Chat with us, powered by LiveChat File System Forensic Analysis Assignment – 3 1. You will need the "raidtab" files in the | Writedemy

File System Forensic Analysis Assignment – 3 1. You will need the “raidtab” files in the

File System Forensic Analysis Assignment – 3 1. You will need the “raidtab” files in the

Question

File System Forensic Analysis Assignment – 3
1. You will need the “raidtab” files in the archive on Blackboard to answer this question. Parse the given /etc/raidtab files and describe their RAID setup, partitions and configurations. Identify a couple of bootable “live” forensic Linux distributions and list which RAID controller drivers are supported in these distributions. Assuming you were setting up a SQL server or other relational database server, which RAID level would you choose? In particular, would RAID level 10 or Level 5 better suit your needs and why?
2. What is a cluster and why is a cluster, as opposed to a sector, currently being used as the smallest data unit for storing files on a hard disk. Let’s say we have a fictitious file system on a storage device with 512 byte sectors. This file system allocates 8 sectors per cluster. Therefore the size of a cluster is bytes. Suppose a file that is 5100 bytes long is saved on this device. There are bytes of slack which can be broken down into bytes of
RAM slack and
bytes of file slack or
sectors. In general, the
maximum size of RAM Slack is
bytes and the maximum size of file
slack, assuming a cluster size of 8 sectors, is therefore
sectors or
bytes. Using any tool of your choice, try hiding data in the slack space of a file on your file system, document your process. Estimate (roughly) the slack space on your Windows host machine. In short, I am asking you to estimate the storage space that is being wasted due to slack. (I am assuming that your virtual machines are shiny new and therefore may not have had much activity and consequently not much wasted slack space) and that your host machines are Windows based. If not, adapt the question to your setting.
3. Design a few experiments which authoritatively assert or refute these statements/questions.
1. Does file slack accompany a file when it is emailed?
2. Does file slack accompany a file when it is renamed?
3. Does file slack accompany a file when it is copied from your hard drive to your USB “flash” drive?
4. Does file slack accompany a file when it is copied to a different location on the same file system?
5. As you read in the book, earlier versions of Windows dumped random chunks of RAM content into a particular slack area of a file creating what we now call “RAM” Slack, albeit abusing the terminology a bit. Find out since which incarnation of Windows did this behavior change?
4. Most operating systems do not “wipe” the contents of a file’s data units when the file is being unallocated. Consequently, there exist some “secure delete” tools that accomplish this task for the user. It turns out that SDelete is a very popular secure delete tool on Windows. It is a part of the Windows SysInternals advanced Systems Utilities/Tool Suite by Mark Russinovich: http://technet.microsoft.com/en-us/sysinternals/bb897443.aspx. Use this tool to securely delete a file on your USB device. Interestingly enough, the manner in which SDelete operates, it leaves a characteristic “signature” on the disk. I’d like you to identify this characteristic which may prove that a suspect has in fact used SDelete or similar wiping tool. Many disk wiping utilities offer multiple-passes as they securely delete the contents of a drive. I would assume overwriting the contents of a drive with random data or zeroes merely once would suffice. This begs the question why are there multiple passes? How many wipes would suffice? Lastly, “delete” a file and use meta-data based analysis or application-based analysis to recover the file – use any tool to do this and explain how it accomplishes its task.

Our website has a team of professional writers who can help you write any of your homework. They will write your papers from scratch. We also have a team of editors just to make sure all papers are of HIGH QUALITY & PLAGIARISM FREE. To make an Order you only need to click Ask A Question and we will direct you to our Order Page at WriteDemy. Then fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.

Fill in all the assignment paper details that are required in the order form with the standard information being the page count, deadline, academic level and type of paper. It is advisable to have this information at hand so that you can quickly fill in the necessary information needed in the form for the essay writer to be immediately assigned to your writing project. Make payment for the custom essay order to enable us to assign a suitable writer to your order. Payments are made through Paypal on a secured billing page. Finally, sit back and relax.

Do you need an answer to this or any other questions?

About Writedemy

We are a professional paper writing website. If you have searched a question and bumped into our website just know you are in the right place to get help in your coursework. We offer HIGH QUALITY & PLAGIARISM FREE Papers.

How It Works

To make an Order you only need to click on “Order Now” and we will direct you to our Order Page. Fill Our Order Form with all your assignment instructions. Select your deadline and pay for your paper. You will get it few hours before your set deadline.

Are there Discounts?

All new clients are eligible for 20% off in their first Order. Our payment method is safe and secure.

Hire a tutor today CLICK HERE to make your first order