30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2.3.4.2 Device Configuration Overlay (DCO) Area<br />

DCO feature was introduced in ATA-6. DCO is used by computer vendors to<br />

configure their hard drives to exactly the same number <strong>of</strong> sectors even when the drives<br />

are from different manufacturers and sizes (Gupta et al., 2006). Commands DEVICE<br />

CONFIGURATION SET, IDENTIFY AND RESTORE are introduced to create and<br />

manipulate DCO. Command DEVICE CONFIGURATION SET is used to reduce the<br />

size <strong>of</strong> the hard drive like commands SET MAX ADDRESS and SET MAX<br />

ADDRESS EXT in HPA. DCO command cannot be executed at where the drive has<br />

HPA in place. DEVICE CONFIGURATION RESTORE command is solely used to<br />

remove DCO. This command cannot be used to remove HPA. DCO and HPA can co-<br />

exist on the same hard drive (Gupta et al., 2006). However, a DCO area must be set<br />

be<strong>for</strong>e an HPA can be configured.<br />

S<strong>of</strong>tware tools such as hdparm and FastBloc® s<strong>of</strong>tware edition can be used to<br />

detect and manipulate the DCO area. FastBloc® S<strong>of</strong>tware Edition developed by<br />

Guidance s<strong>of</strong>tware claims that it supports HPA and/or DCO detection and removal.<br />

However, Guidance s<strong>of</strong>tware (2010, p.567) warns that using FastBloc® s<strong>of</strong>tware<br />

edition to remove DCO or combination <strong>of</strong> DCO and HPA will permanently alter the<br />

hard disk. The HPA area can be removed temporarily but the disk is not permanent<br />

modified. Nevertheless, modifing DCO or the combination <strong>of</strong> DCO and HPA will<br />

modify the disk permanently. The controller settings <strong>of</strong> the hard drive is altered even<br />

the data contained in the drive is not been changed. Guidance S<strong>of</strong>tware (2010, p.567)<br />

states that there is no known way to access an entire hard drive without making such<br />

change. Un<strong>for</strong>tunately, FastBloc® S<strong>of</strong>tware Edition is not available in our laboratory.<br />

2.3.5 Problem Areas In <strong>Disk</strong> Imaging <strong>Tools</strong> - Master Boot Record (MBR) &<br />

GUID Partition Table (GPT)<br />

An MBR contains 512-byte boot sector located in the first sector <strong>of</strong> a hard drive. MBR<br />

holds the primary partition table and contains boot code, four primary partition records<br />

and an MBR signature. Detailed discussion <strong>of</strong> the structure <strong>of</strong> MBR is beyond the<br />

scope <strong>of</strong> this research. The maximum capacity <strong>of</strong> MBR supports up to 2.2 Terabyte<br />

(TB) because the partitions‟ start address and partition length are both fixed at 32 bits.<br />

35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!