preview

Literature Review : Anti Forensics

Decent Essays

Literature Review Anti-forensics The purpose of anti-forensics is to intentionally make digital investigations and the examination of digital media more difficult through several means including data forgery, data hiding or data deletion. The techniques differ in what they do but the purpose is to make sure data is unrecoverable. (Lucia, 2013) Forensic tools There are many tools used to try and find data that has been removed from a disk but none of these tools are able to recover data from devices that have been sanitized. The reason for this is that the data contained in the file is overwritten thus making it unrecoverable. Tools such as encase (proprietary) and diskdigger(free) are able to recover files that have been deleted using the normal delete function with encase building up a complete image of the disk and contains much more information that can be used to see how many times anti-forensic tools were run (if installed) because of prefetch files. Diskdigger on the other hand just recovers files that have been deleted and allows them to be restored. There are many tools designed to securely erase data from a hard disk or just to remove a file. These tools include ccleaner, HDD erase and many more. These tools allow for either files to be delete individually by overwriting the space they take up or overwriting all the free space on the drive to remove any traces that files existed on the device. They overwrite the data and contain many different algorithms that offer

Get Access