Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Extending The Sleuth Kit and its underlying model for pooled storage file system forensic analysis

: Hilgert, J.-N.; Lambertz, M.; Plohmann, D.

Volltext (PDF; )

Digital Investigation 22 (2017), Supplement, S.S76-S85
ISSN: 1742-2876
ISSN: 1873-202X
Digital Forensics Research Conference (DFRWS) <17, 2017, Constance>
Zeitschriftenaufsatz, Konferenzbeitrag, Elektronische Publikation
Fraunhofer FKIE ()

Carrier's book File System Forensic Analysis is one of the most comprehensive sources when it comes to the forensic analysis of file systems. Published in 2005, it provides details about the most commonly used file systems of that time as well as a process model to analyze file systems in general. The Sleuth Kit is the implementation of Carrier's model and it is still widely used during forensic analyses today—standalone or as a basis for forensic suites such as Autopsy.
While The Sleuth Kit is still actively maintained, the model has not seen any updates since then. Moreover, there is no support for modern file systems implementing new paradigms such as pooled storage.
In this paper, we present an update to Carrier's model which enables the analysis of pooled storage file systems. To demonstrate that our model is suitable, we implemented it for ZFS—a file system for large scale storage, cloud, and virtualization environments—and show how to perform an analysis of this file system using our model and extended toolkit.