A Dual Cube Hashing Scheme for Solving LPP Integrity Problem

A Dual Cube Hashing Scheme for Solving LPP Integrity Problem
复制标题

解决LPP完整性问题的双立方哈希方案

DOI:
10.1109/sadfe.2011.1
复制
发表时间:
2011
期刊:
2011 Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering
影响因子:
--
通讯作者:
X. Niu
X. Niu
中科院分区:
--
文献类型:
--
作者:
Jun;Z. L. Jiang;S. Yiu;K. Chow;L. Hui;Long Chen;X. Niu

文献摘要

被引文献

相似文献

在数字取证中,存储在硬盘中的数据通常包含有价值的证据。保护硬盘中数据的完整性是一个关键问题。整个硬盘的单个散列值是不合适的,因为调查可能需要很长时间,并且潜在的扇区错误(LSE)(例如,由于介质缺陷导致的坏扇区)会导致扇区突然不可读,从而使散列值不一致。另一方面,使用每个扇区的散列值可能需要存储大量散列值。以前的研究已经使用较少的散列值,但即使存在LSE,也可以抵抗一些LSE来减少不可验证的扇区数量。在数字取证中,当被扣押的硬盘内存在法律专业特权(LPP)数据时,这种完整性问题更加复杂,因为一旦被扣押,硬盘就必须被克隆,克隆后原始硬盘将被密封。在此克隆过程中需要计算哈希值。但是,在调查员可以处理经过消毒的副本之前,克隆的副本将被返回给嫌疑人以删除LPP数据。因此,必须使用基于原始硬盘计算的散列值来验证未修改扇区的完整性。本文发现现有方案不能很好地解决同时存在LSE和删除LPP数据时的完整性问题。然后,我们提出了一种“双立方体”散列方案来解决这个问题。实验表明,该方案比以往的方案具有更好的性能,更适合于数字取证过程。
In digital forensics, data stored in a hard disk usually contains valuable evidence. Preserving the integrity of the data in the hard disk is a critical issue. A single hash value for the whole hard disk is not appropriate as the investigation may take a long time and latent sector errors (LSEs) (bad sectors due to media imperfection, for example) which cause a sector suddenly unreadable will make the hash value inconsistent. On the other hand, using a hash per sector may need to store a lot of hash values. Previous research has been conducted to use fewer hash values, but can resist some of LSEs to decrease the number of unverifiable sectors even if there are LSEs. This integrity problem is more complicated in the presence of Legal Professional Privileged (LPP) data inside a seized hard disk in digital forensic as the hard disk has to be cloned once seized and the original hard disk will be sealed after cloning. Hash values need to be computed during this cloning process. However, the cloned copy will be returned to the suspect for the deletion of LPP data before the investigator can work on the sanitized copy. Thus, the integrity of unmodified sectors has to be verified using the hash values computed based on the original hard disk. This paper found that existing schemes are not good enough to solve the integrity problem in the presence of both LSEs and deletion of LPP data. We then propose the idea of a “Dual Cube” hashing scheme to solve the problem. The experiments show the proposed scheme performs better than the previous schemes and fits easily into the digital forensic procedure.