Authors :
Zakariyya Hassan Abdullahi; Kabiru Bashir; Yunusa Ibrahim
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/55eub76x
Scribd :
https://tinyurl.com/3zmvdjc4
DOI :
https://doi.org/10.38124/ijisrt/26aug189
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Data software that encrypts information is being used by more and more people to protect data secrecy. The freely
downloadable and open-source programme known as VeraCrypt is one tool that supports data encryption. It can be difficult
for a digital forensic investigator to even find encrypted data. The paper explores the worst-case situation when a memory
seizure or access to the data in a decrypted state is not conceivable and the forensic detective only has access to the suspicious
computer's hard disc after the device has been off for a significant amount of time. It starts by assessing the effectiveness of
current statistical tests in distinguishing between encrypted VeraCrypt data and other non-encrypted data. By analysing
the raw byte data content of the suspicious hard disc, a forensic investigator could utilise a specific process model to locate
the encrypted data. The secret operating system and volume, however, continue to be invisible. The research paper comes
to the final conclusion that it is still difficult for forensic investigators to detect the concealed volume system only from an
investigation of the hard disc of the suspect machine.
Keywords :
Vera Crypt, Encryption, Forensic Investigation, Reverse Engineering.
References :
- D. Lillis, B. Becker, T. O’Sullivan, and M. Scanlon, “Current Challenges and Future Research Areas for Digital Forensic Investigation,” DFRWS 2016 USA - Proc. 16th Annu. USA Digit. Forensics Res. Conf. 11th ADFSL Conf. Digit. Forensics, Secur. Law (CDFSL 2016)At Daytona Beach, FL, USA., vol. 5, no. 2, 2016, [Online]. Available: http://arxiv.org/abs/1604.03850
- K. Conlan, I. Baggili, and F. Breitinger, “Anti-forensics: Furthering digital forensic science through a new extended, granular taxonomy,” DFRWS 2016 USA - Proc. 16th Annu. USA Digit. Forensics Res. Conf., vol. 18, no. December 2015, pp. S66–S75, 2016, doi: 10.1016/j.diin.2016.04.006.
- S. Raghavan, “Digital forensic research: current state of the art,” CSI Trans. ICT, vol. 1, no. 1, pp. 91–114, 2013, doi: 10.1007/s40012-012-0008-7.
- M. A. Ako, “Advanced Encryption Standard (AES) Algorithm to Encrypt and Decrypt Data,” Cryptogr. Netw. Secur., no. June, 2017, [Online]. Available: https://www.researchgate.net/publication/317615794
- G. G. Richard and V. Roussev, “Next-generation digital forensics,” Commun. ACM, vol. 49, no. 2, pp. 76–80, 2006, doi: 10.1145/1113034.1113074.
- D. Denning and W. Baugh, “Encryption and Evolving Technologies: Tools of Organized Crime and Terrorism,” Edpacs, vol. 25, no. 10, pp. 17–17, 1998, doi: 10.1201/1079/43232.25.10.19980401/30163.7.
- A. Davies, “Detecting hidden volumes and operating systems,” 2014.
- D. Nn. H. W. Jackson, an Advanced Introduction To Alloy. Springer International Publishing, 2018.
- A. Tomlinson, “TrueCrypt_Tests.” 2014.
- Werner Koch, “GNU Privacy Guard – Wikipedia.” p. Retrieved 27.April 2023. [Online]. Available: https://de.wikipedia.org/wiki/GNU_Privacy_Guard
- M. Bursać, R. Vulović, and M. Milosavljević, “Comparative Analysis of the Open Source Tools Intended for Data Encryption,” Int. Conf. Inf. Technol. Dev. Educ. Zrenjanin, Repub. Serbia, no. June, 2017.
- K. Saxena, D. Rajdev, D. Bhatia, and M. Bahl, “ProtonMail: Advance Encryption and Security,” Proc. - Int. Conf. Commun. Inf. Comput. Technol. ICCICT 2021, 2021, doi: 10.1109/ICCICT50803.2021.9510041.
- C. Tan, L. Zhang, and L. Bao, “A Deep Exploration of BitLocker Encryption and Security Analysis,” Int. Conf. Commun. Technol. Proceedings, ICCT, vol. 2020-Octob, pp. 1070–1074, 2020, doi: 10.1109/ICCT50939.2020.9295908.
- J. Lee, “Security Evaluation of Romulus,” Fraunhofer Inst. Secur. Inf. Technol. Andreas Poller Rheinstrasse 75, D-64295 Darmstadt, Ger. E-Mail, 2018.
- E. Casey, “Practical approaches to recovering encrypted digital evidence,” Proc. Digit. Forensic Res. Conf. DFRWS 2002 USA, vol. 1, no. 3, 2002.
