Skip to Content
Cyber Forensics: From Data to Digital Evidence
book

Cyber Forensics: From Data to Digital Evidence

by Frederic Guillossou, Albert J. Marcella
May 2012
Beginner content levelBeginner
342 pages
8h 6m
English
Wiley
Content preview from Cyber Forensics: From Data to Digital Evidence

CHAPTER NINE

File Systems—NTFS and Beyond

CHAPTER 9 FURTHER EXAMINES file systems, focusing now on file systems beyond FAT, which are those most likely to be encountered by the cyber forensic investigator.

As technology truly does march to its own beat and is constantly in a state of flux and change, the cyber forensics professional should be attuned to the changes announced by vendors regarding their operating systems and the file system variations that may emerge from any advancement in operating system designs and future release updates to these operating systems.

NEW TECHNOLOGY FILE SYSTEM

Next up, a review of another Windows file system, the New Technology File System (NTFS), whose use started with Windows NT in 1993. Windows XP, 2000, Server 2003, 2008, and Windows 7 also all use later versions of NTFS. The filing system is very complex and to make matters worse there are very little published specifications from Microsoft that describes the “on-disk layout.”

What this means is that logical representations of the physical structure of this file system are speculative and very difficult to visualize. It’s a good thing our goal here is not an in-depth bit-for-bit analysis of each file system, but instead a more conceptual understanding of file systems in general.

An important concept in understanding the NTFS design is that all data is allocated to files, including the file system itself; the file system files can be located anywhere in the volume, as would a regular file. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Digital Forensics and Internet of Things

Digital Forensics and Internet of Things

Anita Gehlot, Rajesh Singh, Jaskaran Singh, Neeta Raj Sharma
Cyber Crime and Cyber Terrorism Investigator's Handbook

Cyber Crime and Cyber Terrorism Investigator's Handbook

Babak Akhgar, Andrew Staniforth, Francesca Bosco

Publisher Resources

ISBN: 9781118273661Purchase book