30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Also, MBR disks only support four primary partitions. In today‟s hardware products, 2<br />

TB hard drives have become more af<strong>for</strong>dable and common. It is only a matter <strong>of</strong> time,<br />

when 2 TB or larger hard drives will become the mainstream products in the market.<br />

In order to solve the limitations and problems with MBR, GPT is developed to replace<br />

MBR partition tables. The maximum disk size can go up to 9.4 billion TB and it<br />

supports 128 partitions by default. GPT also provides CRC32 checksums and backup<br />

utility to maintain the integrity <strong>of</strong> the partition table and header. GPT is widely<br />

supported by popular operating system vendors such as Apple OSX, Micros<strong>of</strong>t<br />

Windows and Linux. GNOME Partition Editor (GParted) and Windows <strong>Disk</strong><br />

Management Tool support GPT creation and manipulation (Smith, 2009). GPT is<br />

more popular in current Apple Intel-based computers. With millions <strong>of</strong> Apple Intel-<br />

based computers have sold and the increasing usage <strong>of</strong> massive storage devices, GPT<br />

will become the mainstream partition scheme.<br />

What‟s the implication <strong>of</strong> GPT <strong>for</strong> <strong>for</strong>ensic tools? The support <strong>of</strong> GPT in<br />

<strong>for</strong>ensic tools industry is still growing (Nikkel, 2009). Popular <strong>for</strong>ensic tools such as<br />

Encase and FTK can recognise and provide access to a GPT disk. However, more<br />

improvements can be made to decode the GPT headers and entries, provide<br />

in<strong>for</strong>mation about the backup GPT and GPT checksums (Nikkel, 2009). Part <strong>of</strong> this<br />

study aims at finding out whether the selected disk imaging tools are able to acquire a<br />

GPT disk and partition in complete and accurate manner. Nikkel (2009) has described<br />

that a full disk or a single partition acquisition can be done the same way as other<br />

partition schemes (DOS or BSD) or traditional MBR partitions.<br />

2.3.6 Problem Areas in <strong>Disk</strong> Imaging <strong>Tools</strong> - Hash Function<br />

Cryptography Hash function has a wide range <strong>of</strong> applications. For example, it<br />

identifies and classifies electronic in<strong>for</strong>mation, authenticates data integrity and online<br />

security. One-way hash function is commonly used as a method <strong>of</strong> authenticating and<br />

verifying the integrity <strong>of</strong> electronic in<strong>for</strong>mation. Hashing function has two very unique<br />

characteristics that are concern <strong>of</strong> to digital <strong>for</strong>ensics. Thompson (2005) explains that<br />

it is computationally infeasible to derive or obtain any in<strong>for</strong>mation about the original<br />

contents from the hash value and to have two pieces <strong>of</strong> content that have the same<br />

hash value. The hash function provided by the disk imaging s<strong>of</strong>tware will ensure that<br />

36

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!