SlideShare a Scribd company logo
1 of 27
Download to read offline
DriveSavers Data Recovery
Title:

ESI Recovery from Solid State Technology
New Challenges for eDiscovery




Presented by:
Chris Bross
Senior Enterprise Recovery Engineer
Survey

 How many of you own a Solid State Device?
        y y
   Smart Phone, Camera, Tablet, Ultrabook?
NAND flash
Who is DriveSavers?

 Corporate Profile
    Pioneered th d t recovery i d t 27 years ago
    Pi       d the data          industry
    Global leader in secure data recovery services

 Who We Serve
    eDiscovery and L
     Di           d Law fifirms, fi
                                 financial organizations, F t
                                       i l      i ti      Fortune 500 companies,
                                                                            i
    healthcare institutions, government agencies, universities and consumers
    Compliance and security dependent clients

 Capabilities
    Fastest, most reliable, and most secure provider
    All storage devices — All OS supported
    Forensic imaging, eDiscovery and Data Sanitization
Data Recovery & Imaging Defined

 Software
   User and professional tools available
   Ineffective with hardware failure

 Professional Data Recovery Service
   Reverse engineering laboratory and clean rooms
   Resolve hardware and more complicated failures
                                p

 Forensic Imaging
   Data as evidence
   Acquisition, analysis and reporting process
The Data Storage Market

 Hard Disk Drive
    History and market dominance
    Current and projected growth

 Solid State Drives
    Growth in Ultrabooks, MacBooks, premium laptops
    In the Enterprise and in the Cloud
                p

 Smart Devices
    2007 birth of the iPhone
    Explosive global growth
Solid State Storage Defined
Solid State Storage Defined

 Data Storage on (
           g     (NVM) Non-Volatile Memory
                     )                   y
    Semiconductor chip based cellular data storage

 NAND flash Technology
    Most common NVM today
    Costs decreasing, capacity increasing
    Scalability, density and reliability challenges
              y        y               y        g

 Advantages over traditional hard disk drives
    No mechanical points of failure
    Performance, reliability, power efficiency, security
Reliability of Solid State Devices

 Reliability Expectations
           y p
    No mechanical failures, no moving parts
    Higher MTBF and lower AFR

 Reality in the Data Recovery Lab
    Failure does occur, volume increasing with installed base
    Recovery can be more challenging than with HDD
           y                    g g

 Storage Industry & Technology Evolving
    Each generation more reliable
    Intel as an example
Why Data Recovery from SSD?

 Physical & Environmental Issues
   y
    Impact or physical trauma to device
    Environmental or liquid exposure

 Device Failure
    Electro-logical failure
    Controller/firmware or NAND flash

 User Fault or Malicious Attack
    Data deletion, accidental format
    Encryption issues
The Issue: Imaging of ESI from SSD

 Hard Disk Drive (HDD)
                 (   )
   Data stored magnetically on platters
   Long data retention, proven imaging methods

 Solid State Drive (SSD)
   Data stored electronically in cells, within pages, on chips
   Shorter data retention, more imaging challenges
                                   g g         g

 Data Lost Due to Self Maintenance of SSD
   Routines like TRIM and garbage collection can
   result in automatic destruction of data
The Story: Mat Honan @ Wired




Photo: Ariel Zambelich/Wired. Illustration: Ross Patton/Wired
Data in Cloud and Solid State
The Challenges in this Case

 Secure Remote Wipe via iCloud hack of 3 Devices
                 p
   Physical layer overwrite of all data
   All storage devices were solid state, no magnetic HDD

 iOS Devices Not Recoverable
   Remote secure wipe was completed
   Apple iOS and hardware encryption complication
    pp                        yp        p

 MacBook Air w SSD Successful Recovery
   “Perfect Storm” of events
   Complications of image and recovery process
   due to SSD self maintenance
Challenges in Forensic Imaging
Challenges in Forensic Imaging

