File recovery and data extraction using automated data recovery tools : a balanced approach using Windows and Linux when working with an unknown disk image and filesystem / by Richard Carbone. : D68-6/161-2009E-PDF

This memorandum is the direct result of the analysis of an unknown disk containing unknown data, files and filesystem. The disk was brought to an analysis team at DRDC Valcartier by an agency that desired to ascertain the research centre’s capabilities for extracting and recovering unknown forensic data from an unknown disk and, if possible, automate the process. However, a thorough analysis using various Windows and Linux-based automated data and file recovery tools has led the author to determine that automated tools, regardless of the underlying system, are not yet up to this specific challenge. In addition, the author is of the opinion that fully automated disk recovery tools will never be entirely successful. Instead, the author has determined that a manual approach to data and file extraction will be necessary in order to recover any meaningful data or files from this disk’s unknown filesystem. However, this memorandum will only examine the automated approach used by the various Windows and Linux tools. An additional follow-up study will specifically examine the required manual approach necessary for data recovery from an unknown disk using data pattern matching techniques and sector-by-sector analysis using known file signatures.

Lien permanent pour cette publication :
publications.gc.ca/pub?id=9.821336&sl=1

Renseignements sur la publication
Ministère/Organisme Canada. Defence R&D Canada.
Titre File recovery and data extraction using automated data recovery tools : a balanced approach using Windows and Linux when working with an unknown disk image and filesystem / by Richard Carbone.
Titre de la série Technical Memorandum ; 2009-161
Type de publication Série - Voir l'enregistrement principal
Langue [Anglais]
Format Électronique
Document électronique
Note(s) "January 2013."
Includes bibliographical references.
Information sur la publication [Ottawa] : Defence Research and Development Canada, c2013.
Auteur / Contributeur Carbone, Richard.
Description x, 52 p. : tables, graphs.
Numéro de catalogue
  • D68-6/161-2009E-PDF
Descripteurs Technical reports
Computer forensics
Data extraction
Data recovery
Demander des formats alternatifs
Pour demander une publication dans un format alternatif, remplissez le formulaire électronique des publications du gouvernement du Canada. Utilisez le champ du formulaire «question ou commentaire» pour spécifier la publication demandée.
Date de modification :