30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.2.2.3 TC-03: Acquiring A Hard Drive With Hidden Sectors<br />

Test case TC-03 involved testing if the tested disk imaging tools were able to acquire<br />

the hidden sectors configured in the test drive. Certain amount <strong>of</strong> sectors in the test<br />

drive was configured as hidden using HPA configuration.<br />

Table 4.5 shows that all three disk imaging tools were failed to acquire the<br />

HPA or DCO hidden area in the test drive. However, all the data that were accessible<br />

were acquired correctly by all three tested tools. FTK Imager was crashed twice when<br />

acquiring the DCO configured test drive (see Section 1.12 in Appendix 7).<br />

Table 4.5<br />

TC-03 Result Summary<br />

FTK Imager Helix 3 Pro AIR<br />

Test Cases HPA DCO HPA DCO HPA DCO<br />

Tested<br />

Assertions<br />

Failed<br />

Assertions<br />

Pass Rate<br />

(%)<br />

AFR01-07, AIC01-02, AIC05-08, ALOG01-03, AHS01-03<br />

AFR06, AHS01-03<br />

AFR06, AHS01-03,<br />

ALOG02<br />

76<br />

AFR06, AHS01-03<br />

85% 75% 85%<br />

The program was crashed when FTK Imager was attempting to create a list <strong>of</strong><br />

directories <strong>of</strong> the acquired data. The debugging in<strong>for</strong>mation <strong>of</strong> the crash is provided by<br />

FTK Imager.<br />

4.2.2.4 TC-05: Acquiring A Digital Source In An Alternative Supported<br />

Format<br />

Test case TC-05 involved testing if the disk imaging tools were able to produce<br />

complete and accurate image files in alternative supported <strong>for</strong>mat. Not all the tested<br />

tools support more than one <strong>for</strong>mat. The image <strong>for</strong>mat dd is supported by all tools.<br />

FTK Imager supports the most alternative image <strong>for</strong>mats, which are dd, SMART and<br />

Encase E01. AIR supports dd and dc3dd image <strong>for</strong>mats and Helix 3 pro supports dd<br />

and Encase E01 <strong>for</strong>mats.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!