Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Reassembling Linux-based Hybrid RAID

Authors
Choi, Jong-HyunPark, JungheumLee, Sangjin
Issue Date
May-2020
Publisher
WILEY
Keywords
RAID reassembly; hybrid RAID; Linux RAID; NAS forensics; RAID superblock; LVM
Citation
JOURNAL OF FORENSIC SCIENCES, v.65, no.3, pp.966 - 973
Indexed
SCIE
SCOPUS
Journal Title
JOURNAL OF FORENSIC SCIENCES
Volume
65
Number
3
Start Page
966
End Page
973
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/56100
DOI
10.1111/1556-4029.14258
ISSN
0022-1198
Abstract
Network-attached storage (NAS) is a system that uses a redundant array of disks (RAID) to create virtual disks comprising multiple disks and provide network services such as FTP, SSH, and WebDAV. Using these services, the NAS's virtual disks store data about individuals or groups, making them a critical analysis target for digital forensics. Well-known storage manufacturers like Seagate, Synology, and NETGEAR use Linux-based software RAID, and they usually support Berkeley RAID (e.g., RAID 0, 1, 5, 6, and 10) as well as self-developed hybrid RAID. Those manufacturers have published data on the introduction and features of hybrid RAID, but there is not enough information to reassemble RAID from a digital forensic perspective. Besides, digital forensic tools (such as EnCase, FTK, X-ways, and RAID Reconstructor) do not support automatic RAID reassembly for hybrid RAID, so research on hybrid RAID reassembly methods is necessary. This paper analyzes the disk array composed of hybrid RAID and explains the layout of disk array, partition layout in hybrid RAID, and hybrid RAID configuration strategy. Furthermore, it suggests parameters that are required for RAID reassembly and then propose a hybrid RAID reassembly procedure using them. Finally, we propose a proof-of-concept tool (Hybrid RAID Reconstructor) that identifies hybrid RAID from disk array and parse RAID parameters.
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher LEE, SANG JIN photo

LEE, SANG JIN
Department of Information Security
Read more

Altmetrics

Total Views & Downloads

BROWSE