信息安全研究 ›› 2016, Vol. 2 ›› Issue (4): 307-316.

• 电子数据取证专题 • 上一篇    下一篇

从取证角度解读MacOS系统Time Machine 备份数据

郭永健   

  1. 北京天宇宁达科技有限公司技术部
  • 收稿日期:2016-04-14 出版日期:2016-04-15 发布日期:2016-04-14
  • 通讯作者: 郭永健
  • 作者简介:本科,高级工程师,主要研究方向为电子数据取证、MacOS取证分析、电子数据司法鉴定. sprite@cflab.cn

Time Machine Forensic

  • Received:2016-04-14 Online:2016-04-15 Published:2016-04-14

摘要: Time Machine是MacOS系统中的一个自动数据备份工具.Mac用户可以通过USB接口移动硬盘、火线接口移动硬盘、雷电接口移动硬盘、Time Capsule等设备对自己的程序和数据进行不断的备份.特别是在调查和案件中,调查人员应该对采用WiFi无线网络进行数据备份的Time Capsule硬盘、网络硬盘重点关注.一个Time Machine备份硬盘能够保存多个用户的备份数据,也可以保存几十台计算机的备份数据,更可能从备份数据中找到用户在Mac 系统中已经删除或擦除的数据,因此案件中能够识别并发现Time Machine备份硬盘,并进一步成功解析备份数据,有可能是案件侦破的突破口.重点针对Time Machine备份方法、存储格式,以及对Time Machine备份数据的解析方法进行探讨.

关键词: MacOS系统, Time Machine备份软件, Time Capsule备份设备, 取证, 备份

Abstract: Time Machine is an automatic data backup tool in Mac OS. Mac users can backup their important programs and data continuously with different kinds of removable disk, such as USB removable hard disk, Firewire hard disk, Thunderbolt hard disk, Time Capsule. Especially in investigations and cases, it is important for investigators to find out if there are any backup storages in a WiFi network. A single Time Machine storage can save multiple users backup data, or even several Mac computers backup data. The normal deleted data in a Mac can even be foundrecovered from Time Machine backup. The important breakthrough may be from a Time Capsule, and the analytical result of Time Machine backup. This article will discuss Time Machine, backup storage, folder structure, and how to make forensics analysis manually and automatically.

Key words: MacOS, Time Machine, Time Capsule, forensic, backup