Related Experiment Video
Updated: Oct 5, 2025

Standardized Method for Measuring Collection Efficiency from Wipe-sampling of Trace Explosives
Published on: April 10, 2017
Digital forensic investigation methodology for Storage Space: Based on the NIST digital forensic process
Junho Kim1, Sangjin Lee1, Doowon Jeong2
1School of Cybersecurity, Korea University, Seoul, South Korea.
Abstract:
For forensic examiners, investigating the RAID systems of servers has been challenging, as the examiners must reconstruct multiple high-capacity disks to identify digital evidence. Software-based RAID systems' use has been released for personal use, so examiners should consider RAID systems even when they investigate personal computers. Although there is a high probability that the software-based RAID will become a target of crime, there has been little research into digital forensic methodology for software-based RAID, as exemplified by Storage Space. In this paper, we introduce details about the structure of Storage Space found through reverse engineering. Storage Space was analyzed by applying the digital forensic process of NIST. We explain how to reconstruct a virtual disk configured using Storage Space and develop an automated tool to do so. To evaluate our study and the tool developed, we created an experimental scenario and describe in detail the forensic procedure and technical methods for the analysis of Storage Space. Our research can be used as the basis of forensic investigations for Storage Space.
More Related Videos
07:57Quantitative Detection of Trace Explosive Vapors by Programmed Temperature Desorption Gas Chromatography-Electron Capture Detector
Published on: July 25, 2014
05:31Gas Chromatography-Mass Spectrometry Paired with Total Vaporization Solid-Phase Microextraction as a Forensic Tool
Published on: May 25, 2021
Related Concept Videos
Archival Research
Storage
Guidelines and Strategies for Safe Computer Charting
Maintain Confidentiality and Security: