Reconstruction in Database Forensics
نویسندگان
چکیده
The increasing usage of databases in the storage of critical and sensitive information in many organizations has led to an increase in the rate at which databases are exploited in computer crimes. Databases are often manipulated to facilitate crimes and as such are usually of interest during many investigations as useful information relevant to the investigation can be found therein. A branch of digital forensics that deals with the identification, preservation, analysis and presentation of digital evidence from databases is known as database forensics. Despite the large amount of information that can be retrieved from databases and the amount of research that has been done on various aspects of databases, database security and digital forensics in general, very little has been done on database forensics. Databases have also been excluded from traditional digital investigations until very recently. This can be attributed to the inherent complexities of databases and the lack of knowledge on how the information contained in the database can be retrieved, especially in cases where such information have been modified or existed in the past. This thesis addresses one major part of the challenges in database forensics, which is the reconstruction of the information stored in the database at some earlier time. The dimensions involved in a database forensics analysis problem are identified and the thesis focuses on one of these dimensions. Concepts such as the relational algebra log and the inverse relational algebra are introduced as tools in the definition of a theoretical framework that can be used for database forensics. © University of Pretoria The thesis provides an algorithm for database reconstruction and outlines the correctness proof of the algorithm. Various techniques for a complete regeneration of deleted or lost data during a database forensics analysis are also described. Due to the importance of having adequate logs in order to use the algorithm, specifications of an ideal log configuration for an effective reconstruction process are given, putting into consideration the various dimensions of the database forensics problem space. Throughout the thesis, practical situations that illustrate the application of the algorithms and techniques described are given. The thesis provides a scientific approach that can be used for handling database forensics analysis practice and research, particularly in the aspect of reconstructing the data in a database. It also adds to the field of digital forensics by providing insights into the field of database forensics reconstruction.
منابع مشابه
On Dimensions of Reconstruction in Database Forensics
Although very little amount of research has been done on database forensics, current research has tacitly focused on digital examination and reconstruction of databases from a number of dimensions. The general assumption is that only one of these dimensions needs to be handled during database forensics investigations. This paper analyses the dimensions in which research in database forensics ha...
متن کاملChapter 19 RECONSTRUCTION IN DATABASE FORENSICS
Despite the ubiquity of databases and their importance in digital forensic investigations, the area of database forensics has received very little research attention. This paper presents an algorithm for reconstructing a database for forensic purposes. Given the current instance of a database and the log of modifying queries executed on the database over time, the database reconstruction algori...
متن کاملSmartphones as Distributed Witnesses for Digital Forensics
Smartphones have become an integral part of people's lives during the last few years. Their wide range of capabilities and support of additional applications cause a wealth of information to be stored on these devices. Although tools are available to extract and view the data stored on smartphones, there is currently no comprehensive process that allows for event reconstruction using the collec...
متن کاملSpecial Issue on Computer-Assisted Craniofacial Reconstruction and Modeling
The reconstruction of facial soft tissue is an essential processing phase in the fields of forensics, anthropology as well as maxillofacial surgery. In the first two areas the working subject is a skull find of a deceased where the soft tissue needs to be reconstructed. In forensics, this work helps to identify skeletons from open cases of death. In anthropology, the comparison of facial featur...
متن کاملOn metadata context in Database Forensics
Database Forensics is an important topic that has received hardly any research attention. This paper starts from the premise that this lack of research is due to the inherent complexity of databases that is not fully understood in a forensic context yet. The paper considers the relevant differences between file systems and databases and then transfers concepts of File System Forensics to Databa...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2012