Reconstructing FAT File System Structures Flashcards
Photographic documentation must be used to…
Place material and to avoid claims of mistaken identity or mis-configuration
Storage comes in arbitrary forms:
- Tiny USB mass storage devices
- Gaming consoles
- Smart watches
- Phones
- Digital photo frames
- Local surveillance camera storage
- Photo frames
- Backup media
Forensic Duplication:
The ability to produce an identical byte stream from the duplicate as from the original
A forensic duplicate as a file (or artefact) containing…
Every bit of information from the source, typically in a raw format
A qualified duplicate provides…
The same information as a forensic duplicate, but contains further embedded meta-data or employs certain kinds of compression
A restored image is a…
Forensic or qualified forensic duplicate restored to another storage medium
A mirror image provides a…
Bit-wise copy from one medium to another
Device must ensure that no write occurs on the original device but…
Recall that even during the read-only operation, the device may alter its internal state
Imaging device must…
Perform sector-by-sector copying
Error conditions must be…
Identified clearly, detailed logging
Integrity of duplicated data must be…
Traceable, typically using cryptographic hash information
Creating Forensic Duplicates - Addition information which should be recorded:
- Time and location of duplication session
* Diagnostic information from device
Any mechanism providing imaging or write blocking must provide assurance of maintaining the objectives:
- Manufacturers may need to provide expert testimony when challenged
- Forensic laboratories may provide test results
- The NIST CFTT provides detailed test plans for imaging and write blocking devices
- Hardware-based systems are simple to implement and particularly to validate
Volume systems may be used to…
Combine multiple sub-volumes into a single volume
All components required for duplication must be…
Identified and recorded clearly