Methods for Detecting and Analyzing Hidden FAT32 Volumes Created with the Use of Cryptographic Tools
2013; Springer Nature; Linguagem: Inglês
10.1007/978-3-319-00945-2_21
ISSN2194-5357
AutoresIreneusz J. Jóźwiak, Michał Kędziora, Aleksandra Melińska,
Tópico(s)Cryptographic Implementations and Security
ResumoThe article describes the theoretical and practical methods for detecting and analyzing hidden volumes created with the use of cryptographic tools. The presented method is based on an analysis of the differences that result from the use of a hidden volume in FAT32 file systems. The method is effective both when the password is known to the host container and in the situations when password is not known. Potential computer forensic application of this methodology varies from standard investigations to advanced analysis of network and in the cloud data storages.
Referência(s)