Generic RAID reassembly using block-level entropy
Autor: | Christian Zoubek, Sabine Seufert, Andreas Dewald |
---|---|
Rok vydání: | 2016 |
Předmět: |
Computer science
RAID Distributed computing Entropy Disk mirroring 02 engineering and technology computer.software_genre Disk Data Format law.invention law 020204 information systems 0202 electrical engineering electronic engineering information engineering Data_FILES Standard RAID levels Hardware_MEMORYSTRUCTURES Digital forensics Disk array controller 020206 networking & telecommunications Parity drive Degraded mode Computer Science Applications Medical Laboratory Technology Operating system Tool Non-standard RAID levels computer Law Data recovery |
Zdroj: | Digital Investigation. 16:S44-S54 |
ISSN: | 1742-2876 |
DOI: | 10.1016/j.diin.2016.01.007 |
Popis: | RAIDs (Redundant Array of Independent Disks) are widely used in storage systems to prevent data loss in case of hardware defects on a hard disk and to improve I/O performance. In case the RAID controller fails or in the context of a forensic investigation, the content of the RAID has to be reconstructed from the single disks or rather from disk images. Due to the variety of RAID controllers and various implementation and configuration possibilities, different parameters that are necessary for reconstruction are often unknown. This might be the case because the original configuration just has not been documented or in the forensic case, the administrator might not be cooperating and not willing to reveal the configuration. Using the original RAID system in such cases is not an option, too, because the original evidence should not be altered. We present a novel approach to automatically detect all parameters to reassemble the logical RAID volume based on block level entropy measurement and generic heuristics. We also provide a performance-optimized open source implementation of our approach that is also able to afterwards reassemble the entire logical RAID volume and to further recover single missing disks using the redundancy information as present in RAID-5. |
Databáze: | OpenAIRE |
Externí odkaz: |