/DCO Detection and<br />

Removal, and Blank <strong>Disk</strong> Check.<br />

Many variants have emerged after DD to fit the purpose <strong>of</strong> <strong>for</strong>ensic disk imaging.<br />

Apart from DD, some other disk imaging tools are developed based on a proprietary or<br />

open source <strong>for</strong>mat. The following sub-sections will discuss some <strong>of</strong> the popular open<br />

source and proprietary disk imaging tools in details.<br />

2.3.3.1 dcfldd<br />

<strong>Disk</strong> imaging tool dcfldd is developed and maintained by Nicholas Harbour who used<br />

to work <strong>for</strong> the Department <strong>of</strong> Defence Computer <strong>Forensic</strong>s Lab. Dcfldd is an<br />

improved version <strong>of</strong> GNU dd with elements <strong>of</strong> digital <strong>for</strong>ensics (Harbour, 2006). One<br />

<strong>of</strong> the improved features <strong>for</strong> <strong>for</strong>ensics is hashing on-the-fly which allows hashing the<br />

input data while it is being transferred. Dcfldd can also verify an image to check<br />

whether it is a bit by bit match to the source. It can also split output or output the<br />

image to multiple locations.<br />

31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!