Ajou University repository

An Security Analysis of Ext Filesystem metadata
Citations

SCOPUS

0

Citation Export

Publication Year
2019-12-01
Journal
TIMES-iCON 2019 - 2019 4th Technology Innovation Management and Engineering Science International Conference
Publisher
Institute of Electrical and Electronics Engineers Inc.
Citation
TIMES-iCON 2019 - 2019 4th Technology Innovation Management and Engineering Science International Conference
Keyword
Digital forensicsExtFile recoveryFilesystem
Mesh Keyword
Change timeFile recoveryFilesystemForensic investigationLinux distributionsLinux kernelSecurity analysis
All Science Classification Codes (ASJC)
Management of Technology and InnovationSoftwareEngineering (all)
Abstract
Until recently, various researches on Linux have been conducted, but the characteristics of the filesystem that can be changed as the Linux kernel version is diversified in terms of security have not been considered. Digital forensic investigations, which are not properly analyzed for major metadata changes by kernel version, can undermine investigative capabilities and lead to serious doubts about evidence. Since investigations can be conducted on a variety of Linux filesystems at the actual forensic investigation, it is necessary to analyze metadata of various filesystems by Linux distribution and kernel version. Therefore, this paper compares the difference of metadata changes that occur when deleting files for various kernel versions of Ext2 filesystems. Furthermore, we provide information about the kernel version and change time which has the change in metadata related to file recovery.
Language
eng
URI
https://aurora.ajou.ac.kr/handle/2018.oak/36476
https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85082402232&origin=inward
DOI
https://doi.org/10.1109/times-icon47539.2019.9024546
Journal URL
http://ieeexplore.ieee.org/xpl/mostRecentIssue.jsp?punumber=9006735
Type
Conference
Funding
This research was supported by Energy Cloud R&D Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Science, ICT (2019M3F2A1073386)ACKNOWLEDGMENT This work was supported by Institute for Information & communications Technology Promotion (IITP) grant funded by the Korea government (MSIT) (No.2018-0-01000, Development of Digital Forensic Integration Platform).
Show full item record

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

SHON, TAE SHIK Image
SHON, TAE SHIK손태식
Department of Cyber Security
Read More

Total Views & Downloads

File Download

  • There are no files associated with this item.