30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Table 4.6<br />

TC-05 Result Summary<br />

Tested<br />

Assertions<br />

Failed<br />

Assertions<br />

Pass Rate<br />

(%)<br />

FTK Imager Helix 3 Pro AIR<br />

AFR01-05, AFR07, AIC01-02, ALOG01-03<br />

None ALOG01-02 None<br />

100% 81.81% 100%<br />

Table 4.6 provides a summary <strong>of</strong> the results <strong>of</strong> test case TC-05. During the testing <strong>of</strong><br />

Test case TC-05, FTK Imager and AIR were able to acquire the digital source<br />

correctly in all supported alternative <strong>for</strong>mats. Helix 3 Pro was able to acquire<br />

successfully the data <strong>of</strong> the supported <strong>for</strong>mats. However, the verification based on<br />

comparison between the source and acquired data was not per<strong>for</strong>med (see Section 2.12<br />

in Appendix 7).<br />

4.2.2.5 TC-06: Acquiring A Digital Source With Unresolved Read Error<br />

Test case TC-06 tested whether the tested disk imaging tools would notify the user<br />

about unresolved read error and would attempt to recover the data. Program MHDD<br />

was utilised to mark the sectors as “bad sectors” so they could be remapped to spare<br />

sectors on the drive. Fifteen sectors were marked with UNC error (refer to sections<br />

1.16, 2.13 and 3.13 in Appendix 7 <strong>for</strong> more details). FTK Imager AIR have passed this<br />

test and all the assertions were fulfilled. Table 4.7 has shown the summary <strong>of</strong> the test<br />

case TC-06 results.<br />

Alternative verification method was employed to verify whether the disk<br />

imaging tools had replaced the inaccessible data sectors with value 0 as they were<br />

described. Hex editor UltraEdit was used to check each pre-configured data sector that<br />

had UNC error and to confirm whether the sector had been replaced with pre-<br />

configured value. All three disk imaging tools had replaced the inaccessible data<br />

sector with value 0.<br />

77

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!