메뉴 건너뛰기
소속 기관 / 학교 인증
인증하면 논문, 학술자료 등을  무료로 열람할 수 있어요.
한국대학교, 누리자동차, 시립도서관 등 나의 기관을 확인해보세요
(국내 대학 90% 이상 구독 중)
고객센터 ENG
주제분류

추천
검색

논문 기본 정보

자료유형
학위논문
저자정보

(아주대학교, 아주대학교 대학원)

지도교수
손태식
발행연도
저작권
아주대학교 논문은 저작권에 의해 보호받습니다.

이용수10

표지
AI에게 요청하기
추천
검색

초록· 키워드

상세정보 수정요청해당 페이지 내 제목·저자·목차·페이지
정보가 잘못된 경우 알려주세요!
Digital forensics is defined as a process and method for inquiring and proving, in a court of law, specific actions and factual grounds of occurrences through digital devices. The importance of digital forensics is becoming heightened as the personal and corporate digital devices, such as smartphones and tablet PC, have become more essential and critical as our daily usage of these devices are diversified in recent years. Crimes that abuse or target digital devices are increasing, and obtaining evidence through digital devices have increased significantly.
Among digital forensics area, recovering deleted data is playing an important role because it could discover key evidence stored within the digital devices. Moreover, in order to establish restored data as evidence, all process must observe due process, and data acquisition process must especially be carefully attended to. If due process is not observed during the data acquisition process, a solid evidence acquired in the process may not be admissible as a key evidence. Therefore, laws and institutional matters related to this topic has been actively studied, and there is a necessity for further research on technical areas.
Digital device relies on file system structure to store data on the storage. Among these file systems, Ext4 file system is a well-known file system typically used in a Linux distribution version, and are being used in many types of digital devices, from Android to raspberry pi. Therefore, the need for a study on analysis and restoration of deleted file for Ext4 file system is becoming more prominent in the modern digital society.
In this study, we proposed new digital forensic technique for Ext4 file system and analyzed a few considerations that are required from the legal and institutional perspective.

목차

  1. 1. Introduction 1
    2. Background and related works 4
    A. Ext4 filesystem 4
    B. Related works 9
    3. The issue of admissibility of digital evidence 12
    A. Analysis of laws and precedent 12
    1. Analysis on the relevant law and finding its limitations 12
    2. Analysis of cases related to establishing admissibility 15
    B. Acquiring methods for legally admissible digital evidence 20
    4. Deleted data recovery for Ext4 based Open Platform Systems 23
    A. Acquisition and analysis of digital evidence 23
    1. Acquiring digital evidence using a dd command (imaging) 23
    2. Analyzing acquired data 24
    B. Deleted file recovery using journal area 28
    1. Checking unallocated inode number 28
    2. Confirming the deleted inode from unallocated inode 29
    3. Finding deleted inode at journal area 31
    C. File name recovery through directory entry 33
    1. Directory entry analysis 34
    2. Identify the directory entry of the deleted file 35
    3. Understand the directory entry creation mechanism 35
    4. The H-tree structure in directory entry 36
    D. Design and implementation of recovery tool 37
    5. Experiment and result 44
    A. Confirming the reliability of the data acquisition methods 44
    B. Deleted file recovery 48
    6. Conclusion 53
    7. References 54

최근 본 자료

전체보기