2021 International Conference on Cyber Warfare and Security (ICCWS) 2021
DOI: 10.1109/iccws53234.2021.9702989
|View full text |Cite
|
Sign up to set email alerts
|

SSD Forensic: Evidence Generation and Forensic Research on Solid State Drives Using Trim Analysis

Abstract: Traditional hard drives consisting of spinning magnetic media platters are becoming things of the past as with the emergence of the latest digital technologies and electronic equipment, the demand for faster, lighter, and more reliable alternate storage solutions is imperative. To attain these requirements, flash storage technologies like Solid State Drive (SSD) has overtaken traditional hard disk drives. In a forensic analysis of flash storage devices, forensic investigators are facing severe challenges for t… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
1
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
1
1

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 8 publications
0
1
0
Order By: Relevance
“…According to the digital forensic perspective, the contradiction of using an SSD with its TRIM feature [16] has a negative effect on forensic analysis, especially on data recovery regarding the integrity value of the authenticity of data that has been lost or deleted, which means that it is necessary to carry out live forensic techniques in carrying out HDD and SSD fusion analysis. RAID 0 configuration TRIM function which refers to the SNI 27037:2014 standard uses forensic tools Sleuthkit Autopsy and Tesdisk in digital forensic investigations used for data recovery.…”
Section: Resultsmentioning
confidence: 99%
See 1 more Smart Citation
“…According to the digital forensic perspective, the contradiction of using an SSD with its TRIM feature [16] has a negative effect on forensic analysis, especially on data recovery regarding the integrity value of the authenticity of data that has been lost or deleted, which means that it is necessary to carry out live forensic techniques in carrying out HDD and SSD fusion analysis. RAID 0 configuration TRIM function which refers to the SNI 27037:2014 standard uses forensic tools Sleuthkit Autopsy and Tesdisk in digital forensic investigations used for data recovery.…”
Section: Resultsmentioning
confidence: 99%
“…It is a stage in preparing hardware and software specifications used in this research such as fusion HDD and SSD RAID 0 configuration and implementation of Non-Vollatille memory analysis used as the object of research [16]. While the forensic tools used are FTK Imager Portable and Testdisk Recovery.…”
Section: A System Preparation and Forensic Toolsmentioning
confidence: 99%
“…Foremost was also used to develop a carving tool called Scalpel, and Scalpel currently shares the code with Foremost but uses an optimized method to reduce unnecessary memory-to-memory copy and disk I/O, and has relatively good performance. However, since Scalpel has more diverse header/footer signatures and data structures for file carving than Foremost, which is set by default, the number of files that can be carved increases unnecessarily (7) . There are limitations to the experimental environment in the study.…”
Section: File Carving Toolsmentioning
confidence: 99%