Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Forensic signature for tracking storage devices: Analysis of UEFI firmware image, disk signature and windows artifacts

Full metadata record
DC Field Value Language
dc.contributor.authorJeong, Doowon-
dc.contributor.authorLee, Sangjin-
dc.date.accessioned2021-09-01T14:01:03Z-
dc.date.available2021-09-01T14:01:03Z-
dc.date.created2021-06-19-
dc.date.issued2019-06-
dc.identifier.issn1742-2876-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/64865-
dc.description.abstractTracking storage devices is one of the important fields in digital forensics. The existing methods and tools about registry, event log or IconCache analysis help solving cases on confidential leakage, illegal copying, and security incident cases. However, previous approach has drawback in tracking storage devices such as HDD, SSD, and etc since it was based on the good performance of USB device tracking. Another drawback in previous approach is that it is vulnerable to anti-forensics because the artifacts are dependent on the operating system. This paper introduces a new definition of forensic signature for tracking various storage devices and reviews the known artifacts. Furthermore, this study introduces unidentified artifact stored in UEFI firmware image and independent of operating system. Moreover, this paper develops a methodology for tracking storage devices using forensic signature according to the storage type. (C) 2019 Elsevier Ltd. All rights reserved.-
dc.languageEnglish-
dc.language.isoen-
dc.publisherELSEVIER SCI LTD-
dc.titleForensic signature for tracking storage devices: Analysis of UEFI firmware image, disk signature and windows artifacts-
dc.typeArticle-
dc.contributor.affiliatedAuthorLee, Sangjin-
dc.identifier.doi10.1016/j.diin.2019.02.004-
dc.identifier.scopusid2-s2.0-85062462970-
dc.identifier.wosid000469921600003-
dc.identifier.bibliographicCitationDIGITAL INVESTIGATION, v.29, pp.21 - 27-
dc.relation.isPartOfDIGITAL INVESTIGATION-
dc.citation.titleDIGITAL INVESTIGATION-
dc.citation.volume29-
dc.citation.startPage21-
dc.citation.endPage27-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.relation.journalWebOfScienceCategoryComputer Science, Interdisciplinary Applications-
dc.subject.keywordAuthorDisk forensics-
dc.subject.keywordAuthorFirmware image analysis-
dc.subject.keywordAuthorUEFI-
dc.subject.keywordAuthorDisk serial number-
dc.subject.keywordAuthorDigital investigation-
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher LEE, SANG JIN photo

LEE, SANG JIN
정보보호학과
Read more

Altmetrics

Total Views & Downloads

BROWSE