|

Study of USB drives in work of a computer forensic expert

Authors: Pavlova A.A.
Published in issue: #12(17)/2017
DOI: 10.18698/2541-8009-2017-12-215


Category: Informatics, Computer Engineering and Control | Chapter: Methods and Systems of Information Protection, Information Security

Keywords: USB drive, computer forensic examination, software, damaged devices, data recovery, data retrieval
Published: 29.11.2017

The article considers USB drives, in particular, internal components of the USB-device, as well as systems used at present within computer forensic examination in work with USB drives. The special attention is given to the hardware-software package PC-3000 flash, which allows for data recovery from damaged USB devices, and Encase Forensic software package, which is used to search, analyze and restore data from USB devices.


References

[1] Chugunkov V. Vybiraem fleshku. Osnovnye kharakteristiki USB-flesh-nakopiteley: chto takoe flesh-nakopitel’ [Select the flash drive. The main characteristics of USB flash drives: what is a flash drive]. Available at: http://www.compbegin.ru/articles/view/_116 (accessed 22.11.2017).

[2] What is a flash drive? Available at: https://www.lifewire.com/what-is-a-flash-drive-2625794 (accessed 10 September 2017).

[3] Printsip raboty i ustroystvo USB-fleshki [Operating principle and structure of the USB stick]. Available at: https://hobbyits.com/cifrovye-texnologii/princip-raboty-i-ustrojstvo-usb-fleshki.html (accessed 10 September 2017).

[4] V chem otlichiya USB-fleshek USB 3.0 ot USB 2.0 [What’s the difference between USB 3.0 and USB 2.0 memory sticks]. Available at: http://otnaspodarok.ru/v-chem-otlichiya-fleshek-usb-3-0-ot-usb-2-0/ (accessed 10 September 2017).

[5] Polezhaev P.N. “The Achilles heel” of USB-devices: attack and defense. Filosofskie problemy informatsionnykh tekhnologiy i kiberprostranstva [Philosophical problems of IT and Cyberspace], 2015, no. 1. Available at: http://cyberspace.pglu.ru/issues/detail.php?ELEMENT_ID=98191.

[6] Spiryaev O. Tekhnologii flesh-pamyati [USB-memory technologies]. Available at: https://www.bytemag.ru/articles/detail.php?ID=8660 (accessed 11 September 2017).

[7] USB-fleshki: chto eto i zachem oni nuzhny [USB stick: what is it and what do we need them for]. Available at: http://www.novintex.ru/read/actions/usb_flash (accessed 28 September 2017).

[8] Snyatie zashchity ot zapisi s fleshki [Write deprotection of USB stick]. Available at: http://bsodstop.ru/kak-snyat-zashchitu-ot-zapisi-s-fleshki (accessed 28 September 2017).

[9] Usov A.I. Kontseptual’nye osnovy sudebnoy komp’yuterno–tekhnicheskoy ekspertizy. Dis. dok. yurid. nauk [Conceptual foundations of computer forensic examination. Dok. jur. sci. diss.]. Moscow, 2002, 402 p.

[10] Vekhov V.B. Application of computer technologies in criminalistics activity and criminal procedure. Vestnik Akademii Sledstvennogo komiteta Rossiyskoy Federatsii, 2014, no. 1, pp. 70–73.

[11] Kuchin O.S., ed. Elektronnye nositeli informatsii v kriminalistike [Electronic data storage devices in criminalistics]. Moscow, Yurlitinform publ., 2017, 304 p.

[12] RS-3000 flash. Available at: http://www.acelab.ru/dep.pc/pc3000.flash.php (accessed 17.08.2017).

[13] Encase Forensic. Available at: https://old.dialognauka.ru/products/encase_forensic/ (accessed 22.08.2017).