Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
3.4.1.3 Tool Testing Requirements ................................................................... 62<br />
3.4.1.4 Development <strong>of</strong> Test Scenarios ............................................................. 62<br />
3.4.1.5 Testing <strong>of</strong> <strong>Disk</strong> Imaging <strong>Tools</strong> .............................................................. 63<br />
3.4.2 <strong>Data</strong> Processing Methods ................................................................................... 63<br />
3.4.3 <strong>Data</strong> Analysis Methods ....................................................................................... 64<br />
3.4.3.1 Gap Analysis (GA) ................................................................................ 60<br />
3.5 Limitations <strong>of</strong> the Research ........................................................................................ 65<br />
3.6 Conclusion .................................................................................................................. 67<br />
Chapter 4. Research Findings<br />
4.0 Introduction ................................................................................................................. 69<br />
4.1 Variations in Research Specifications ........................................................................ 70<br />
4.1.1 <strong>Data</strong> Collection ................................................................................................... 70<br />
4.1.2 <strong>Data</strong> Processing & Analysis ............................................................................... 71<br />
4.2 Field Findings ............................................................................................................. 71<br />
4.2.1 Testing Environments ......................................................................................... 71<br />
4.2.2 Field Findings: <strong>Disk</strong> Imaging <strong>Tools</strong> Evaluation ................................................. 74<br />
4.2.2.1 TC-01: Acquiring Various Physical Interfaces ..................................... 74<br />
4.2.2.2 TC-02: Acquiring Various Digital Sources ........................................... 75<br />
4.2.2.3 TC-03: Acquiring A Hard Drive with Hidden Sectors .......................... 75<br />
4.2.2.4 TC-05: Acquire A Digital Source in an Alternate Supported Format ... 76<br />
4.2.2.5 TC-06: Acquire a Digital Source with Unresolved Read Error ............. 77<br />
4.2.2.6 TC-07 & TC-08: Insufficient Space at Destination Device .................. 78<br />
4.2.2.7 TC-09: Verify a Correct Image ............................................................. 79<br />
4.2.2.8 TC-10: Verify a Corrupted Image ......................................................... 79<br />
4.2.2.9 TC-11: Convert Existing Image Files to another Image Format ........... 80<br />
4.2.2.10 TC-12 (1&2): Acquire Partition Partially or Completely Hidden ....... 81<br />
4.2.2.11 TC-13: Acquire Overlapping Partitions .............................................. 82<br />
4.2.2.12 TC-14: Partitions Out <strong>of</strong> Physical Boundary ....................................... 82<br />
4.2.2.13 TC-15: Acquire a Hard drive with a Unreadable MBR ....................... 83<br />
4.2.2.14 TC-16(1): Acquire a Single GUID Partition ....................................... 84<br />
4.2.2.15 TC-16(2): Acquire a GPT <strong>Disk</strong> ........................................................... 85<br />
4.2.2.16 TC-17: Acquire a partially hidden GPT Partition ............................... 85<br />
4.2.2.17 TC-18: Acquire Single Partition using Local Network Connection .... 86<br />
viii