Research Article

A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives

Volume: 4 Number: 3 December 31, 2021
EN

A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives

Abstract

The development and widespread use of computer systems has increased the need for secure storage of data. At the same time, the analysis of digital data storage devices is very important for forensic IT professionals who aim to access information to clarify the crime. File systems of disk drives use partition structures to securely store data and prevent problems such as corruption. In this study, deletion or corruption of partitions on commonly used DOS / Master Boot Record (MBR) configured hard disk drives are investigated by using forensic tools. In order to analyze hard disk drives, Forensic Tool Kit (FTK), Magnet AXIOM, Encase, Autopsy and The Sleuth Kit (TSK), which are widely used as commercial and open source, are analyzed by using a presented scenario. In the scenario, the primary partition and the extended partition are created using the DOS / MBR partitioning structure on the test disk. Test files are added to the sections and the sections are deleted. The digital forensics tools were tested on the presented scenario. According to the obtained results, TSK and Encase are successful tools for DOS / MBR structured HDD analysis. However, FTK, Magnet AXIOM and Autopsy could not achieve information detection on DOS/MBR structured disks. These results clearly demonstrated that crime data can be hidden in MBR structured HDD. To carve these data, the correct methodology should be selected.

Keywords

References

  1. [1] C. Altheide and H. Carvey, Digital forensics with open source tools. Elsevier, 2011.
  2. [2] B. Carrier, "Open source digital forensics tools: The legal argument," stake, 2002.
  3. [3] R. Harris, "Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem," digital investigation, vol. 3, pp. 44-49, 2006.
  4. [4] G. Horsman, "Formalising investigative decision making in digital forensics: proposing the Digital Evidence Reporting and Decision Support (DERDS) framework," Digital Investigation, vol. 28, pp. 146-151, 2019.
  5. [5] T. Vidas, B. Kaplan, and M. Geiger, "OpenLV: Empowering investigators and first-responders in the digital forensics process," Digital Investigation, vol. 11, pp. S45-S53, 2014.
  6. [6] S. L. Garfinkel, "Digital forensics research: The next 10 years," digital investigation, vol. 7, pp. S64-S73, 2010.
  7. [7] Y. Guo, J. Slay, and J. Beckett, "Validation and verification of computer forensic software tools—Searching Function," digital investigation, vol. 6, pp. S12-S22, 2009.
  8. [8] A. C. Bogen and D. A. Dampier, "Unifying computer forensics modeling approaches: a software engineering perspective," in First International Workshop on Systematic Approaches to Digital Forensic Engineering (SADFE'05), 2005: IEEE, pp. 27-39.

Details

Primary Language

English

Subjects

Empirical Software Engineering

Journal Section

Research Article

Publication Date

December 31, 2021

Submission Date

November 13, 2021

Acceptance Date

December 7, 2021

Published in Issue

Year 2021 Volume: 4 Number: 3

APA
Akbal, E., Yakut, Ö. F., Dogan, S., Tuncer, T., & Ertam, F. (2021). A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives. Sakarya University Journal of Computer and Information Sciences, 4(3), 326-346. https://doi.org/10.35377/saucis...1022600
AMA
1.Akbal E, Yakut ÖF, Dogan S, Tuncer T, Ertam F. A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives. SAUCIS. 2021;4(3):326-346. doi:10.35377/saucis.1022600
Chicago
Akbal, Erhan, Ömer Faruk Yakut, Sengul Dogan, Türker Tuncer, and Fatih Ertam. 2021. “A Digital Forensics Approach for Lost Secondary Partition Analysis Using Master Boot Record Structured Hard Disk Drives”. Sakarya University Journal of Computer and Information Sciences 4 (3): 326-46. https://doi.org/10.35377/saucis. 1022600.
EndNote
Akbal E, Yakut ÖF, Dogan S, Tuncer T, Ertam F (December 1, 2021) A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives. Sakarya University Journal of Computer and Information Sciences 4 3 326–346.
IEEE
[1]E. Akbal, Ö. F. Yakut, S. Dogan, T. Tuncer, and F. Ertam, “A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives”, SAUCIS, vol. 4, no. 3, pp. 326–346, Dec. 2021, doi: 10.35377/saucis...1022600.
ISNAD
Akbal, Erhan - Yakut, Ömer Faruk - Dogan, Sengul - Tuncer, Türker - Ertam, Fatih. “A Digital Forensics Approach for Lost Secondary Partition Analysis Using Master Boot Record Structured Hard Disk Drives”. Sakarya University Journal of Computer and Information Sciences 4/3 (December 1, 2021): 326-346. https://doi.org/10.35377/saucis. 1022600.
JAMA
1.Akbal E, Yakut ÖF, Dogan S, Tuncer T, Ertam F. A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives. SAUCIS. 2021;4:326–346.
MLA
Akbal, Erhan, et al. “A Digital Forensics Approach for Lost Secondary Partition Analysis Using Master Boot Record Structured Hard Disk Drives”. Sakarya University Journal of Computer and Information Sciences, vol. 4, no. 3, Dec. 2021, pp. 326-4, doi:10.35377/saucis. 1022600.
Vancouver
1.Erhan Akbal, Ömer Faruk Yakut, Sengul Dogan, Türker Tuncer, Fatih Ertam. A Digital Forensics Approach for Lost Secondary Partition Analysis using Master Boot Record Structured Hard Disk Drives. SAUCIS. 2021 Dec. 1;4(3):326-4. doi:10.35377/saucis. 1022600

Cited By

 

INDEXING & ABSTRACTING & ARCHIVING

 

31045 31044   ResimLink - Resim Yükle  31047 

31043 28939 28938 34240
 

 

29070    The papers in this journal are licensed under a Creative Commons Attribution-NonCommercial 4.0 International License