Premium Partner

Bruce Nikkel 1_4_storage_media.pdf

Bruce Nikkel 1_4_storage_media.pdf

Bruce Nikkel 1_4_storage_media.pdf


Set of flashcards Details

Flashcards 10
Language English
Category Computer Science
Level University
Created / Updated 20.06.2019 / 02.07.2021
Licencing Not defined
Weblink
https://card2brain.ch/box/20190620_bruce_nikkel_14storagemedia_pdf
Embed
<iframe src="https://card2brain.ch/box/20190620_bruce_nikkel_14storagemedia_pdf/embed" width="780" height="150" scrolling="no" frameborder="0"></iframe>

What are some types of modern storage?

  • Magnetic tape (cartridge)
  • Magnetic disks (hard drives)
  • Non-Volatile Memory (Flash, SSD, USB sticks)
  • Optical discs (CD, DVD, Blue-ray)

Name some modern drive interfaces.

  • SATA - Serial ATA
  • SAS - Serial Attached SCSI
  • NVME - Non-Volatile Memory Express

Name some common drive interface protocols

 

  • ATA Command Set (ACS) - uses registers
  • ATAPI commands - packet interface via ATA
  • SCSI commands - client/server (initiator/target)
  • USB BOT - Bulk Only Transport
  • USB UASP - USB Attached SCSI

Name some common interface standards.

  • OS can have a stadard device driver for all devices
  • SATA - AHCI
  • USB - xHCI
  • NVME - NVME(NVMEHCI)

What can you tell me about the sector sizes of magnetic disk drives?

Sector sizes:

  • Typical drives appear to have 512 Byte sectors ("512e")
  • There is an "Advanced Format" agreement by drive manufacturers
  • 512 byte sectors are just emulated, modern drives 4096 byte sectors
  • "4Kn" are drives with native sectors

On a magnetic disk drive what is relevant to forensics?

  • "deleted" data on the platters
  • HPA - Host Protected Area
  • DCO - Disk Configuration Overlay
  • drive service area
  • ATA security (set of security featurs)

What are the chalanges with non-volatile memory (flash drives)?

  • FTL - Flash Translation Layer
  • over-provisioned blocks
  • "chip-off"
  • TRIM commands
  • NVME and SATA Express are not the same.

What are non standard ways to access a drive?

  • JTAG access to the drive electronics
  • TTL/serial access to drive electronics
  • Securtiy exploits to get access