Open-Source Forensics Tools for Recovery of Deleted Data in Unconventional Ways

Open-Source Forensics Tools for Recovery of Deleted Data in Unconventional Ways

Tuqa Al-Makkawi (Hashemite University, Jordan), Ayoub Alsarhan (Hashemite University, Jordan), Qais Al-Na'amneh (Applied Science Private University, Jordan), Mohammad Aljaidi (Zarqa University, Jordan), Mohammed Amin Almaiah (University of Jordan, Jordan), Mahmoud AlJamal (Hashemite University, Jordan), Rabee Alqura'n (Hashemite University, Jordan), and Mahmoud Aljawarneh (Applied Science Private University, Jordan)
DOI: 10.4018/979-8-3693-8014-7.ch003
OnDemand:
(Individual Chapters)
Available
$37.50
No Current Special Offers
TOTAL SAVINGS: $37.50

Abstract

Nowadays, technology is propagation rapidly that it is virtually completely replacing the real world with a “virtual world.” Electronic forensics important as medical forensics to investigate electronic crime” which increases with time”, to prevent unwanted file recovery, many computer users choose to overwrite files instead of deleting them to collect evidence and analysis by several methods and tools to present in front of the law. This paper studies the collection and analysis of files with an emphasis on deleted files from different resources and evaluates the performance of open-source programs for recovering deleted data using unconventional ways. It discusses some forensics tools, including FTK, and Encase, and the ability to extract the deleted file, showing a general comparison between forensics tools.
Chapter Preview

Complete Chapter List

Search this Book:
Reset