Abstract : Nowadays, forensic on flash memories has drawn much attention. In this paper, a recovery method for SQLite database history records (I.e. updated and deleted records) form YAFFS2 is proposed. Based on the out-of-place-write strategies in NAND flash memory required by YAFFS2, the SQLite history recorders can be recovered and ordered into timeline by their timestamps. The experiment results show that the proposed method can recover the updated or deleted records correctly. Our method can help investigators to find the significant information about user actions in Android smart phones by these history recorders, although they seem to have been disappeared or deleted.
https://hal.inria.fr/hal-01480183 Contributor : Hal IfipConnect in order to contact the contributor Submitted on : Wednesday, March 1, 2017 - 11:04:52 AM Last modification on : Thursday, March 2, 2017 - 1:04:25 AM Long-term archiving on: : Tuesday, May 30, 2017 - 2:31:24 PM
Beibei Wu, Ming Xu, Haiping Zhang, Jian Xu, yizhi Ren, et al.. A Recovery Approach for SQLite History Recorders from YAFFS2. 1st International Conference on Information and Communication Technology (ICT-EurAsia), Mar 2013, Yogyakarta, Indonesia. pp.295-299, ⟨10.1007/978-3-642-36818-9_30⟩. ⟨hal-01480183⟩