An efficient technique for enhancing forensic capabilities of Ext2 file system

As electronic documents become more important and valuable in the modern era, attempts are invariably made to take undue-advantage by tampering with them. Tampering with the modification, access and creation date and time stamps (MAC DTS) of digital documents pose a great threat and proves to be a major handicap in digital forensic investigation. Authentic date and time stamps (ADTS) can provide crucial evidence in linking crime to criminal in cases of Computer Fraud and Cyber Crimes (CFCC) through reliable time lining of digital evidence. But the ease with which the MAC DTS of stored digital documents can be changed raises some serious questions about the integrity and admissibility of digital evidence, potentially leading to rejection of acquired digital evidence in the court of Law. MAC DTS procedures of popular operating systems are inherently flawed and were created only for the sake of convenience and not necessarily keeping in mind the security and digital forensic aspects. This paper explores these issues in the context of the Ext2 file system and also proposes one solution to tackle such issues for the scenario where systems have preinstalled plug-ins in the form of Loadable Kernel Modules, which provide the capability to preserve ADTS.

[1]  Michael C. Weil Dynamic Time & Date Stamp Analysis , 2002, Int. J. Digit. EVid..

[2]  C. Hosmer Time-lining computer evidence , 1998, 1998 IEEE Information Technology Conference, Information Environment for the Future (Cat. No.98EX228).

[3]  Pete Forster,et al.  Time and date issues in forensic computing - a case study , 2004, Digit. Investig..

[4]  Maurice J. Bach The Design of the UNIX Operating System , 1986 .

[5]  Christopher Ray Russell Analysis of a Secure Time Stamp Device , 2001 .

[6]  Daniel Pierre Bovet,et al.  Understanding the Linux Kernel , 2000 .

[7]  R. Card,et al.  Design and Implementation of the Second Extended Filesystem , 2001 .

[8]  Dan Farmer,et al.  Forensic Discovery , 2004 .

[9]  Chet Hosmer Proving the Integrity of Digital Evidence with Time , 2002, Int. J. Digit. EVid..