论文标题
技术报告:实时系统中文件系统数据的选择性成像
Technical Report: Selective Imaging of File System Data on Live Systems
论文作者
论文摘要
与在分析之前获得完整的存储设备副本的共同习惯相反,选择性成像有望减轻存储设备能力增加所带来的问题。成像是选择性的,如果仅从图像中选择的明确选择的数据对象包含在复制数据中。尽管已定义了用于验尸数据采集后的选择性成像,但实时执行此过程,即通过使用包含证据的系统也可以执行成像软件的确定性,但较少定义和理解。我们介绍了一个名为SIT的新的实时选择成像工具的设计和实现,该工具基于DFIR ORC框架,并将AFF4用作容器格式。我们讨论了SIT设计背后的理由并评估其有效性。
In contrast to the common habit of taking full bitwise copies of storage devices before analysis, selective imaging promises to alleviate the problems created by the increasing capacity of storage devices. Imaging is selective if only selected data objects from an image that were explicitly chosen are included in the copied data. While selective imaging has been defined for post-mortem data acquisition, performing this process live, i.e., by using the system that contains the evidence also to execute the imaging software, is less well defined and understood. We present the design and implementation of a new live Selective Imaging Tool for Windows, called SIT, which is based on the DFIR ORC framework and uses AFF4 as a container format. We discuss the rationale behind the design of SIT and evaluate its effectiveness.