首页 | 本学科首页   官方微博 | 高级检索  
     检索      


The Linux FAT32 allocator and file creation order reconstruction
Institution:1. Institut de Recherche Criminelle de la Gendarmerie Nationale (IRCGN), Digital Forensics department (INL), 1 boulevard Théophile Sueur, 93110 Rosny-Sous-Bois, France;2. PRES Sorbonne Universités – Université Panthéon-Assas Paris II, 12 place de Panthéon, 75005 Paris Cedex 05, France;3. Kriminaltechnisches Institut (KTI) des Bundeskriminalamtes (BKA), Äppelallee 45, 65173 Wiesbaden, Germany;1. Faculty of Computing, Engineering and Science, University of South Wales, Treforest, CF37 1DL, UK;2. ECU Security Research Institute, Perth, Australia;3. Noroff University College, Norway
Abstract:The allocation algorithm of the Linux FAT32 file system driver positions files on disk in such a way that their relative positions reveal information on the order in which these files have been created. This provides an opportunity to enrich information from (carved) file fragments with time information, even when such file fragments lack the file system metadata in which time-related information is usually to be found.Through source code analysis and experiments the behaviour of the Linux FAT allocator is examined. How an understanding of this allocator can be applied in practice is demonstrated with a case study involving a TomTom GPS car navigation device. In this case, time information played a crucial role. Large amounts of location records could be carved from this device's flash storage, yielding insight into the locations the device has visited—yet the carved records themselves offered no information on when the device had been at the locations. Still, bounds on the records' time of creation could be inferred when making use of filesystem timestamps related to neighbouring on-disk positions.Finally, we perform experiments which contrast the Linux behaviour with that of Windows 7. We show that the latter differs subtly, breaking the strong relation between creation order and position.
Keywords:Linux kernel  TomTom  File systems  File allocation  The Sleuth Kit (TSK)  FAT16  FAT32  Event order reconstruction  Antedating
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号