Font Size: a A A

Research On Information Acquisition Technology Based On Data Recovery

Posted on:2008-02-20Degree:MasterType:Thesis
Country:ChinaCandidate:H WeiFull Text:PDF
GTID:2178360242472370Subject:Computer software and theory
Abstract/Summary:PDF Full Text Request
With the rapid development of computer and network, hi-tech crime is becoming more serious. Criminals would delete digital evidence which can testify crime. So it is the important subject for computer forensic to research how to acquire and analyze sensitive information from memorizer.This paper elaborates on the information acquisition technology which is based on the research and realization of two modules: one is hard disk data scan recovery module and another is network trace acquisition module. According to the research and analyze the FAT file system principle and the existence mode of the trace data, I mentioned to develop a set of tool which can acquire information form memorizer such as hard disk. And at last the successful realization of fast scan and deep scan to memorizer, finding deleted data most and detecting remnant data after formatting, restoring deleted data most and displaying the file content, and the acquisition of history data such as Index.dat.The successful research of the hard disk scan recovery module and network trace acquisition module is good at static computer forensic and can improve the traceability of system files.
Keywords/Search Tags:Hard disk Scan, Data Recovery, BPB, FAT, FDT, History data, Index.dat
PDF Full Text Request
Related items