File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method

File carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However,...

Szczegółowa specyfikacja

Opis bibliograficzny
Główni autorzy: Khoirul Anam Dahlan, Anton Yudhana, Herman Yuliansyah
Format: Artykuł
Język:English
Wydane: Fakultas Ilmu Komputer UMI 2024-12-01
Seria:Ilkom Jurnal Ilmiah
Hasła przedmiotowe:
Dostęp online:https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360
_version_ 1826912247525408768
author Khoirul Anam Dahlan
Anton Yudhana
Herman Yuliansyah
author_facet Khoirul Anam Dahlan
Anton Yudhana
Herman Yuliansyah
author_sort Khoirul Anam Dahlan
collection DOAJ
description File carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However, recovering SSD devices have a lower probability success rate than HDD because the security system often hampers files recovered on SSD. Based on previous research, the success rate of Security Digital High Capacity (SDHC) only achieved 50% more than SSD, whereas SSD can only return 85.7% of its success. Forensics Digital is a part of Forensics Knowledge for deliver valid digital evidence for law investigation. This research aims to increase the success rate of recovery files using two different software: Foremost and Autopsy. The research uses a 512GB Eaget brand SSD with a New Technology File System (NTFS). The file carving is also conducted using the Association of Chief Police Officers (ACPO) method. APCO has several stages: Planning, Capture, Analysis, and Presentation. The experiment results show that Autopsy software with deep recover mode returned 81 out of 88 files (92%), whereas Foremost software run on Debian to make sure no virus on device that could damage computer especially windows system. First attempt recovery can only return 46 out of 88 files (52%). The findings show that the Autopsy software has a higher successful return rate and can be used for evidence in law enforcement and digital forensics investigations.
first_indexed 2025-02-17T10:26:24Z
format Article
id doaj.art-2912de9e8a414931b7d9734dba28b5b1
institution Directory Open Access Journal
issn 2087-1716
2548-7779
language English
last_indexed 2025-02-17T10:26:24Z
publishDate 2024-12-01
publisher Fakultas Ilmu Komputer UMI
record_format Article
series Ilkom Jurnal Ilmiah
spelling doaj.art-2912de9e8a414931b7d9734dba28b5b12024-12-31T13:17:47ZengFakultas Ilmu Komputer UMIIlkom Jurnal Ilmiah2087-17162548-77792024-12-0116328329510.33096/ilkom.v16i3.2360.283-295701File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer MethodKhoirul Anam Dahlan0Anton Yudhana1Herman Yuliansyah2Universitas Ahmad DahlanUniversitas Ahmad DahlanUniversitas Ahmad DahlanFile carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However, recovering SSD devices have a lower probability success rate than HDD because the security system often hampers files recovered on SSD. Based on previous research, the success rate of Security Digital High Capacity (SDHC) only achieved 50% more than SSD, whereas SSD can only return 85.7% of its success. Forensics Digital is a part of Forensics Knowledge for deliver valid digital evidence for law investigation. This research aims to increase the success rate of recovery files using two different software: Foremost and Autopsy. The research uses a 512GB Eaget brand SSD with a New Technology File System (NTFS). The file carving is also conducted using the Association of Chief Police Officers (ACPO) method. APCO has several stages: Planning, Capture, Analysis, and Presentation. The experiment results show that Autopsy software with deep recover mode returned 81 out of 88 files (92%), whereas Foremost software run on Debian to make sure no virus on device that could damage computer especially windows system. First attempt recovery can only return 46 out of 88 files (52%). The findings show that the Autopsy software has a higher successful return rate and can be used for evidence in law enforcement and digital forensics investigations.https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360acpoautopsydigital forensicsforemostssd
spellingShingle Khoirul Anam Dahlan
Anton Yudhana
Herman Yuliansyah
File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
Ilkom Jurnal Ilmiah
acpo
autopsy
digital forensics
foremost
ssd
title File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
title_full File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
title_fullStr File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
title_full_unstemmed File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
title_short File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
title_sort file carving analyze of foremost and autopsy on external ssd msata using the association of chief police officer method
topic acpo
autopsy
digital forensics
foremost
ssd
url https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360
work_keys_str_mv AT khoirulanamdahlan filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod
AT antonyudhana filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod
AT hermanyuliansyah filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod