Logo des Repositoriums
 

A kernel driver modification to visualize and reconstruct data transfer between computer and USB mass storage devices

dc.contributor.authorZöllner, Joshua
dc.contributor.authorPetschke, Dmitry
dc.contributor.authorSchinner, Alexander
dc.contributor.authorWeber, Kristin
dc.contributor.authorMayer, Manuel
dc.date.accessioned2021-12-14T10:57:45Z
dc.date.available2021-12-14T10:57:45Z
dc.date.issued2021
dc.description.abstractThe aim of this work is to create a completely new method for analysing the physical access to USB mass storage devices and to reconstruct the file access from the logged data. This is achieved by replacing a real USB stick with a full software simulation based on a Raspberry PI Zero using USB gadget mode. To achieve full information, we extended the logging capabilities of the Linux kernel driver. This allows to log position and size of each reading operation at the lowest possible level. For write operation, the written data is logged, too. This enables logging completely independent of the operating system or file system and allows a forensic image to be calculated that has time as an additional dimension. Further advantages of this method are that it is completely undetectable from the host computer and random accesses bypassing a file system can also be logged. A reconstruction of the original file access is shown and the possibilities for new attack vectors are discussed.en
dc.identifier.doi10.18420/informatik2021-073
dc.identifier.isbn978-3-88579-708-1
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/37741
dc.language.isoen
dc.publisherGesellschaft für Informatik, Bonn
dc.relation.ispartofINFORMATIK 2021
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-314
dc.subjectDigital forensics
dc.subjectData Transfer
dc.subjectFile System Analysis
dc.subjectProtocol Reverse Engineering
dc.subjectForensic Image
dc.subjectUSB Software-Defined Mass Storage Device
dc.titleA kernel driver modification to visualize and reconstruct data transfer between computer and USB mass storage devicesen
gi.citation.endPage865
gi.citation.startPage857
gi.conference.date27. September - 1. Oktober 2021
gi.conference.locationBerlin
gi.conference.sessiontitleWorkshop: International Workshop on Digital Forensics (WDF)

Dateien

Originalbündel
1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
I1-3.pdf
Größe:
3.16 MB
Format:
Adobe Portable Document Format