A Phase of Deleted File Recovery for Digital Forensics Research in Tizen

Digital Forensics, not only for the computers of suspect, needs to collect the various digital evidences especially in many different kinds of mobile devices and operating systems. Moreover, in case of acquiring digital evidences, recovering a deleted file is more meaningful that it can find the concealed evidence by the suspect. In this paper, the phase of deleted file recovery in Tizen operating system is suggested and certified with the experiment.

[1]  Sangjin Lee,et al.  Forensic Analysis of Android Phone Using Ext4 File System Journal Log , 2012 .

[2]  Kevin D. Fairbanks An Analysis of Ext 4 for Digital Forensics , 2012 .

[3]  Wayne Jansen,et al.  Guidelines on Cell Phone Forensics , 2007 .

[4]  Chung-Huang Yang,et al.  Design and Implementation of Live SD Acquisition Tool in Android Smart Phone , 2011, 2011 Fifth International Conference on Genetic and Evolutionary Computing.

[5]  Wayne Jansen,et al.  Guidelines on Cell Phone Forensics | NIST , 2007 .

[6]  Ali Dehghantanha,et al.  An approach for forensic investigation in Firefox OS , 2014, 2014 Third International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec).

[7]  Fabio Massacci,et al.  Security in the Firefox OS and Tizen Mobile Platforms , 2014, Computer.

[8]  Patrick D. McDaniel,et al.  Understanding Android Security , 2009, IEEE Security & Privacy Magazine.

[9]  Kevin D. Fairbanks An analysis of Ext4 for digital forensics , 2012 .

[10]  Seokjun Lee,et al.  Improved deleted file recovery technique for Ext2/3 filesystem , 2014, The Journal of Supercomputing.

[11]  Ali Dehghantanha,et al.  Mobile forensic data acquisition in Firefox OS , 2014, 2014 Third International Conference on Cyber Security, Cyber Warfare and Digital Forensic (CyberSec).