 Proprietary Technologies From OEM
    p      y         g
   Highly protected trade secrets may prevent data access
   Rapid competitive technology advances

 Encryption
   Default built in to SSD hardware controller
   Corporate software encryption deployments
      p                   yp       p y

 TRIM & Garbage Collection
   Self maintenance and performance routines
   Detrimental to recovery and forensic imaging
Encryption

 In Software
   Common in large corporate or government deployments
   No imaging issues if keys/credentials are provided
   Physical failure can produce partial corrupt image

 In Hardware
   Controller or firmware failure can prevent imaging
                                      p          g g
   Encryption key unknown to user
   Firmware reload can trigger key regeneration
   Linked via TPM to software encryption
TRIM

 TRIM defined
   Operating system command to remove data at device level

 TRIM support
   Must be enabled in hardware and supported in software
   Current Windows, MacOS and Linux full implementation

 Operation and R
 O    ti     d Results
                   lt
   Runs immediately upon empty of recycle bin
   Resets (programs) cells to 1 (erased)
   Data is unrecoverable
Garbage Collection

 Background Garbage Collection (
     g           g             (BGC) defined
                                   )
   Automatic controller function for maintenance

 BGC support
   All current SSDs support in hardware
   OS independent operation

 Operation and R
 O    ti     d Results
                   lt
   Runs indeterminately and quickly in the background
   Defragments and optimizes saved data
   Resets (programs) cells to 1 (erased)
   Prior data is unrecoverable
Process in the Recovery Lab
Process in the Recovery Lab

 Capture & Acquire Image ASAP
   p         q        g
   Source is a moving target that may degrade/purge data
   Disabling BGC impossible without help from OEM
   Using a write-blocker DOES NOT stop these processes
           write blocker

 Image Access Via Controller & Data Interface
   Ideal to work with device intact and functional
   Imperative for encrypting devices

 NAND Chip Extraction and Imaging
   Only on non-encrypting devices
   Complicated reverse engineering of write algorithm
Advantages at DriveSavers Lab

 Engineering and Experience
   g       g       p
    Hundreds of thousands of cases completed
    Specialized SSD and NAND engineers

 Strategic Industry Alliances
    Trusted exchange of field failure analysis
    Development of OEM specific tools
          p             p

 R&D
    Non-stop commitment to new tools and tech
    Acting as “thought leaders” for the industry
Forensic and eDiscovery Services

 Data Collection

 Data Processing

 Data Export
        p

 Data Review and Hosting

 Expert Witness Testimony

 Litigation Management

 Data Analytics
Best Practices To Follow

 Understand the Differences of HDD vs SSD Imaging
                                             g g
    First chance may be only chance
    Understand the limitations of the technology

 Litigation Hold Letters
    Consider specific instructions for SSD ESI requests
    Require immediate imaging of devices
      q                  g g

 If Unable to Image SSD
    STOP, power off and engage a professional lab
    ESI will potentially degrade with any attempts
Looking Forward

 Greater Market Adoption of Solid State Storage
                   p                         g
    Everything mobile, corporate and enterprise

 Solid State now in the Cloud!
    SandForce/LSI example

 New Technologies = New Challenges
    More security, encryption & “secret sauce”
    Compression, de-duplication, FTL
    Sanitization of SSD

 Imaging and Recovery Challenges Continue
DriveSavers Data Recovery
Q&A
DriveSavers Data Recovery
Thank You!

