为解决计算机取汪的数据恢复问题,提出了一种基于新技术文件系统(New technology file system,NTFS)的数据恢复算法.该算法通过分析NTFS文件系统的结构,将待取证的数据分为3类,采取不同的策略进行处理:对于不可组织的数据依据其字节分布频率进行恢复和取证;对于尚可组织的数据依据NTFS文件系统中的相关记录进行数据恢复和取证.结果表明,该算法能重新组织被删除的数据,为计算机取证提供了一种解决途径.
In order to solve data recovery problems in computer forensics, this paper proposes a new algorithm based on NTFS. By analyzing the structure of NFTS, this algorithm classifies data into three varieties and handles them differently. Organized-impossible data is recovered and taken forensics by the distributing of the words. Organized-possible data is recovered and taken forensics by the references records of NTFS. Result shows that this algorithm could rebuild deleted data and make foundation for forensics.