Assessing Trace Evidence Left by Secure Deletion Programs

  • Paul Burke
  • Philip Craiger
Conference paper
Part of the IFIP Advances in Information and Communication book series (IFIPAICT, volume 222)

Abstract

Secure deletion programs purport to permanently erase files from digital media. These programs are used by businesses and individuals to remove sensitive information from media, and by criminals to remove evidence of the tools or fruits of illegal activities. This paper focuses on the trace evidence left by secure deletion programs. In particular, five Windows-based secure deletion programs are tested to determine if they leave identifiable signatures after deleting a file. The results show that the majority of the programs leave identifiable signatures. Moreover, some of the programs do not completely erase file metadata, which enables forensic investigators to extract the name, size, creation date and deletion date of the “deleted” files.

Keywords

Secure deletion trace evidence Windows XP FAT12 file system 

References

  1. [1]
    Defense Security Service, National Industrial Security Program Operating Manual (NISPOM), DoD 5220.22-M, U.S. Department of Defense (www.dss.mil/isec/nispom_0195.pdf), 1995.Google Scholar
  2. [2]
    M. Geiger and L. Cranor, Counter-Forensic Privacy Tools: A Forensic Evaluation, Technical Report CMU-ISRI-05-119, Institute for Software Research International, School of Computer Science, Carnegie Mellon University, Pittsburgh, Pennsylvania (reports-archive.adm.cs.cmu.edu/anon/isri2005/CMU-ISRI-05-119.pdf), 2005.Google Scholar
  3. [3]
    P. Guttman, Secure deletion of data from magnetic and solid-state memory, Proceedings of the Sixth USENIX Security Symposium (www.cs.auckland.ac.nz/~pgut001/pubs/secure_del.html), 1996.Google Scholar
  4. [4] Microsoft Corporation, FAT32 File System Specification (www.microsoft.com/whdc/system/platform/firmware/fatgen.mspx), 2000.Google Scholar

Copyright information

© IFIP Internatonal Federation for Information Processing 2006

Authors and Affiliations

  • Paul Burke
    • 1
  • Philip Craiger
    • 1
    • 2
  1. 1.National Center for Forensic ScienceUniversity of Central FloridaOrlandoUSA
  2. 2.University of Central FloridaOrlandoUSA

Personalised recommendations