Comments on the Linux FAT32 allocator and file creation order reconstruction [Digit Investig 11( 4), 224-233]

被引:5
作者
Lee, Wan Yeon [1 ]
Kwon, Hyuckmin [2 ]
Lee, Heejo [2 ]
机构
[1] Dongduk Womens Univ, Dept Comp Sci, Seoul 136714, South Korea
[2] Korea Univ, Dept Comp Sci & Engn, Seoul 136713, South Korea
基金
新加坡国家研究基金会;
关键词
Linux file system; FAT32; Recovered file; Creation time;
D O I
10.1016/j.diin.2015.09.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Minnaard proposed a novel method that constructs a creation time bound of files recovered without time information. The method exploits a relationship between the creation order of files and their locations on a storage device managed with the Linux FAT32 file system. This creation order reconstruction method is valid only in non-wraparound situations, where the file creation time in a former position is earlier than that in a latter position. In this article, we show that if the Linux FAT32 file allocator traverses the storage space more than once, the creation time of a recovered file is possibly earlier than that of a former file and possibly later than that of a latter file on the Linux FAT32 file system. Also it is analytically verified that there are at most n candidates for the creation time bound of each recovered file where n is the number of traversals by the file allocator. Our analysis is evaluated by examining file allocation patterns of two commercial in-car dashboard cameras. (C) 2015 Elsevier Ltd. All rights reserved.
引用
收藏
页码:119 / 123
页数:5
相关论文
共 4 条
[1]  
Carrier B., 2005, File System Forensic Analysis
[2]   The Linux FAT32 allocator and file creation order reconstruction [J].
Minnaard, Wicher .
DIGITAL INVESTIGATION, 2014, 11 (03) :224-233
[3]   Pinpointing TomTom location records: A forensic analysis [J].
Nutter, Beverley .
DIGITAL INVESTIGATION, 2008, 5 (1-2) :10-18
[4]   Forensic acquisition and analysis of the Random Access Memory of TomTom GPS navigation systems [J].
van Eijk, Onno ;
Roeloffs, Mark .
DIGITAL INVESTIGATION, 2010, 6 (3-4) :179-188