期刊文献+

基于Ext4元数据Extent树重构的数据恢复研究 被引量:2

Research on Ext4 Recovery by Metadata Extent Reconstruction
下载PDF
导出
摘要 为了解决计算机取证中Ext4文件系统的数据恢复问题,提出了一种基于文件头尾特征元数据Extent重构的恢复方法。在Extent树完整性遭到破坏的情况下提出了重构的方法,通过扫描磁盘扇区定位文件头尾特征所在的磁盘位置,确定文件大小,并根据ext4_extent_header中魔数信息实现对Extent的重建,进而实现对文件的恢复。实验结果表明,经该方法设计的软件在文件恢复的时间效率和成功率方面有了较大的提高。 In order to realize Ext4 file system data recovery in computer forensics, this paper propo- ses a recovery method based on extent reconstruction of head and foot feature metadata. In the con- text of Extent tree integrity damage, an Extent reconstruction method is proposed. By scanning the disk sector, the head and tail characteristics of the file could be located and the file size could be determined. Then, the ext4_exteut_header magical number is utilized to reconstruct Extent and re- cover file completely. Experimental results show that the software designed by the recovery method can improve evidently the time efficiency and success rate.
出处 《信息工程大学学报》 2017年第1期98-102,共5页 Journal of Information Engineering University
基金 国家自然科学基金资助项目(60903220)
关键词 Ext4文件系统 Extent 文件头尾特征 恢复 Ext4 file system Extent head and foot feature recovery
  • 相关文献

参考文献1

二级参考文献10

  • 1李炳龙,王清贤,罗军勇,刘镔.可信计算环境中的数字取证[J].武汉大学学报(理学版),2006,52(5):523-526. 被引量:9
  • 2Kruse W, Heiser J. Computer Forensics: Incident Response Essentials[M]. Addison Wesley, 2001.
  • 3Reith M, Carr C. An examinatkm of digital forensics modeh[J]. International .Journal of Digital Evidence, 2002,1 (3): 1- 12.
  • 4Scicntiflc Working Group on Digital Evidence. ASCLD Glossary Definitions: Version 1.0[EB/OL], Available at: http://www.swgde.org. 2005.
  • 5Carrie M W. An Historicai Perspective of Digital Evidence: A F ic Scientist's View[J1. International Journal of Digital Evidence (IJDE), 2002,1 (1):235-246.
  • 6United States National Institute of Justice Technical Working Group for Electronic Crime Scene Investigation. Electronic Crime Scene Investigation: A Guide for First Responders, July 2-X)1.
  • 7Binglong Li, Qingxian Wang, Junyong Luo, Forensic Analysis of Document Fragment Based On SVMIC1. 2006 International Conference on Intelligent Information Hiding and Multimedia. 2(X)6: 236-239.
  • 8Peter S. The Application of Formal Methods to Root Cause Analysis of Digital Incidents[J]. lntemationalJoumal of Digital Evidence. 2004,3(1).
  • 9Pavel G, Ahmed P. Finite State Machine Approach to Digital Event Reconstruction[J]. International Journal of Digital Investigation, 2004,1 (2).
  • 10李炳龙 王清贤 罗军勇 等.文档碎片分类模型及其关键问题[J].哈尔滨工业大学学报,2006,38:834-834.

共引文献12

同被引文献3

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部