检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:徐国天[1]
机构地区:[1]中国刑警学院计算机犯罪侦查系,辽宁沈阳110854
出 处:《信息网络安全》2012年第3期63-65,共3页Netinfo Security
基 金:公安部应用创新计划项目[2011YYCXXJXY119]
摘 要:文章研究了基于日志文件的EXT3文件系统数据恢复方法,采用实例式研究方法,首先分析了EXT3文件系统中文件构成和文件被删除之后inode结点的变化;接下来研究了通过inode编号定位inode结点所在数据块的方法,以及通过日志恢复被删除文件的地址指针和文件名称的方法;最后介绍了通过地址指针和文件名将若干个地址空间中的数据合并成一个文件的方法。最终得出的结论是在日志文件和删除数据未被完全覆盖的情况下,可以通过日志有效恢复EXT3文件系统中被删除的文件。该研究成果可应用于公安机关的电子数据鉴定工作,也可作为公安院校的《电子物证检验》课程。The research of file recovery method on EXT3 file system was important for computer forensics. The recovery method on journal had been studied in detail. In this paper, specific examples were used to study. First, the composition of file was analyzed. After the file was deleted, The change of inode was analyzed. According to the inode number, the method to locate the data block was studied. The way to restore the name and address pointer of deleted file had been discussed in detail. The conclusion was investigators could effectively restore deleted files on EXT3 file system by journal. The research results could be applied in computer forensics and "electronic evidence examination" courses.
分 类 号:TP309.3[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.28