Detecting Hidden Encrypted Volumes - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Detecting Hidden Encrypted Volumes

Résumé

Hidden encrypted volumes can cause problems in digital investigations since they provide criminal suspects with a range of opportunities for deceptive anti-forensics and a countermeasure to legislation written to force suspects to reveal decryption keys. This paper describes how hidden encrypted volumes can be detected, and their size estimated. The paper shows how multiple copies of an encrypted container can be obtained from a single disk image of Windows Vista and Windows 7 systems using the Volume Shadow Copy feature, and how the changes between shadow copies can be visualised to detect hidden volumes. The visualisation assists in the presentation of this information to a court, and exposes patterns of change which allows the size and file system of the hidden volume to be determined.
Fichier principal
Vignette du fichier
cms2010_submission_32.pdf (257.04 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01056376 , version 1 (18-08-2014)

Licence

Paternité

Identifiants

Citer

Christopher Hargreaves, Howard Chivers. Detecting Hidden Encrypted Volumes. 11th IFIP TC 6/TC 11 International Conference on Communications and Multimedia Security (CMS), May 2010, Linz, Austria. pp.233-244, ⟨10.1007/978-3-642-13241-4_21⟩. ⟨hal-01056376⟩
501 Consultations
2231 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More