Study of USB drives in work of a computer forensic expert
Authors: Pavlova A.A. | |
Published in issue: #12(17)/2017 | |
DOI: 10.18698/2541-8009-2017-12-215 | |
Category: Informatics, Computer Engineering and Control | Chapter: Methods and Systems of Information Protection, Information Security |
|
Keywords: USB drive, computer forensic examination, software, damaged devices, data recovery, data retrieval |
|
Published: 29.11.2017 |
The article considers USB drives, in particular, internal components of the USB-device, as well as systems used at present within computer forensic examination in work with USB drives. The special attention is given to the hardware-software package PC-3000 flash, which allows for data recovery from damaged USB devices, and Encase Forensic software package, which is used to search, analyze and restore data from USB devices.
References
[1] Chugunkov V. Vybiraem fleshku. Osnovnye kharakteristiki USB-flesh-nakopiteley: chto takoe flesh-nakopitel’ [Select the flash drive. The main characteristics of USB flash drives: what is a flash drive]. Available at: http://www.compbegin.ru/articles/view/_116 (accessed 22.11.2017).
[2] What is a flash drive? Available at: https://www.lifewire.com/what-is-a-flash-drive-2625794 (accessed 10 September 2017).
[3] Printsip raboty i ustroystvo USB-fleshki [Operating principle and structure of the USB stick]. Available at: https://hobbyits.com/cifrovye-texnologii/princip-raboty-i-ustrojstvo-usb-fleshki.html (accessed 10 September 2017).
[4] V chem otlichiya USB-fleshek USB 3.0 ot USB 2.0 [What’s the difference between USB 3.0 and USB 2.0 memory sticks]. Available at: http://otnaspodarok.ru/v-chem-otlichiya-fleshek-usb-3-0-ot-usb-2-0/ (accessed 10 September 2017).
[5] Polezhaev P.N. “The Achilles heel” of USB-devices: attack and defense. Filosofskie problemy informatsionnykh tekhnologiy i kiberprostranstva [Philosophical problems of IT and Cyberspace], 2015, no. 1. Available at: http://cyberspace.pglu.ru/issues/detail.php?ELEMENT_ID=98191.
[6] Spiryaev O. Tekhnologii flesh-pamyati [USB-memory technologies]. Available at: https://www.bytemag.ru/articles/detail.php?ID=8660 (accessed 11 September 2017).
[7] USB-fleshki: chto eto i zachem oni nuzhny [USB stick: what is it and what do we need them for]. Available at: http://www.novintex.ru/read/actions/usb_flash (accessed 28 September 2017).
[8] Snyatie zashchity ot zapisi s fleshki [Write deprotection of USB stick]. Available at: http://bsodstop.ru/kak-snyat-zashchitu-ot-zapisi-s-fleshki (accessed 28 September 2017).
[9] Usov A.I. Kontseptual’nye osnovy sudebnoy komp’yuterno–tekhnicheskoy ekspertizy. Dis. dok. yurid. nauk [Conceptual foundations of computer forensic examination. Dok. jur. sci. diss.]. Moscow, 2002, 402 p.
[10] Vekhov V.B. Application of computer technologies in criminalistics activity and criminal procedure. Vestnik Akademii Sledstvennogo komiteta Rossiyskoy Federatsii, 2014, no. 1, pp. 70–73.
[11] Kuchin O.S., ed. Elektronnye nositeli informatsii v kriminalistike [Electronic data storage devices in criminalistics]. Moscow, Yurlitinform publ., 2017, 304 p.
[12] RS-3000 flash. Available at: http://www.acelab.ru/dep.pc/pc3000.flash.php (accessed 17.08.2017).
[13] Encase Forensic. Available at: https://old.dialognauka.ru/products/encase_forensic/ (accessed 22.08.2017).