RecuperaBit: Forensic File System Reconstruction Given Partially Corrupted Metadata

DSpace/Manakin Repository

Show simple item record

dc.contributor.advisor Focardi, Riccardo it_IT Lazzarotto, Andrea <1991> it_IT 2016-02-10 it_IT 2016-05-04T11:46:25Z 2016-05-04T11:46:25Z 2016-03-09 it_IT
dc.description.abstract File system analysis is an important process in the fields of data recovery and computer forensics. The file system is formed by metadata describing how files and directories are organized in a hard drive. File system corruption, either accidental or intentional, may compromise the ability to access and recover the contents of files. Existing techniques, such as file carving, allow for the recovery of file contents partially, without considering the file system structure. However, the loss of metadata may prevent the attribution of meaning to extracted contents, given by file names or timestamps. We present a signature recognition process that matches and parses known records belonging to files on a drive, followed by a bottom-up reconstruction algorithm which is able to recover the structure of the file system by rebuilding the entire tree, or multiple subtrees if the upper nodes are missing. Partition geometry is determined even if partition boundaries are unknown by applying the Baeza-Yates–Perleberg approximate string matching algorithm. We focus on NTFS, a file system commonly found in personal computers and high-capacity external hard drives. We compare the results of our algorithm with existing open source and commercial tools for data recovery. it_IT
dc.language.iso it_IT
dc.publisher Università Ca' Foscari Venezia it_IT
dc.rights © Andrea Lazzarotto, 2016 it_IT
dc.title RecuperaBit: Forensic File System Reconstruction Given Partially Corrupted Metadata it_IT
dc.title.alternative it_IT
dc.type Master's Degree Thesis it_IT Informatica - computer science it_IT Laurea magistrale it_IT Dipartimento di Scienze Ambientali, Informatica e Statistica it_IT
dc.description.academicyear 2014/2015, sessione straordinaria it_IT
dc.rights.accessrights openAccess it_IT
dc.thesis.matricno 833897 it_IT
dc.subject.miur it_IT
dc.description.note it_IT it_IT it_IT it_IT
dc.provenance.upload Andrea Lazzarotto (, 2016-02-10 it_IT
dc.provenance.plagiarycheck Riccardo Focardi (, 2016-02-22 it_IT

Files in this item

This item appears in the following Collection(s)

Show simple item record