⚠ Official Notice: www.ijisrt.com is the official website of the International Journal of Innovative Science and Research Technology (IJISRT) Journal for research paper submission and publication. Please beware of fake or duplicate websites using the IJISRT name.



Examining VeraCrypt Security: Finding Hidden Volumes Using Reverser Engineering Techniques


Authors : Zakariyya Hassan Abdullahi; Kabiru Bashir; Yunusa Ibrahim

Volume/Issue : Volume 11 - 2026, Issue 8 - August


Google Scholar : https://tinyurl.com/55eub76x

Scribd : https://tinyurl.com/3zmvdjc4

DOI : https://doi.org/10.38124/ijisrt/26aug189

Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.


Abstract : Data software that encrypts information is being used by more and more people to protect data secrecy. The freely downloadable and open-source programme known as VeraCrypt is one tool that supports data encryption. It can be difficult for a digital forensic investigator to even find encrypted data. The paper explores the worst-case situation when a memory seizure or access to the data in a decrypted state is not conceivable and the forensic detective only has access to the suspicious computer's hard disc after the device has been off for a significant amount of time. It starts by assessing the effectiveness of current statistical tests in distinguishing between encrypted VeraCrypt data and other non-encrypted data. By analysing the raw byte data content of the suspicious hard disc, a forensic investigator could utilise a specific process model to locate the encrypted data. The secret operating system and volume, however, continue to be invisible. The research paper comes to the final conclusion that it is still difficult for forensic investigators to detect the concealed volume system only from an investigation of the hard disc of the suspect machine.

Keywords : Vera Crypt, Encryption, Forensic Investigation, Reverse Engineering.

References :

