Evaluation of file carving tools for forensic investigation in docker containers

dc.contributor.authorHaribabu, K.
dc.date.accessioned2025-05-07T10:16:13Z
dc.date.available2025-05-07T10:16:13Z
dc.date.issued2023-01
dc.description.abstractContainer Technology has attracted a lot of attention and is increasingly utilized to deploy the industrial applications. Containers are executable units of software which encapsulate the code along with the libraries and other dependencies in order to facilitate the code to run anywhere. They take advantage of operating system virtualization and can run anything from a small microservice or software process to a larger application. Containers are very lightweight as compared to Virtual Machines. They offer high portability with very less overhead. This emerging field of container technology has attracted a lot of attention from the community of researchers. In this paper, we have performed digital forensics on the Docker containers using file carving techniques in order to test whether the lost data from the deleted containers can be retrieved or not. For this purpose, we have used three popular file carving tools and compared their performance. The results of the experiments show that the file carving is an effective way to recover the lost data from the deleted containers.en_US
dc.identifier.urihttps://ieeexplore.ieee.org/document/9997954
dc.identifier.urihttp://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/18862
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.subjectComputer Scienceen_US
dc.subjectContainersen_US
dc.subjectDockeren_US
dc.subjectVirtualizationen_US
dc.subjectFile carvingen_US
dc.titleEvaluation of file carving tools for forensic investigation in docker containersen_US
dc.typeArticleen_US

Files