Chris Bross
Senior Enterprise Recovery Engineer
chris.bross@drivesavers.com
chris bross@drivesavers com

More Related Content

Viewers also liked (17)

Philippines 2013
Philippines 2013 Philippines 2013
Philippines 2013
 
Diversity moment philippines-9
Diversity moment   philippines-9Diversity moment   philippines-9
Diversity moment philippines-9
 
Online policy primer
Online policy primerOnline policy primer
Online policy primer
 
Ppt enseñanza aprendizaje
Ppt enseñanza aprendizajePpt enseñanza aprendizaje
Ppt enseñanza aprendizaje
 
Psm Cv Presentation Aug 16, 2012
Psm Cv Presentation Aug 16, 2012Psm Cv Presentation Aug 16, 2012
Psm Cv Presentation Aug 16, 2012
 
Slide show trivia
Slide show triviaSlide show trivia
Slide show trivia
 
Wellington Public Transport Presentation 23Aug2012
Wellington Public Transport Presentation 23Aug2012Wellington Public Transport Presentation 23Aug2012
Wellington Public Transport Presentation 23Aug2012
 
Adjetivos descriptivos
Adjetivos descriptivos Adjetivos descriptivos
Adjetivos descriptivos
 
Workshop
WorkshopWorkshop
Workshop
 
2014 java functional
2014 java functional2014 java functional
2014 java functional
 
Philippine diversity 2013
Philippine diversity 2013 Philippine diversity 2013
Philippine diversity 2013
 
Diversity in Philippines
Diversity in PhilippinesDiversity in Philippines
Diversity in Philippines
 
Psm Cv Presentation 3 2012
Psm Cv Presentation 3  2012Psm Cv Presentation 3  2012
Psm Cv Presentation 3 2012
 
Portada uniminuto apa
Portada uniminuto apaPortada uniminuto apa
Portada uniminuto apa
 
Correo
CorreoCorreo
Correo
 
Inventar de autoevaluare a aptitudinii de comunicare a părintelui cu adolesce...
Inventar de autoevaluare a aptitudinii de comunicare a părintelui cu adolesce...Inventar de autoevaluare a aptitudinii de comunicare a părintelui cu adolesce...
Inventar de autoevaluare a aptitudinii de comunicare a părintelui cu adolesce...
 
Ранжирование «коммерческих» вопросов
Ранжирование «коммерческих» вопросовРанжирование «коммерческих» вопросов
Ранжирование «коммерческих» вопросов
 

Similar to ESI Recovery from Solid State Technology

Webinar: Cleaning up the SDS Mess - Four Keys to Success
Webinar: Cleaning up the SDS Mess - Four Keys to SuccessWebinar: Cleaning up the SDS Mess - Four Keys to Success
Webinar: Cleaning up the SDS Mess - Four Keys to SuccessStorage Switzerland
 
Physical media damage is data recoverable from my hard drive
Physical media damage  is data recoverable from my hard drivePhysical media damage  is data recoverable from my hard drive
Physical media damage is data recoverable from my hard driveTaking IT Mobile Data Solutions
 
Data Protection Fde Solution Presentation
Data Protection Fde Solution PresentationData Protection Fde Solution Presentation
Data Protection Fde Solution Presentationjuniortstanley
 
Murli Thirumale, CEO Ocarina Networks
Murli Thirumale, CEO Ocarina NetworksMurli Thirumale, CEO Ocarina Networks
Murli Thirumale, CEO Ocarina NetworksEntrepreneurTrek
 
Are your ready for in memory applications?
Are your ready for in memory applications?Are your ready for in memory applications?
Are your ready for in memory applications?G2MCommunications
 
Big data introduction
Big data introductionBig data introduction
Big data introductionChirag Ahuja
 
Are Your PCs and Laptops Recovery and Discovery Ready?
Are Your PCs and Laptops Recovery and Discovery Ready?Are Your PCs and Laptops Recovery and Discovery Ready?
Are Your PCs and Laptops Recovery and Discovery Ready?Iron Mountain
 
Webinar: How to Design Primary Storage for GDPR
Webinar: How to Design Primary Storage for GDPRWebinar: How to Design Primary Storage for GDPR
Webinar: How to Design Primary Storage for GDPRStorage Switzerland
 
Flash Stories: How Customers Make Smarter Decisions Faster
Flash Stories: How Customers Make Smarter Decisions FasterFlash Stories: How Customers Make Smarter Decisions Faster
Flash Stories: How Customers Make Smarter Decisions FasterWestern Digital
 
