30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FTK Imager successfully verified the corrupt image file <strong>of</strong> FAT16 partition. The<br />

verification hash values matched the source hash values.<br />

4.2.2.8 TC-10: Verify A Corrupted Image<br />

Test case TC-10 involved testing whether FTK Imager was capable to identify the<br />

corrupted image. This test case only applied to FTK Imager because it was the only<br />

imaging tool that supported the function. Hex editor was used in the test case to<br />

change the data in the image file where the hex value <strong>of</strong> address 35df5f70h <strong>of</strong>fset 8<br />

was changed from value 43 to 42. Table 4.10 shows the test result <strong>of</strong> FTK Imager in<br />

test case TC-10.<br />

Table 4.10<br />

TC-10 Result Summary<br />

80<br />

FTK Imager<br />

Tested Assertions AFR03, AIC06-08, ALOG01-03<br />

Failed Assertions AIC08<br />

Pass Rate (%) 85.71%<br />

FTK Imager successfully detected that the image files had been corrupted. The<br />

verification hash values did not match the source hash values. However, the location<br />

<strong>of</strong> the corrupted data was not reported to the user.<br />

4.2.2.9 TC-11: Converting Existing Image Files To Another Image Format<br />

Test case TC-11 involved testing whether the disk imaging tool could convert an<br />

existing image file to another supported image file <strong>for</strong>mat. This test case only applied<br />

to FTK Imager because it was the only imaging tool that supported the function. FTK<br />

Imager supported three different image <strong>for</strong>mats; there<strong>for</strong>e, six combinations <strong>of</strong> <strong>for</strong>mat<br />

conversions were derived <strong>for</strong> testing.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!