- Henry B Wolfe, “Encountering Encrypted Evidence (potential),” Proc. 2002 InSITE Conf., no. June, 2002, doi: 10.28945/2590.
- H. Wolfe, “Penetrating encrypted evidence,” Digit. Investig., vol. 1, no. 2, pp. 102–105, 2004, doi: 10.1016/j.diin.2004.04.002.
- A. Van Deursen and E. Burd, “Software reverse engineering,” J. Syst. Softw., vol. 77, no. 3, pp. 209–211, 2005, doi: 10.1016/j.jss.2004.03.031.
- Y. Huang, T. Y. Zhuo, Q. Xu, H. Hu, X. Yuan, and C. Chen, “Training-free Lexical Backdoor Attacks on Language Models,” 2023, doi: 10.1145/3543507.3583348.
- V. Cambareri, M. Mangia, F. Pareschi, R. Rovatti, and G. Setti, “On Known-Plaintext Attacks to a Compressed Sensing-Based Encryption: A Quantitative Analysis,” IEEE Trans. Inf. Forensics Secur., vol. 10, no. 10, pp. 2182–2195, 2015, doi: 10.1109/TIFS.2015.2450676.
- N. Zaidenberg and A. Resh, “Timing and side channel attacks,” Intell. Syst. Control Autom. Sci. Eng., vol. 78, no. May, pp. 183–194, 2015, doi: 10.1007/978-3-319-18302-2_11.
- H. Bojinov, D. Sanchez, P. Reber, D. Boneh, and P. Lincoln, “Neuroscience meets cryptography,” Commun. ACM, vol. 57, no. 5, pp. 110–118, 2014, doi: 10.1145/2594445.
- S. Yadav, K. Ahmad, and J. Shekhar, “Analysis of digital forensic tools and investigation process,” Commun. Comput. Inf. Sci., vol. 169 CCIS, pp. 435–441, 2011, doi: 10.1007/978-3-642-22577-2_59.
- Q. X. Miao, “Research and analysis on Encryption Principle of TrueCrypt software system,” 2nd Int. Conf. Inf. Sci. Eng. ICISE2010 - Proc., pp. 1409–1412, 2010, doi: 10.1109/ICISE.2010.5691392.
- E. Casey, G. Fellows, M. Geiger, and G. Stellatos, “The growing impact of full disk encryption on digital forensics,” Digit. Investig., vol. 8, no. 2, pp. 129–134, 2011, doi: 10.1016/j.diin.2011.09.005.
- S. E, R. C. Davis, and B. A. Jackson, “Digital Evidence and the US Criminal justice system,” Crimanal justices J., vol. 5, 2019.
- S. Rekhis and N. Boudriga, “A system for formal digital forensic investigation aware of anti-forensic attacks,” in IEEE Transactions on Information Forensics and Security, 2012, vol. 7, no. 2, pp. 635–650. doi: 10.1109/TIFS.2011.2176117.
- A. Balducci, S. Devlin, and T. Ritter, “Open Crypto Audit Project TrueCrypt Cryptographic Review Cryptography Services Final Report,” Cryptogr. Netw. Secur., vol. 5, 2015.
- I. P. R. L. Tvrdík, “Analysis of the Rescue File of BestCrypt Volume Encryption,” 2017.
- C. Meijer and B. Van Gastel, “Advisory on Solid State Disks ( SSDs ) / Digital Security , Radboud University / 5-11-2018 Research results,” pp. 1–2, 2018.
- Z. H. Abdullahi and S. K. Singh, “A Conceptual and Technical Perspective of Reverse Engineering In Digital forensic,” in 2nd International Conference on Recent Development in Engineering ,Sciences, and Management Goverment Engineering College Bharatpur, Rjasthan, 2023, no. April. [Online]. Available: ISBN; 978-9391535-43-8
- H. Payal and R. Tomer, “Review on reverse engineering,” J. Crit. Rev., vol. 7, no. 7, pp. 1408–1412, 2020, doi: 10.31838/jcr.07.07.255.
- A. Czeskis, D. J. St Hilaire, K. Koscher, S. D. Gribble, T. Kohno, and B. Schneier, “Defeating encrypted and deniable file systems: TrueCrypt v5.1a and the case of the tattling OS and applications,” in HotSec 2008 - 3rd USENIX Workshop on Hot Topics in Security, 2008, pp. 1–7.
- H. A. Miiller, J. H. Jahnke, D. B. Smith, M. A. Storey, S. R. Tilley, and K. Wong, “Reverse engineering: A roadmap,” Proc. Conf. Futur. Softw. Eng. ICSE 2000, pp. 47–60, 2000, doi: 10.1145/336512.336526.
