Recovering multiple versions of YAFFS2 files based on Hash and timestamps Online publication date: Wed, 01-Aug-2018
by Yameng Li; Jingsha He; Na Huang; Gongzheng Liu
International Journal of Embedded Systems (IJES), Vol. 10, No. 4, 2018
Abstract: With the popularity of digital devices, digital forensic research targeted at Android-based devices has drawn increasing attention. Among the many issues in digital forensics, data recovery has received a great deal of attention. In data recovery, deleted or updated data may contain important information about past activities of the user, making such information viable evidence as far as digital forensics is concerned. In this paper, according to special characteristics of YAFFS2, we propose a new method based on the notions of Hash and timestamp to recover multiple versions of YAFFS2 files during which the relationship between timestamps and file operations is analysed. To verify the effectiveness of our proposed method, we will simulate a NAND chip under Linux and perform some experiments to show that the proposed method is both effective and efficient in the recovery of multiple versions of different types of YAFFS2 files as well as Android images.
Online publication date: Wed, 01-Aug-2018
Go to Inderscience Online Journals to access the Full Text of this article.
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Embedded Systems (IJES):
Login with your Inderscience username and password:
Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.
If you still need assistance, please email email@example.com