Quantifying Windows File Slack Size and Stability

نویسندگان

  • Martin Mulazzani
  • Sebastian Neuner
  • Peter Kieseberg
  • Markus Huber
  • Sebastian Schrittwieser
  • Edgar R. Weippl
چکیده

In digital forensics, different forms of slack space can be used to hide information from either the operating system or other users, or both. While some forms are easily detectable others are very subtle, and require an experienced forensic investigator to discover the hidden information. The exact amount of information that can be hidden varies with the form of slack space used, as well as environmental parameters like file system block size or partition alignment. While some methods for slack space can be used to hide arbitrary amounts of information, file slack has tighter constraints and was thought to be rather limited in space. In this paper we evaluate how much file slack space modern operating systems offer by default and how stable it is over time with special regards to system updates. In particular we measure the file slack for 18 different versions of Microsoft Windows using NTFS. We show that many files of the operating systems are rather static regarding system updates and do not change much on disk during updates, and are thus highly suitable for hiding information. We furthermore introduce a model for investigators to estimate the total amount of data that can be hidden in file slack for file systems of arbitrary size.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Single machine slack due-window assignment and scheduling of linear time-dependent deteriorating jobs and a deteriorating maintenance activity

In this paper, we consider the slack due-window assignment model and study a single machine scheduling problem of linear time-dependent deteriorating jobs and a deteriorating maintenance activity. The cost for each job consists of four components: earliness, tardiness, window location and window size. The objective is to schedule the jobs and to assign the maintenance activity and due-windows s...

متن کامل

Clockwise: A Mixed-Media File System

This (short) paper presents the Clockwise, a mixedmedia file system. The primary goal of the Clockwise is to provide a storage architecture that supports the storage and retrieval of best-effort and real-time file system data. Clockwise provides an abstraction called a dynamic partition that groups lists of related (large) blocks on one or more disks. Dynamic partition can grow and shrink in si...

متن کامل

A Comparison of File Size Traces

Outline Large scale traces of file sizes on file systems were collected and compared. The traces were compared using descriptive, explorative and inferential methods. The result of the study is, that the data on unix file systems has increased functionally over 10 years and that file sizes on windows file systems are structured differently.

متن کامل

Slack Space Recycling: Delaying On-Demand Cleaning in LFS for Performance and Endurance

The Log-structured File System (LFS) transforms random writes to a huge sequential one to provide superior write performance on storage devices. However, LFS inherently suffers from overhead incurred by cleaning segments. Specifically, when file system utilization is high and the system is busy, write performance of LFS degenerates significantly due to high cleaning cost. Also, in the newer fla...

متن کامل

Heuristic Methods for Solving Job-Shop Scheduling Problems

Solving scheduling problems with Constraint Satisfaction Problems (CSP’s) techniques implies a wide space search with a large number of variables, each one of them with a wide interpretation domain. This paper discusses the application of CSP heuristic techniques (based on the concept of slack of activities) for variable and value ordering on a special type of job-shop scheduling problems in wh...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013