  1. D. Lillis, B. Becker, T. O’Sullivan, and M. Scanlon, “Current Challenges and Future Research Areas for Digital Forensic Investigation,” DFRWS 2016 USA - Proc. 16th Annu. USA Digit. Forensics Res. Conf. 11th ADFSL Conf. Digit. Forensics, Secur. Law (CDFSL 2016)At Daytona Beach, FL, USA., vol. 5, no. 2, 2016, [Online]. Available: http://arxiv.org/abs/1604.03850
  2. K. Conlan, I. Baggili, and F. Breitinger, “Anti-forensics: Furthering digital forensic science through a new extended, granular taxonomy,” DFRWS 2016 USA - Proc. 16th Annu. USA Digit. Forensics Res. Conf., vol. 18, no. December 2015, pp. S66–S75, 2016, doi: 10.1016/j.diin.2016.04.006.
  3. S. Raghavan, “Digital forensic research: current state of the art,” CSI Trans. ICT, vol. 1, no. 1, pp. 91–114, 2013, doi: 10.1007/s40012-012-0008-7.
  4. M. A. Ako, “Advanced Encryption Standard (AES) Algorithm to Encrypt and Decrypt Data,” Cryptogr. Netw. Secur., no. June, 2017, [Online]. Available: https://www.researchgate.net/publication/317615794
  5. G. G. Richard and V. Roussev, “Next-generation digital forensics,” Commun. ACM, vol. 49, no. 2, pp. 76–80, 2006, doi: 10.1145/1113034.1113074.
  6. D. Denning and W. Baugh, “Encryption and Evolving Technologies: Tools of Organized Crime and Terrorism,” Edpacs, vol. 25, no. 10, pp. 17–17, 1998, doi: 10.1201/1079/43232.25.10.19980401/30163.7.
  7. A. Davies, “Detecting hidden volumes and operating systems,” 2014.
  8. D. Nn. H. W. Jackson, an Advanced Introduction To Alloy. Springer International Publishing, 2018.
  9. A. Tomlinson, “TrueCrypt_Tests.” 2014.
  10. Werner Koch, “GNU Privacy Guard – Wikipedia.” p. Retrieved 27.April 2023. [Online]. Available: https://de.wikipedia.org/wiki/GNU_Privacy_Guard
  11. M. Bursać, R. Vulović, and M. Milosavljević, “Comparative Analysis of the Open Source Tools Intended for Data Encryption,” Int. Conf. Inf. Technol. Dev. Educ. Zrenjanin, Repub. Serbia, no. June, 2017.
  12. K. Saxena, D. Rajdev, D. Bhatia, and M. Bahl, “ProtonMail: Advance Encryption and Security,” Proc. - Int. Conf. Commun. Inf. Comput. Technol. ICCICT 2021, 2021, doi: 10.1109/ICCICT50803.2021.9510041.
  13. C. Tan, L. Zhang, and L. Bao, “A Deep Exploration of BitLocker Encryption and Security Analysis,” Int. Conf. Commun. Technol. Proceedings, ICCT, vol. 2020-Octob, pp. 1070–1074, 2020, doi: 10.1109/ICCT50939.2020.9295908.
  14. J. Lee, “Security Evaluation of Romulus,” Fraunhofer Inst. Secur. Inf. Technol. Andreas Poller Rheinstrasse 75, D-64295 Darmstadt, Ger. E-Mail, 2018.
  15. E. Casey, “Practical approaches to recovering encrypted digital evidence,” Proc. Digit. Forensic Res. Conf. DFRWS 2002 USA, vol. 1, no. 3, 2002.
  16. Henry B Wolfe, “Encountering Encrypted Evidence (potential),” Proc. 2002 InSITE Conf., no. June, 2002, doi: 10.28945/2590.
  17. H. Wolfe, “Penetrating encrypted evidence,” Digit. Investig., vol. 1, no. 2, pp. 102–105, 2004, doi: 10.1016/j.diin.2004.04.002.
  18. A. Van Deursen and E. Burd, “Software reverse engineering,” J. Syst. Softw., vol. 77, no. 3, pp. 209–211, 2005, doi: 10.1016/j.jss.2004.03.031.
  19. Y. Huang, T. Y. Zhuo, Q. Xu, H. Hu, X. Yuan, and C. Chen, “Training-free Lexical Backdoor Attacks on Language Models,” 2023, doi: 10.1145/3543507.3583348.
  20. V. Cambareri, M. Mangia, F. Pareschi, R. Rovatti, and G. Setti, “On Known-Plaintext Attacks to a Compressed Sensing-Based Encryption: A Quantitative Analysis,” IEEE Trans. Inf. Forensics Secur., vol. 10, no. 10, pp. 2182–2195, 2015, doi: 10.1109/TIFS.2015.2450676.
  21. N. Zaidenberg and A. Resh, “Timing and side channel attacks,” Intell. Syst. Control Autom. Sci. Eng., vol. 78, no. May, pp. 183–194, 2015, doi: 10.1007/978-3-319-18302-2_11.
  22. H. Bojinov, D. Sanchez, P. Reber, D. Boneh, and P. Lincoln, “Neuroscience meets cryptography,” Commun. ACM, vol. 57, no. 5, pp. 110–118, 2014, doi: 10.1145/2594445.
  23. S. Yadav, K. Ahmad, and J. Shekhar, “Analysis of digital forensic tools and investigation process,” Commun. Comput. Inf. Sci., vol. 169 CCIS, pp. 435–441, 2011, doi: 10.1007/978-3-642-22577-2_59.
  24. Q. X. Miao, “Research and analysis on Encryption Principle of TrueCrypt software system,” 2nd Int. Conf. Inf. Sci. Eng. ICISE2010 - Proc., pp. 1409–1412, 2010, doi: 10.1109/ICISE.2010.5691392.
  25. E. Casey, G. Fellows, M. Geiger, and G. Stellatos, “The growing impact of full disk encryption on digital forensics,” Digit. Investig., vol. 8, no. 2, pp. 129–134, 2011, doi: 10.1016/j.diin.2011.09.005.
  26. S. E, R. C. Davis, and B. A. Jackson, “Digital Evidence and the US Criminal justice system,” Crimanal justices J., vol. 5, 2019.
  27. S. Rekhis and N. Boudriga, “A system for formal digital forensic investigation aware of anti-forensic attacks,” in IEEE Transactions on Information Forensics and Security, 2012, vol. 7, no. 2, pp. 635–650. doi: 10.1109/TIFS.2011.2176117.
  28. A. Balducci, S. Devlin, and T. Ritter, “Open Crypto Audit Project TrueCrypt Cryptographic Review Cryptography Services Final Report,” Cryptogr. Netw. Secur., vol. 5, 2015.
  29. I. P. R. L. Tvrdík, “Analysis of the Rescue File of BestCrypt Volume Encryption,” 2017.
  30. C. Meijer and B. Van Gastel, “Advisory on Solid State Disks ( SSDs ) / Digital Security , Radboud University / 5-11-2018 Research results,” pp. 1–2, 2018.
  31. Z. H. Abdullahi and S. K. Singh, “A Conceptual and Technical Perspective of Reverse Engineering In Digital forensic,” in 2nd International Conference on Recent Development in Engineering ,Sciences, and Management Goverment Engineering College Bharatpur, Rjasthan, 2023, no. April. [Online]. Available: ISBN; 978-9391535-43-8
  32. H. Payal and R. Tomer, “Review on reverse engineering,” J. Crit. Rev., vol. 7, no. 7, pp. 1408–1412, 2020, doi: 10.31838/jcr.07.07.255.
  33. A. Czeskis, D. J. St Hilaire, K. Koscher, S. D. Gribble, T. Kohno, and B. Schneier, “Defeating encrypted and deniable file systems: TrueCrypt v5.1a and the case of the tattling OS and applications,” in HotSec 2008 - 3rd USENIX Workshop on Hot Topics in Security, 2008, pp. 1–7.
  34. H. A. Miiller, J. H. Jahnke, D. B. Smith, M. A. Storey, S. R. Tilley, and K. Wong, “Reverse engineering: A roadmap,” Proc. Conf. Futur. Softw. Eng. ICSE 2000, pp. 47–60, 2000, doi: 10.1145/336512.336526.
  35. J. Leng and T. Li, “Research on Computer System Information Hiding Anti-Forensic Technology,” vol. 83, no. Snce, pp. 55–60, 2018.
  36. A. Balducci, S. Devlin, and T. Ritter, “Open Crypto Audit Project - TrueCrypt Cryptographic Review,” iSECpartners, no. Security Assesment, 2015.
  37. A. Tomlinson and R. Holloway, “Detecting the use of TrueCrypt Forensic investigations : Detecting evidence of the use of TrueCrypt,” R. Hollow. Inf. Secur. Thesis Ser. | Detect. use TrueCrypt Forensic, 2018.
  38. L. Zhang, Y. Zhou, and J. Fan, “The forensic analysis of encrypted Truecrypt volumes,” PIC 2014 - Proc. 2014 IEEE Int. Conf. Prog. Informatics Comput., pp. 405–409, 2014, doi: 10.1109/PIC.2014.6972366.
  39. C. T. Lijun Zhang, Xiaoyan Deng, “An Extensive Analysis of truecrypt Encryption Forensics,” pp. 1–6, 2019, doi: 10.1145/3331453.3361328.
  40. H. Agarwal, F. Husain, and P. Saini, Advances in Computing and Data Sciences, vol. 1046, no. July. Springer Singapore, 2019. doi: 10.1007/978-981-13-9942-8.
  41. R. Wartell, Y. Zhou, K. W. Hamlen, M. Kantarcioglu, and B. Thuraisingham, “Differentiating code from data in x86 binaries,” Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics), vol. 6913 LNAI, no. PART 3, pp. 522–536, 2011, doi: 10.1007/978-3-642-23808-6_34.
  42. E. Stroulia and T. Systä, “Dynamic analysis for reverse engineering and program understanding,” ACM SIGAPP Appl. Comput. Rev., vol. 10, no. 1, pp. 8–17, 2002, doi: 10.1145/568235.568237.
  43. N. Chen, B. Chen, and W. Shi, “MobiWear: A Plausibly Deniable Encryption System for Wearable Mobile Devices,” Springer, pp. 138–154, 2021, doi: 10.1007/978-3-030-80851-8_10.
  44. E. C. Hosgor, “Detection and Mitigation of,” Computer (Long. Beach. Calif)., no. December 2020, pp. 1–8, 2020, doi: 10.5281/zenodo.4425257.
  45. S. G. Lewis and T. Palumbo, “BitLocker Full-Disk Encryption,” 2018. doi: 10.1145/3235715.3241363.
  46. R. Stoykova, R. Nordvik, M. Ahmed, K. Franke, S. Axelsson, and F. Toolan, “Legal and technical questions of file system reverse engineering,” Comput. Law Secur. Rev., vol. 46, 2022, doi: 10.1016/j.clsr.2022.105725.
  47. E. Casey, G. Fellows, M. Geiger, and G. Stellatos, “The growing impact of full disk encryption on digital forensics,” Digit. Investig., vol. 8, no. 2, pp. 129–134, 2011, doi: 10.1016/j.diin.2011.09.005.
  48. Et. al., Pravin Soni, “Performance Analysis of Cascaded Hybrid Symmetric Encryption Models,” Turkish J. Comput. Math. Educ., vol. 12, no. 2, pp. 1699–1708, 2021, doi: 10.17762/turcomat.v12i2.1506.
  49. Benjamin Wah, “Encyclopedia of Computer Science and Engineering,” Wiley Encycl. Comput. Sci. Eng., vol. 1–170, 2008.
  50. S. Arif and M. M. Kumar, “Cyber Safety Analysis Using Reverse Engineering Syed,” Int. J. Res. Publ. Rev. J. homepage www.ijrpr.com ISSN 2582-7421 Cyber, vol. 4, no. 1, pp. 399–403, 2023.

