23.12.2012 Views

Digital Forensics in Small Devices: RFID Tag Investigation

Digital Forensics in Small Devices: RFID Tag Investigation

Digital Forensics in Small Devices: RFID Tag Investigation

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

file, such as the transaction log file, could be lost when the server <strong>in</strong>stance was<br />

shut down or restarted (Fowler, 2009). Hence, the volatile SQL Server artefacts<br />

were acquired and preserved by us<strong>in</strong>g different collection methods for different<br />

purposes <strong>in</strong> order to help the <strong>in</strong>vestigation (see Table A1. 1 <strong>in</strong> Appendix 1).<br />

Even though, most of the volatile server evidence was acquired by<br />

runn<strong>in</strong>g the automated WFT, which was stated <strong>in</strong> the previous section; hence,<br />

the active virtual log files (VLFs) and r<strong>in</strong>g buffer data were collected by ad hoc<br />

artefacts collection method.<br />

The acquisition of VLFs conta<strong>in</strong><strong>in</strong>g the crucial volatile <strong>in</strong>formation such<br />

as Data Manipulation Language (DML) and Data Def<strong>in</strong>ition Language (DL)<br />

statements were performed early <strong>in</strong> the stage of volatile artefacts acquisition.<br />

However, the current state of physical database transaction log files was<br />

determ<strong>in</strong>ed by execut<strong>in</strong>g the follow<strong>in</strong>g syntax through SQLCMD with<strong>in</strong> the<br />

<strong>RFID</strong>_test database before perform<strong>in</strong>g the active VLF data (Fowler, 2009).<br />

:out E:\DBSE_LGNF.txt<br />

DBCC log<strong>in</strong>fo<br />

GO<br />

Accord<strong>in</strong>g to the result output (Figure 4.21); the only physical database<br />

transaction log was associated with <strong>RFID</strong>_test database (FileId = 2). The values<br />

of StartOffset for active (Status = 2) and <strong>in</strong>active (Status = 0) VLFs could later<br />

be useful <strong>in</strong> order to carve <strong>in</strong>active VLF data from the transaction log (Folwer,<br />

2009).<br />

Figure 4.21: Database Console Commands (DBCC) log<strong>in</strong>fo command results<br />

95

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!