- J. Leng and T. Li, “Research on Computer System Information Hiding Anti-Forensic Technology,” vol. 83, no. Snce, pp. 55–60, 2018.
- A. Balducci, S. Devlin, and T. Ritter, “Open Crypto Audit Project - TrueCrypt Cryptographic Review,” iSECpartners, no. Security Assesment, 2015.
- A. Tomlinson and R. Holloway, “Detecting the use of TrueCrypt Forensic investigations : Detecting evidence of the use of TrueCrypt,” R. Hollow. Inf. Secur. Thesis Ser. | Detect. use TrueCrypt Forensic, 2018.
- L. Zhang, Y. Zhou, and J. Fan, “The forensic analysis of encrypted Truecrypt volumes,” PIC 2014 - Proc. 2014 IEEE Int. Conf. Prog. Informatics Comput., pp. 405–409, 2014, doi: 10.1109/PIC.2014.6972366.
- C. T. Lijun Zhang, Xiaoyan Deng, “An Extensive Analysis of truecrypt Encryption Forensics,” pp. 1–6, 2019, doi: 10.1145/3331453.3361328.
- H. Agarwal, F. Husain, and P. Saini, Advances in Computing and Data Sciences, vol. 1046, no. July. Springer Singapore, 2019. doi: 10.1007/978-981-13-9942-8.
- R. Wartell, Y. Zhou, K. W. Hamlen, M. Kantarcioglu, and B. Thuraisingham, “Differentiating code from data in x86 binaries,” Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics), vol. 6913 LNAI, no. PART 3, pp. 522–536, 2011, doi: 10.1007/978-3-642-23808-6_34.
- E. Stroulia and T. Systä, “Dynamic analysis for reverse engineering and program understanding,” ACM SIGAPP Appl. Comput. Rev., vol. 10, no. 1, pp. 8–17, 2002, doi: 10.1145/568235.568237.
- N. Chen, B. Chen, and W. Shi, “MobiWear: A Plausibly Deniable Encryption System for Wearable Mobile Devices,” Springer, pp. 138–154, 2021, doi: 10.1007/978-3-030-80851-8_10.
- E. C. Hosgor, “Detection and Mitigation of,” Computer (Long. Beach. Calif)., no. December 2020, pp. 1–8, 2020, doi: 10.5281/zenodo.4425257.
- S. G. Lewis and T. Palumbo, “BitLocker Full-Disk Encryption,” 2018. doi: 10.1145/3235715.3241363.
- R. Stoykova, R. Nordvik, M. Ahmed, K. Franke, S. Axelsson, and F. Toolan, “Legal and technical questions of file system reverse engineering,” Comput. Law Secur. Rev., vol. 46, 2022, doi: 10.1016/j.clsr.2022.105725.
- E. Casey, G. Fellows, M. Geiger, and G. Stellatos, “The growing impact of full disk encryption on digital forensics,” Digit. Investig., vol. 8, no. 2, pp. 129–134, 2011, doi: 10.1016/j.diin.2011.09.005.
- Et. al., Pravin Soni, “Performance Analysis of Cascaded Hybrid Symmetric Encryption Models,” Turkish J. Comput. Math. Educ., vol. 12, no. 2, pp. 1699–1708, 2021, doi: 10.17762/turcomat.v12i2.1506.
- Benjamin Wah, “Encyclopedia of Computer Science and Engineering,” Wiley Encycl. Comput. Sci. Eng., vol. 1–170, 2008.
- S. Arif and M. M. Kumar, “Cyber Safety Analysis Using Reverse Engineering Syed,” Int. J. Res. Publ. Rev. J. homepage www.ijrpr.com ISSN 2582-7421 Cyber, vol. 4, no. 1, pp. 399–403, 2023.
Data software that encrypts information is being used by more and more people to protect data secrecy. The freely
downloadable and open-source programme known as VeraCrypt is one tool that supports data encryption. It can be difficult
for a digital forensic investigator to even find encrypted data. The paper explores the worst-case situation when a memory
seizure or access to the data in a decrypted state is not conceivable and the forensic detective only has access to the suspicious
computer's hard disc after the device has been off for a significant amount of time. It starts by assessing the effectiveness of
current statistical tests in distinguishing between encrypted VeraCrypt data and other non-encrypted data. By analysing
the raw byte data content of the suspicious hard disc, a forensic investigator could utilise a specific process model to locate
the encrypted data. The secret operating system and volume, however, continue to be invisible. The research paper comes
to the final conclusion that it is still difficult for forensic investigators to detect the concealed volume system only from an
investigation of the hard disc of the suspect machine.
Keywords :
Vera Crypt, Encryption, Forensic Investigation, Reverse Engineering.