کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
457845 696061 2013 11 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A metadata-based method for recovering files and file traces from YAFFS2
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
A metadata-based method for recovering files and file traces from YAFFS2
چکیده انگلیسی

Nowadays, flash memory has drawn much attention of digital investigators, however most of them try to recover the content from logical aspect and few of them pay attention to how those files were created or modified. The deleted and edited contents of a file on the flash chips are commonly related to user behaviors which can be used as digital evidence. In this paper, a method using YAFFS2 metadata to recover files, reconstruct file system, and recover their previous history versions is proposed. The experimental results under Linux operating system show that the proposed method can correctly reconstruct file system, recover file and file traces from YAFFS2; and experiments conducted on physical images of Android phones show that our method can be applied to real scenarios.


► Recovering files and reconstructing file system from YAFFS2 image based on metadata.
► Recovering history versions of files from YAFFS2 image.
► Recovering files and traces based on a simulated NAND chips under Linux.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 10, Issue 1, June 2013, Pages 62–72
نویسندگان
, , , , , , ,