Optimal sector sampling for drive triage

Download
Author
Taguchi, James K.
Date
2013-06Advisor
Young, Joel D.
Garfinkel, Simson L.
Metadata
Show full item recordAbstract
With digital storage becoming cheaper, bigger, and more prevalent, finding evidence from the hard drives collected for a case is too difficult and time consuming. Simply reading an entire drive takes hours and it takes even longer to analyze the drive for deleted files and data fragments. Investigations frequently involve multiple drives, and this traditional method of reading entire drives for analysis simply cannot keep up in modern cases. Furthermore, investigators often search drives only for known files, which we call target data, that could help identify a drive holding evidence such as child pornography or malware. Triage is needed to sift through drives to quickly identify drives containing target data. One way is by randomly sampling drive data to find known files or to give a confidence that less than some small amount is present. We determine the optimal sampling strategy bypassing the file system to find even deleted files and fragments in minimum time with maximum confidence. With 15 minutes of sampling we can give a 90% confidence that less than 10MiB of target data is present on a 500GB hard disk drive. By using statistical sampling in combination with sector hashing, our software forms an efficient triage tool for digital forensics.
Rights
This publication is a work of the U.S. Government as defined in Title 17, United States Code, Section 101. Copyright protection is not available for this work in the United States.Related items
Showing items related by title, author, creator and subject.
-
Associating Drives Based on Their Artifact and Metadata Distributions
Rowe, Neil C. (ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, 2019);Associations between drive images can be important in many forensic investigations, particularly those involving organizations, conspiracies, or contraband. This work investigated metrics for comparing drives based on the ... -
Turbulence profiles and outer length scale determination in the atmosphere using balloons/ Aaron M Holdaway
Holdaway, Aaron M. (Monterey, California. Naval Postgraduate School, 2000-03);Turbulence in the atmosphere drives the formation of temperature inhomogeneities that scatter and diffract propagating electromagnetic waves, adversely affecting laser weapons and high-resolution optical systems. Military ... -
Maritime Strategy and Naval Innovation (Continuation)
Russell, James A.; Wirtz, Jim (Monterey, California: Naval Postgraduate SchoolMonterey, California. Naval Postgraduate School, 2019-12); NPS-19-N001-AThis project is a continuation of ongoing support by NPS to the work of N50 to further refining and improving the Navy's strategy development and implementation processes. This will be the fourth year of support to the ...