2015
DOI: 10.14257/ijhit.2015.8.3.36
|View full text |Cite
|
Sign up to set email alerts
|

Recovering YAFFS2 Files for Forensic Analysis Based on Timestamps and Tnode Trees

Abstract: As Android-based intelligent devices get more popular, digital technologies for forensic investigation have received increasingly more attention. Among the main technical issues in digital forensics, however, data recovery requires a significant amount of effort. In this paper, we first analyze the characteristics of the NAND flash storage as well as the mechanisms in the YAFFS2 file system. We then propose a file reconstruction method based on timestamps using Tnode trees in the YAFFS2 file system. Based on t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...

Citation Types

0
0
0

Publication Types

Select...

Relationship

0
0

Authors

Journals

citations
Cited by 0 publications
references
References 8 publications
(18 reference statements)
0
0
0
Order By: Relevance

No citations

Set email alert for when this publication receives citations?