File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method
File carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However,...
Główni autorzy: | , , |
---|---|
Format: | Artykuł |
Język: | English |
Wydane: |
Fakultas Ilmu Komputer UMI
2024-12-01
|
Seria: | Ilkom Jurnal Ilmiah |
Hasła przedmiotowe: | |
Dostęp online: | https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360 |
_version_ | 1826912247525408768 |
---|---|
author | Khoirul Anam Dahlan Anton Yudhana Herman Yuliansyah |
author_facet | Khoirul Anam Dahlan Anton Yudhana Herman Yuliansyah |
author_sort | Khoirul Anam Dahlan |
collection | DOAJ |
description | File carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However, recovering SSD devices have a lower probability success rate than HDD because the security system often hampers files recovered on SSD. Based on previous research, the success rate of Security Digital High Capacity (SDHC) only achieved 50% more than SSD, whereas SSD can only return 85.7% of its success. Forensics Digital is a part of Forensics Knowledge for deliver valid digital evidence for law investigation. This research aims to increase the success rate of recovery files using two different software: Foremost and Autopsy. The research uses a 512GB Eaget brand SSD with a New Technology File System (NTFS). The file carving is also conducted using the Association of Chief Police Officers (ACPO) method. APCO has several stages: Planning, Capture, Analysis, and Presentation. The experiment results show that Autopsy software with deep recover mode returned 81 out of 88 files (92%), whereas Foremost software run on Debian to make sure no virus on device that could damage computer especially windows system. First attempt recovery can only return 46 out of 88 files (52%). The findings show that the Autopsy software has a higher successful return rate and can be used for evidence in law enforcement and digital forensics investigations. |
first_indexed | 2025-02-17T10:26:24Z |
format | Article |
id | doaj.art-2912de9e8a414931b7d9734dba28b5b1 |
institution | Directory Open Access Journal |
issn | 2087-1716 2548-7779 |
language | English |
last_indexed | 2025-02-17T10:26:24Z |
publishDate | 2024-12-01 |
publisher | Fakultas Ilmu Komputer UMI |
record_format | Article |
series | Ilkom Jurnal Ilmiah |
spelling | doaj.art-2912de9e8a414931b7d9734dba28b5b12024-12-31T13:17:47ZengFakultas Ilmu Komputer UMIIlkom Jurnal Ilmiah2087-17162548-77792024-12-0116328329510.33096/ilkom.v16i3.2360.283-295701File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer MethodKhoirul Anam Dahlan0Anton Yudhana1Herman Yuliansyah2Universitas Ahmad DahlanUniversitas Ahmad DahlanUniversitas Ahmad DahlanFile carving is a method for recovering files using software such as Foremost and Autopsy. The recovery is conducted for deleted files or formatted devices. Popularity Solid State Drive (SSD) has outperformed Hard Disk Drive (HDD) because SSD is faster, more efficient, and shock resistant. However, recovering SSD devices have a lower probability success rate than HDD because the security system often hampers files recovered on SSD. Based on previous research, the success rate of Security Digital High Capacity (SDHC) only achieved 50% more than SSD, whereas SSD can only return 85.7% of its success. Forensics Digital is a part of Forensics Knowledge for deliver valid digital evidence for law investigation. This research aims to increase the success rate of recovery files using two different software: Foremost and Autopsy. The research uses a 512GB Eaget brand SSD with a New Technology File System (NTFS). The file carving is also conducted using the Association of Chief Police Officers (ACPO) method. APCO has several stages: Planning, Capture, Analysis, and Presentation. The experiment results show that Autopsy software with deep recover mode returned 81 out of 88 files (92%), whereas Foremost software run on Debian to make sure no virus on device that could damage computer especially windows system. First attempt recovery can only return 46 out of 88 files (52%). The findings show that the Autopsy software has a higher successful return rate and can be used for evidence in law enforcement and digital forensics investigations.https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360acpoautopsydigital forensicsforemostssd |
spellingShingle | Khoirul Anam Dahlan Anton Yudhana Herman Yuliansyah File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method Ilkom Jurnal Ilmiah acpo autopsy digital forensics foremost ssd |
title | File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method |
title_full | File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method |
title_fullStr | File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method |
title_full_unstemmed | File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method |
title_short | File carving Analyze of Foremost and Autopsy on external SSD mSATA using the Association of Chief Police Officer Method |
title_sort | file carving analyze of foremost and autopsy on external ssd msata using the association of chief police officer method |
topic | acpo autopsy digital forensics foremost ssd |
url | https://jurnal.fikom.umi.ac.id/index.php/ILKOM/article/view/2360 |
work_keys_str_mv | AT khoirulanamdahlan filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod AT antonyudhana filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod AT hermanyuliansyah filecarvinganalyzeofforemostandautopsyonexternalssdmsatausingtheassociationofchiefpoliceofficermethod |