![]() |
|||
English |
|||
| Computer Forensics | |||
Home > Importance of File System in Computer ForensicsAny computer that can be used should be installed with an operating system that acts as an interface between the user and the hardware. There is also a secondary storage device in every computer over which the operating system is installed. To store any data or information over the secondary storage device there should be some sort of structure that can be used to represent the data. This representation of the data over the secondary memory is called as the file system. The files system is important part in the collection of evidence. Different operating systems employ different file systems. The most popular operating system is Windows. The files system that is used in the Windows Operating system is FAT. FAT stands for File Allocation Table. Also FAT happens to be the most widely used file system as well. Other operating systems may have there own file systems. For example consider the file system in the Linux operating system. The file system of the Linux operating system is called as Extended file system. It is also possible that some operating system does provide support for the other file systems. Like in case of the Windows the Linux file system is not supported. The Windows operating system not at all is capable of listing the files and data that is stored over the partition with extended file system or Linux file system. Hence for such cases there are some software that can be used overcome this limitation. The example of one such software is Partition Magic. The task of the computer forensics specialist is to have complete knowledge of all the different types of file systems that can be used in a computer system. The file system NTFS is another such example of file system usually used on Windows NT. Usually each operating system has its own file system. The Solaris operating system uses the ZFS file system. The importance of the file system for a computer forensics expert is because of the details that need to be examined for the collection of the data or information as the evidence. The physical representation of a file over one file system differs from that of another. The details that need to be studied are hence file system dependent. A good practice for the computer forensics expert is to take the complete image of the storage device and then find out the relatively important evidence in the form of data from the copy. The advantage of this method is that the original data or information is intact and there is no possibility of losing the data while the investigative procedures are carried on. More over the file system corruption during the analysis can lead serious consequence. The process of recovery of data from a corrupted file system is itself a tedious job. The file system is vital as it is responsible for the storage of file permissions. The directory structure and the file structure representation plays vital role in forensics. Computer forensics professional should have the knowledge to utilize the tools effectively for the purpose of extracting the information from the encrypted files. The forensics tools that are available provide support for the easy usage of analyzing the files of different operating systems. |
Computer Refurbished Data Recovery USA Data Storage Data Backup and Recovery Hard Disk Damage |
||
| Log
File Recovery | Incident
Response System | Computer
Forensic Operating System Intrusion Detection System | Data Encryption | Computer Forensic Windows |
|||
| Data Recovery Software Download | dbx Repair | File Recovery Programs | Hard Disk Data Recovery | NTFS Recovery Photo Recovery Software | Recover Deleted Email | Recover mp3 | USB Data Recovery |
|||
| File Recovery | RAID Concept | Hard Disk Configuration | |||
| Copyright © 2006 ComputerForensics1. All Rights Reserved. www.computerforensics1.com | |||