25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

implementations of the thumbnail cache; therefore the approach used in this<br />

research could enable the identification of other file types.<br />

This chapter investigates methods for identifying thumbnail cache file<br />

fragments. Section 7.2discusses traditional data carving techniques; recent<br />

data carving research is discussed in Section 7.3. In Section 7.4 a<br />

methodology for the research in this chapter is established; the information to<br />

be carved is described in Section 7.5. This is followed by the four most<br />

common types of identification method being adapted and implemented for<br />

thumbnail cache file fragment identification [Sections 7.6 – 7.9]. Section 7.10<br />

describes the results of the implemented file fragment identification methods; a<br />

comparative discussion of the four techniques follows in Section 7.11. A<br />

discussion of this research is provided in Section 7.12; finally this chapter is<br />

concluded in Section 7.13.<br />

7.2 Traditional Data Carving<br />

Both NTFS and FAT store information showing a relationship between<br />

individual clusters and their contents. The references in the file system provide<br />

a starting point to identify the clusters used to store a file. Fellows [2005]<br />

discusses the recoverability of deleted files when the directory structures such<br />

as the MFT are available; however the paper has little discussion on the<br />

recoverability of potential evidence from such files when the MFT information<br />

relating to a cluster is no longer available. There may be information on a<br />

device which does not have any file system references but is pertinent to the<br />

investigation; the file system references may not always be available, for<br />

example if the device has been formatted.<br />

Without the file system references, recovery becomes more complex; this<br />

creates a requirement for file carving. File carving is the technique of extracting<br />

Page<br />

158

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!