Ruwa F. Abu Hweidi, M. Jazzar, A. Eleyan, T. Bejaoui
{"title":"SATA M.2 on Forensics: Trim Function Effect on Recovering Permanently Deleted Files","authors":"Ruwa F. Abu Hweidi, M. Jazzar, A. Eleyan, T. Bejaoui","doi":"10.1109/SmartNets58706.2023.10215536","DOIUrl":null,"url":null,"abstract":"The spread of different types of SSD memory in a wide range of devices increases the challenge of cybercrime and forensic investigation. This is due to the features of the memory structure and how the data is recovered under such features. This research paper consists of an experiment to recover permanently deleted files in SATAM.2 SSD memory when- the Trim function is disabled and permitted with various forensic tools such as OSForensics, Autopsy, FTK and AXIOM. The experiment is applied to the NTFS file system under the Windows 11 environment. The research finds that 0% of files are recovered when the Trim function is enabled and 100% of files can be recovered if Trim function is disabled. This makes the recovery process difficult for investigators to find valid evidence. In future work, there is a need for a method that allows investigators to recover files in such conditions, and to apply more experiments to various features under different file system types and operating systems.","PeriodicalId":301834,"journal":{"name":"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)","volume":"85 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on Smart Applications, Communications and Networking (SmartNets)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SmartNets58706.2023.10215536","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The spread of different types of SSD memory in a wide range of devices increases the challenge of cybercrime and forensic investigation. This is due to the features of the memory structure and how the data is recovered under such features. This research paper consists of an experiment to recover permanently deleted files in SATAM.2 SSD memory when- the Trim function is disabled and permitted with various forensic tools such as OSForensics, Autopsy, FTK and AXIOM. The experiment is applied to the NTFS file system under the Windows 11 environment. The research finds that 0% of files are recovered when the Trim function is enabled and 100% of files can be recovered if Trim function is disabled. This makes the recovery process difficult for investigators to find valid evidence. In future work, there is a need for a method that allows investigators to recover files in such conditions, and to apply more experiments to various features under different file system types and operating systems.