Netinfo Security ›› 2016, Vol. 16 ›› Issue (5): 51-57.doi: 10.3969/j.issn.1671-1122.2016.05.008

• Orginal Article • Previous Articles     Next Articles

Research on Different Versions of YAFFS2 File Recovery Algorithm Based on Hash

Yameng LI(), Jingsha HE   

  1. School of Software Engineering, Beijing University of Technology, Beijing 100124, China
  • Received:2016-04-01 Online:2016-05-20 Published:2020-05-13

Abstract:

In digital forensic, the technology of Android forensic becomes hot spot of research currently. And there are some research interests such as data extraction, data recovery for Android forensic. Among these research interests, data recovery is one of the most important step. YAFFS2 is a new flash file system. It is designed for mobile devices which use NAND flash and is widely used in Android devices. Thus, this paper proposes a method that recover different versions of YAFFS2 file based on Hash. Through extracting and storing the same object header information into Hash linked list, it can recover different versions of file. The experiment is executed under Linux system with YAFFS2 file system environment. And the experiment results show that the method can recover different types of file especially SQLite3 file and recover different versions of different types of file effectively. And this method lays the foundation for the follow-up research of Android forensic.

Key words: digital forensics, file recovery, Android, YAFFS2, Hash

CLC Number: