Researchers use disk frag to hide data
Data is hidden in plain sight as fragmented pieces
Computerworld - Researchers have released a paper detailing a way to conceal data from the prying eyes of law enforcement officials by exploiting disk fragmentation on a clustered file system, thereby hiding it in plain sight.
The researchers, from the University of Southern California and the National University of Science and Technology (NUST) in Islamabad, Pakistan, stated that encryption is ineffective as a means of hiding data from law enforcement officials who undertake a forensic investigation of a computer system.
That is "mainly because the presence of encrypted data on a disk can be easily detected and disk owners can subsequently be forced (by law or other means) to release decryption keys," the researchers wrote in a summary of their paper.
The paper, "Designing a Cluster-based Covert Channel to Evade Disk Investigation and Forensics," details how information can be hidden in the arrangement of the clusters of a file, which causes deliberate fragmentation -- "a phenomenon that is not unusual to find on heavily-used file systems," according to the report.
In order to keep data from being detected during a forensic investigation, the researchers propose storing sensitive information on a covert channel as 24-bit fragments on half-empty drives on a clustered file system, allowing the user to plausibly deny any knowledge of the existence of the data.
The data-hiding algorithm is created using FAT32-formatted disk drives and exploiting the way operating systems group consecutive sectors on a disk. Those sectors create the clusters that store the content.
"This approach works well until there are no consecutive unallocated clusters available. In that case, the contents of the file are scattered or fragmented across the file system," the research paper states.
The researchers also presented statistics about the incidence of file fragmentation on actual file systems from 52 disk drives belonging to a diverse set of users. Based on the statistics, they presented guidelines for selecting good cover files.
"Finally, we show that even if an investigator gets suspicious, he/she will [have difficulty uncovering a] hidden message," they wrote.
Lucas Mearian covers storage, disaster recovery and business continuity, financial services infrastructure and health care IT for Computerworld. Follow Lucas on Twitter at
@lucasmearian or subscribe to Lucas's RSS feed
. His email address is lmearian@computerworld.com.
Read more about Storage in Computerworld's Storage Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- ESG: Defining Tier One Storage in the Modern Data Center
- This report defines "tier-1" storage in the modern IT world and in the data centers and services that support it. What was a...
- ESG: Using HP's Converged Storage to Develop/Enhance Business Resiliency in VMware Environments
- In this report, Enterprise Strategy Group reviews how HP's portfolio of hardware, software, and services can provide the foundational support for VMware environments....
- HP 3PAR Storage Systems Designed for Mission Critical High Availability
- In this technical whitepaper, learn how HP 3PAR Storage Systems have been designed to deliver 99.999% and greater availability, bringing new possibilities to...
- HP X5000 G2 Network Storage System Data Sheet
- The new HP X5000 G2 Network Storage Systems is ideal for midsize companies. The solution is a two-node Network Attached Storage (NAS) cluster...
- Windows Storage Server 2008 R2 Architecture and Deployment Guide
- Adding additional file-based storage to your Microsoft Windows environment is easier than ever with the new HP X5000 G2 Network Storage Systems, powered... All Storage White Papers
- Understand Your Data: The Future of Backup and Archiving
- Archiving and Backup are the foundation of the next generation of information governance. However, commodity data protection tools and basic archives are only...
- The Higher-Bandwidth, Lower-Cost Connection of Choice: 10GBASE-T LAN on Motherboard
- Learn how Expedient, a cloud provider, is using 10 Gigabit Ethernet to boost its services and rein in costs.
- Banish Poor Application Performance
- End User Experience, 30-Min Webinar
Wed. March 21st ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Virtualization KnowledgeVault
- Virtualization initiatives are underway at most small and midsize businesses, but some unexpected challenges have prevented many organizations from achieving original goals. This...
- Mobility KnowledgeVault
- How "mobile ready" is your infrastructure? This Mobility Knowledge Vault provides a wide variety of expert advice on how to strike a balance... All Storage Webcasts