Data software that encrypts information is being used by more and more people to protect data secrecy. The freely downloadable and open-source programme known as VeraCrypt is one tool that supports data encryption. It can be difficult for a digital forensic investigator to even find encrypted data. The paper explores the worst-case situation when a memory seizure or access to the data in a decrypted state is not conceivable and the forensic detective only has access to the suspicious computer's hard disc after the device has been off for a significant amount of time. It starts by assessing the effectiveness of current statistical tests in distinguishing between encrypted VeraCrypt data and other non-encrypted data. By analysing the raw byte data content of the suspicious hard disc, a forensic investigator could utilise a specific process model to locate the encrypted data. The secret operating system and volume, however, continue to be invisible. The research paper comes to the final conclusion that it is still difficult for forensic investigators to detect the concealed volume system only from an investigation of the hard disc of the suspect machine.

Keywords : Vera Crypt, Encryption, Forensic Investigation, Reverse Engineering.

Paper Submission Last Date
31 - August - 2026

SUBMIT YOUR PAPER CALL FOR PAPERS
Video Explanation for Published paper

Never miss an update from Papermashup

Get notified about the latest tutorials and downloads.

Subscribe by Email

Get alerts directly into your inbox after each post and stay updated.
Subscribe
OR

Subscribe by RSS

Add our RSS to your feedreader to get regular updates from us.
Subscribe