Forensic Recovery of SQL Server Database: Practical Approach

نویسندگان

چکیده

Database forensics is becoming more important for investigators with the increased use of information system. Although various database forensic methods such as log analysis and investigation model development have been studied, among methods, recovering deleted data a key technique in DB tampering anti-forensics. Previous studies mainly focused on transaction or journal to recover data, but if logs are set be periodically containing critical evidence overwritten by new logs, log-based recovery method can not used practically. For this reason, an engine-based that analyzes file at raw level has also introduced. There research small-sized databases SQLite EDB, there no prior work describing structure technology large enterprises organizations. In context, we investigate Microsoft SQL Server (MSSQL), which one most databases. Our focuses storage engine MSSQL. Through analyzing engine, identify internal MSSQL files mechanism. Based these findings, tables records presented empirical examination. It compatible versions because it accesses level. proposed verified comparative experiment tools implemented data. The experimental results show our recovers all from unallocated area. types including multimedia called Large Objects (LOB) field. To contribute digital community, provide source code implementation; facilitates knowledge sharing forensics.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

SD-SQL Server: Scalable Distributed Database System

We present SD-SQL Server, a prototype scalable distributed database system. It let a relational table to grow over new storage nodes invisibly to the application. The evolution uses splits dynamically generating a distributed range partitioning of the table. The splits avoid the reorganization of a growing database, necessary for the current DBMSs and a headache for the administrators. We illus...

متن کامل

Overview of Scalable Distributed Database System SD-SQL Server

We present a scalable distributed database system SD-SQL Server. Its original feature is the scalable distributed partitioning of its relational tables. The system dynamically distributes the tables into segments created each at a different SD-SQL Server node. The partitioning is transparent to the applications. New segments result from splits following overflowing inserts. SD SQL Server avoids...

متن کامل

Implementing SD - SQL Server : a Scalable Distributed Database System ( Extended

SD-SQL Server is a scalable distributed DBS using internally the SQL Server. The relational tables of SD-SQL Server scale through splits transparently for the application. SD-SQL Server is the only DBS with this capability at present. It constitutes an important step beyond the current technology of a parallel DBMS, long awaited by the users. The splitting and addressing principles of our syste...

متن کامل

MTCache: Mid-Tier Database Caching for SQL Server

MTCache is a prototype mid-tier database caching solution for SQL Server that transparently offloads part of the query workload from a backend server to front-end servers. The goal is to improve system throughput and scalability but without requiring application changes. This paper outlines the architecture of MTCache and highlights several of its key features: modeling of data as materialized ...

متن کامل

SQL Server Workload Consolidation

Database workloads are very diverse. While most database servers are lightly loaded, larger database workloads can be resource-intensive, exhibiting high I/O rates or consuming large amounts of memory. With improvements in virtualization technology and hardware, even servers running large database workloads run well in virtual machines. Servers running Microsoft's SQL Server, among the top data...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: IEEE Access

سال: 2021

ISSN: ['2169-3536']

DOI: https://doi.org/10.1109/access.2021.3052505