30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

cases TC-01, TC-02, TC-05, TC-07, TC-11 and TC-17 are the examples that followed<br />

the generic procedures (see Appendix 4). However, some test cases were setup and<br />

configured differently than the others. Test cases TC-03, TC-12 and TC-16 were<br />

required to setup hidden sectors in the test drive after the drive was partitioned.<br />

HDAT2 was used to configure HPA and/or DCO hidden areas in the test drive (see<br />

Appendix 4.4). TC-06 used a tool called MHDD to emulate uncorrectable (UNC) data<br />

error in particular sectors <strong>of</strong> the test drive. TC-15 is a test case that used Hex editor to<br />

corrupt the data in the Master Boot Record (MBR) <strong>of</strong> the test drive. A DOS-based<br />

partition editor was used in test case TC-13 to create the status known as “partitions<br />

overlapping”.<br />

Table 4.2<br />

Support S<strong>of</strong>tware that used to configure and setup the test drives<br />

S<strong>of</strong>tware Version Description agnostics tool <strong>for</strong> storage devices<br />

MHDD 4.5 Low-level HDD Diagnostics S<strong>of</strong>tware<br />

UltraEdit 16.10.0.1036 Hex Editor<br />

Darik's Boot<br />

2.2.6 Used to securely wipe the test drive<br />

and Nuke<br />

Hdparm<br />

9.29<br />

Linux Hard drive tool, used to check and change<br />

parameter <strong>of</strong> the test hard drive<br />

Gparted 0.6.2 Linux hard drive partitioning tool<br />

<strong>Disk</strong><br />

Management<br />

Tool<br />

1.0.0<br />

Windows hard disk partitioning tool<br />

(Supports GUID partition table partition style)<br />

<strong>Disk</strong>_stat 3.1.2 Used to check the existence <strong>of</strong> Host protected areas<br />

EnCase 6.16.1 Used to verify the hash value <strong>of</strong> the acquired images<br />

WinHex 15.6<br />

Computer <strong>Forensic</strong>s & <strong>Data</strong> Recovery S<strong>of</strong>tware,<br />

Hex Editor & <strong>Disk</strong> Editor from X-Ways S<strong>of</strong>tware<br />

A combination <strong>of</strong> tools was required to create and build up different testing<br />

environments <strong>for</strong> the analysis and evaluation <strong>of</strong> the actual per<strong>for</strong>mance <strong>of</strong> the tools.<br />

Test case TC-04 was not conducted due to the tool used to configure the test<br />

environment not being available. Specially-developed programs would be required to<br />

meet the requirements in order to conduct some specific test cases in this research.<br />

HDAT2 is program <strong>for</strong> testing or diagnostics <strong>of</strong> various types <strong>of</strong> storage devices.<br />

73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!