2015
DOI: 10.1016/j.diin.2015.05.013
|View full text |Cite
|
Sign up to set email alerts
|

Database forensic analysis through internal structure carving

Abstract: a b s t r a c tForensic tools assist analysts with recovery of both the data and system events, even from corrupted storage. These tools typically rely on "file carving" techniques to restore files after metadata loss by analyzing the remaining raw file content. A significant amount of sensitive data is stored and processed in relational databases thus creating the need for database forensic tools that will extend file carving solutions to the database realm. Raw database storage is partitioned into individual… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
21
0

Year Published

2017
2017
2023
2023

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 39 publications
(21 citation statements)
references
References 11 publications
0
21
0
Order By: Relevance
“…Internal database investigation MariaDB requires knowledge to interpret every bit contained in each table in the database [4,8]. Digital forensic analysis is not possible without a good understanding of the properties of the MariaDB table [12].…”
Section: Results Of Internal Investigationsmentioning
confidence: 99%
See 2 more Smart Citations
“…Internal database investigation MariaDB requires knowledge to interpret every bit contained in each table in the database [4,8]. Digital forensic analysis is not possible without a good understanding of the properties of the MariaDB table [12].…”
Section: Results Of Internal Investigationsmentioning
confidence: 99%
“…The internal investigation includes checking the database engine which is the default used by MariaDB [4]. MariaDB stores all information on each table into the .frm file.…”
Section: Internal Investigationmentioning
confidence: 99%
See 1 more Smart Citation
“…First of all, reactive database forensics is comprised of bottom-up methods that adapt traditional digital forensics techniques for recovering scattered pieces of evidence in order to reconstruct the database state [7]. Examples of these methods are table-relationship analysis [8] and data file carving [9]. However, these methods either lack formalisation and scientific background [10], or may not be suitable for investigating databases [11].…”
Section: Introductionmentioning
confidence: 99%
“…It is possible to retrieve data from databases by other means. In the study of [24], some work has been done on recovering data from DBMS structures. Another subject to consider is compressed data within databases.…”
Section: Releated Workmentioning
confidence: 99%