Browse > Article
http://dx.doi.org/10.13089/JKIISC.2015.25.5.1143

A recovery method for deleted records in the ESE Database  

Kim, Jeong-hyeon (Center for Information Security Technologies, Korea University)
Choi, Jong-hyun (Center for Information Security Technologies, Korea University)
Lee, Sang-jin (Center for Information Security Technologies, Korea University)
Abstract
Extensible Storage Engine (ESE) database is a database developed by Microsoft. This database is used in web browser like Internet Explorer, Spartan and in Windows system with Windows Search, System Resource Usage Monitor. Previous ESE database viewer can display an incorrect result and can't read the file depending on collected environment and status of files. And the deleted record recovery tool is limited to some program and cannot recover all tables. This paper suggests the universal recovery method for deleted records and presents the experimental results through development of tool.
Keywords
ESE database analysis; ESE database format; ESE database forensic;
Citations & Related Records
연도 인용수 순위
  • Reference
1 J. Douglas, "Forensic artefacts present in microsoft windows desktop search," Master's Thesis, Cranfield University, 2009
2 Mircosoft, "Extensible Storage Engine," https://technet.microsoft.com/library/Cc961824
3 J. Metz, "Extensible Storage Engine (ESE) Database File (EDB) format specification," https://github.com/libyal/libesedb/tree/master/documentation
4 woanware, "EseDbViewer v1.0.6," http://www.woanware.co.uk/forensics/esedbviewer.html
5 NirSoft, "ESEDatabaseView v1.30," http://www.nirsoft.net/utils/ese_database_view.html
6 H. Chivers and C. Hargreaves, "Forensic data recovery from the windows search database," Digital Investigation, vol. 7, no. 3-4, pp. 114-126, Apr. 2011.   DOI
7 H. Chivers, "Private browsing: A window of forensic opportunity," Digital Investigation, vol. 11, no. 1, pp. 20-29, Mar. 2014.   DOI
8 JM. Gordon, "A forensic examination of windows desktop search (version 3)," Master's Thesis, Cranfield University, 2009