Digital forensics is defined as a process and method for inquiring and proving, in a court of law, specific actions and factual grounds of occurrences through digital devices. The importance of digital forensics is becoming heightened as the personal and corporate digital devices, such as smartphones and tablet PC, have become more essential and critical as our daily usage of these devices are diversified in recent years. Crimes that abuse or target digital devices are increasing, and obtaining evidence through digital devices have increased significantly.
Among digital forensics area, recovering deleted data is playing an important role because it could discover key evidence stored within the digital devices. Moreover, in order to establish restored data as evidence, all process must observe due process, and data acquisition process must especially be carefully attended to. If due process is not observed during the data acquisition process, a solid evidence acquired in the process may not be admissible as a key evidence. Therefore, laws and institutional matters related to this topic has been actively studied, and there is a necessity for further research on technical areas.
Digital device relies on file system structure to store data on the storage. Among these file systems, Ext4 file system is a well-known file system typically used in a Linux distribution version, and are being used in many types of digital devices, from Android to raspberry pi. Therefore, the need for a study on analysis and restoration of deleted file for Ext4 file system is becoming more prominent in the modern digital society.
In this study, we proposed new digital forensic technique for Ext4 file system and analyzed a few considerations that are required from the legal and institutional perspective.