A Study of Acquisition and Analysis on the Bios Firmware Image File in the Digital Forensics


KIPS Transactions on Computer and Communication Systems, Vol. 5, No. 12, pp. 491-498, Dec. 2016
10.3745/KTCCS.2016.5.12.491,   PDF Download:
Keywords: digital forensic, BIOS Firmware Image, BIOS Boot Sequence
Abstract

Recently leakages of confidential information and internal date have been steadily increasing by using booting technique on portable OS such as Windows PE stored in portable storage devices (USB or CD/DVD etc). This method allows to bypass security software such as USB security or media control solution installed in the target PC, to extract data or insert malicious code by mounting the PC’s storage devices after booting up the portable OS. Also this booting method doesn’t record a log file such as traces of removable storage devices. Thus it is difficult to identify whether the data are leaked and use trace-back technique. In this paper is to propose method to help facilitate the process of digital forensic investigation or audit of a company by collecting and analyzing BIOS firmware images that record data relating to BIOS settings in flash memory and finding traces of portable storage devices that can be regarded as abnormal events.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from September 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
S. H. Jeong, Y. H. Lee, S. J. Lee, "A Study of Acquisition and Analysis on the Bios Firmware Image File in the Digital Forensics," KIPS Transactions on Computer and Communication Systems, vol. 5, no. 12, pp. 491-498, 2016. DOI: 10.3745/KTCCS.2016.5.12.491.

[ACM Style]
Seung Hoon Jeong, Yun Ho Lee, and Sang Jin Lee. 2016. A Study of Acquisition and Analysis on the Bios Firmware Image File in the Digital Forensics. KIPS Transactions on Computer and Communication Systems, 5, 12, (2016), 491-498. DOI: 10.3745/KTCCS.2016.5.12.491.