earticle

논문검색

Internet

Design and Implementation of APFS Object Identification Tool for Digital Forensics

초록

영어

Since High Sierra, APFS has been used as the main file system. It is a well-established file system that has been used stably thus far. From the perspective of digital forensics, there are still many areas to be investigated. Apple File System Reference is provided to the apple developer site, but it is not satisfactory to fully analyze APFS. Researchers know more about the structure of APFS than before, but they have not yet fully analyzed its structure to a perfect level about it. In this paper, we develop APFS object identification tool for digital forensics. The most basic and essential object identification and analysis of the APFS filesystem will be conducted with the tool. The analysis in this study serves as the background for an analysis of the checkpoint operation principle and structure, including the more complex B-tree structure of APFS. There are several options for the developed tool, but the results of two use cases will be shown here. Based on the implemented tool, it is hoped that more functions will be added to make APFS a useful tool for faster and more accurate analyses.

목차

Abstract
1. Introduction
2. Object’s data type
2.1 Object Types
2.2 Object Flags
2.3 Object subtype
2.4 APFS Overall Configuration
3. Configuration of the APFS Object Identification Tool
3.1 Overview
3.2 Development Environments
3.3 Command Line Options
3.4 Experimental Results
5. Conclusions
Acknowledgement
References

저자정보

  • Gyu-Sang Cho Professor, Dept. of Computer&Software, Dongyang University, Korea

참고문헌

자료제공 : 네이버학술정보

    함께 이용한 논문

      ※ 기관로그인 시 무료 이용이 가능합니다.

      • 4,000원

      0개의 논문이 장바구니에 담겼습니다.