Power Point example for module 3 assignment
Power Point example for module 3 assignmentPower Point example for module 3 assignment
Power Point example for module 3 assignmentnaterator
 
Peerless DRM and Enterprise Security-Enabled Removable Data Storage Cartridges
Peerless DRM and Enterprise Security-Enabled Removable Data Storage CartridgesPeerless DRM and Enterprise Security-Enabled Removable Data Storage Cartridges
Peerless DRM and Enterprise Security-Enabled Removable Data Storage CartridgesFred_C_Thomas
 
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?Webinar: What's Best for VDI, Hybrid or All-Flash Storage?
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?Storage Switzerland
 
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signage
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signageSilicon Motion's PCIe FerriSSD : High speed and reliability for digital signage
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signageSilicon Motion
 
Academic Workflows with iRODS FINAL
Academic Workflows with iRODS FINALAcademic Workflows with iRODS FINAL
Academic Workflows with iRODS FINALRandy Splinter
 
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...Transforming Backup and Recovery in VMware environments with EMC Avamar and D...
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...CTI Group
 
Unitrends Sales Presentation 2010
Unitrends Sales Presentation 2010Unitrends Sales Presentation 2010
Unitrends Sales Presentation 2010lincolng
 
Skip the Disk, Move to the Cloud
Skip the Disk, Move to the CloudSkip the Disk, Move to the Cloud
Skip the Disk, Move to the CloudIron Mountain
 
StoreGrid : Introduction & Features
StoreGrid : Introduction & FeaturesStoreGrid : Introduction & Features
StoreGrid : Introduction & FeaturesRevolucion
 
DataLockerOverview vs 3.9 Final_120715
DataLockerOverview vs 3.9 Final_120715DataLockerOverview vs 3.9 Final_120715
DataLockerOverview vs 3.9 Final_120715Patrick Eyberg
 

Similar to ESI Recovery from Solid State Technology (20)

Webinar: Cleaning up the SDS Mess - Four Keys to Success
Webinar: Cleaning up the SDS Mess - Four Keys to SuccessWebinar: Cleaning up the SDS Mess - Four Keys to Success
Webinar: Cleaning up the SDS Mess - Four Keys to Success
 
Computer Forensic
Computer ForensicComputer Forensic
Computer Forensic
 
Physical media damage is data recoverable from my hard drive
Physical media damage  is data recoverable from my hard drivePhysical media damage  is data recoverable from my hard drive
Physical media damage is data recoverable from my hard drive
 
Data Protection Fde Solution Presentation
Data Protection Fde Solution PresentationData Protection Fde Solution Presentation
Data Protection Fde Solution Presentation
 
Murli Thirumale, CEO Ocarina Networks
Murli Thirumale, CEO Ocarina NetworksMurli Thirumale, CEO Ocarina Networks
Murli Thirumale, CEO Ocarina Networks
 
Are your ready for in memory applications?
Are your ready for in memory applications?Are your ready for in memory applications?
Are your ready for in memory applications?
 
Big data introduction
Big data introductionBig data introduction
Big data introduction
 
Are Your PCs and Laptops Recovery and Discovery Ready?
Are Your PCs and Laptops Recovery and Discovery Ready?Are Your PCs and Laptops Recovery and Discovery Ready?
Are Your PCs and Laptops Recovery and Discovery Ready?
 
Webinar: How to Design Primary Storage for GDPR
Webinar: How to Design Primary Storage for GDPRWebinar: How to Design Primary Storage for GDPR
Webinar: How to Design Primary Storage for GDPR
 
Flash Stories: How Customers Make Smarter Decisions Faster
Flash Stories: How Customers Make Smarter Decisions FasterFlash Stories: How Customers Make Smarter Decisions Faster
Flash Stories: How Customers Make Smarter Decisions Faster
 
Power Point example for module 3 assignment
Power Point example for module 3 assignmentPower Point example for module 3 assignment
Power Point example for module 3 assignment
 
Peerless DRM and Enterprise Security-Enabled Removable Data Storage Cartridges
Peerless DRM and Enterprise Security-Enabled Removable Data Storage CartridgesPeerless DRM and Enterprise Security-Enabled Removable Data Storage Cartridges
Peerless DRM and Enterprise Security-Enabled Removable Data Storage Cartridges
 
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?Webinar: What's Best for VDI, Hybrid or All-Flash Storage?
Webinar: What's Best for VDI, Hybrid or All-Flash Storage?
 
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signage
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signageSilicon Motion's PCIe FerriSSD : High speed and reliability for digital signage
Silicon Motion's PCIe FerriSSD : High speed and reliability for digital signage
 
Academic Workflows with iRODS FINAL
Academic Workflows with iRODS FINALAcademic Workflows with iRODS FINAL
Academic Workflows with iRODS FINAL
 
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...Transforming Backup and Recovery in VMware environments with EMC Avamar and D...
Transforming Backup and Recovery in VMware environments with EMC Avamar and D...
 
Unitrends Sales Presentation 2010
Unitrends Sales Presentation 2010Unitrends Sales Presentation 2010
Unitrends Sales Presentation 2010
 
Skip the Disk, Move to the Cloud
Skip the Disk, Move to the CloudSkip the Disk, Move to the Cloud
Skip the Disk, Move to the Cloud
 
StoreGrid : Introduction & Features
StoreGrid : Introduction & FeaturesStoreGrid : Introduction & Features
StoreGrid : Introduction & Features
 
DataLockerOverview vs 3.9 Final_120715
DataLockerOverview vs 3.9 Final_120715DataLockerOverview vs 3.9 Final_120715
DataLockerOverview vs 3.9 Final_120715
 

Recently uploaded

Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsAndrey Dotsenko
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 

Recently uploaded (20)

Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 

ESI Recovery from Solid State Technology

  • 1. DriveSavers Data Recovery Title: ESI Recovery from Solid State Technology New Challenges for eDiscovery Presented by: Chris Bross Senior Enterprise Recovery Engineer
  • 2. Survey How many of you own a Solid State Device? y y Smart Phone, Camera, Tablet, Ultrabook?
  • 4. Who is DriveSavers? Corporate Profile Pioneered th d t recovery i d t 27 years ago Pi d the data industry Global leader in secure data recovery services Who We Serve eDiscovery and L Di d Law fifirms, fi financial organizations, F t i l i ti Fortune 500 companies, i healthcare institutions, government agencies, universities and consumers Compliance and security dependent clients Capabilities Fastest, most reliable, and most secure provider All storage devices — All OS supported Forensic imaging, eDiscovery and Data Sanitization
  • 5. Data Recovery & Imaging Defined Software User and professional tools available Ineffective with hardware failure Professional Data Recovery Service Reverse engineering laboratory and clean rooms Resolve hardware and more complicated failures p Forensic Imaging Data as evidence Acquisition, analysis and reporting process
  • 6. The Data Storage Market Hard Disk Drive History and market dominance Current and projected growth Solid State Drives Growth in Ultrabooks, MacBooks, premium laptops In the Enterprise and in the Cloud p Smart Devices 2007 birth of the iPhone Explosive global growth
  • 8. Solid State Storage Defined Data Storage on ( g (NVM) Non-Volatile Memory ) y Semiconductor chip based cellular data storage NAND flash Technology Most common NVM today Costs decreasing, capacity increasing Scalability, density and reliability challenges y y y g Advantages over traditional hard disk drives No mechanical points of failure Performance, reliability, power efficiency, security
  • 9. Reliability of Solid State Devices Reliability Expectations y p No mechanical failures, no moving parts Higher MTBF and lower AFR Reality in the Data Recovery Lab Failure does occur, volume increasing with installed base Recovery can be more challenging than with HDD y g g Storage Industry & Technology Evolving Each generation more reliable Intel as an example
  • 10. Why Data Recovery from SSD? Physical & Environmental Issues y Impact or physical trauma to device Environmental or liquid exposure Device Failure Electro-logical failure Controller/firmware or NAND flash User Fault or Malicious Attack Data deletion, accidental format Encryption issues
  • 11. The Issue: Imaging of ESI from SSD Hard Disk Drive (HDD) ( ) Data stored magnetically on platters Long data retention, proven imaging methods Solid State Drive (SSD) Data stored electronically in cells, within pages, on chips Shorter data retention, more imaging challenges g g g Data Lost Due to Self Maintenance of SSD Routines like TRIM and garbage collection can result in automatic destruction of data
  • 12. The Story: Mat Honan @ Wired Photo: Ariel Zambelich/Wired. Illustration: Ross Patton/Wired
  • 13. Data in Cloud and Solid State
  • 14. The Challenges in this Case Secure Remote Wipe via iCloud hack of 3 Devices p Physical layer overwrite of all data All storage devices were solid state, no magnetic HDD iOS Devices Not Recoverable Remote secure wipe was completed Apple iOS and hardware encryption complication pp yp p MacBook Air w SSD Successful Recovery “Perfect Storm” of events Complications of image and recovery process due to SSD self maintenance
  • 16. Challenges in Forensic Imaging Proprietary Technologies From OEM p y g Highly protected trade secrets may prevent data access Rapid competitive technology advances Encryption Default built in to SSD hardware controller Corporate software encryption deployments p yp p y TRIM & Garbage Collection Self maintenance and performance routines Detrimental to recovery and forensic imaging
  • 17. Encryption In Software Common in large corporate or government deployments No imaging issues if keys/credentials are provided Physical failure can produce partial corrupt image In Hardware Controller or firmware failure can prevent imaging p g g Encryption key unknown to user Firmware reload can trigger key regeneration Linked via TPM to software encryption
  • 18. TRIM TRIM defined Operating system command to remove data at device level TRIM support Must be enabled in hardware and supported in software Current Windows, MacOS and Linux full implementation Operation and R O ti d Results lt Runs immediately upon empty of recycle bin Resets (programs) cells to 1 (erased) Data is unrecoverable
  • 19. Garbage Collection Background Garbage Collection ( g g (BGC) defined ) Automatic controller function for maintenance BGC support All current SSDs support in hardware OS independent operation Operation and R O ti d Results lt Runs indeterminately and quickly in the background Defragments and optimizes saved data Resets (programs) cells to 1 (erased) Prior data is unrecoverable
  • 20. Process in the Recovery Lab
  • 21. Process in the Recovery Lab Capture & Acquire Image ASAP p q g Source is a moving target that may degrade/purge data Disabling BGC impossible without help from OEM Using a write-blocker DOES NOT stop these processes write blocker Image Access Via Controller & Data Interface Ideal to work with device intact and functional Imperative for encrypting devices NAND Chip Extraction and Imaging Only on non-encrypting devices Complicated reverse engineering of write algorithm
  • 22. Advantages at DriveSavers Lab Engineering and Experience g g p Hundreds of thousands of cases completed Specialized SSD and NAND engineers Strategic Industry Alliances Trusted exchange of field failure analysis Development of OEM specific tools p p R&D Non-stop commitment to new tools and tech Acting as “thought leaders” for the industry
  • 23. Forensic and eDiscovery Services Data Collection Data Processing Data Export p Data Review and Hosting Expert Witness Testimony Litigation Management Data Analytics
  • 24. Best Practices To Follow Understand the Differences of HDD vs SSD Imaging g g First chance may be only chance Understand the limitations of the technology Litigation Hold Letters Consider specific instructions for SSD ESI requests Require immediate imaging of devices q g g If Unable to Image SSD STOP, power off and engage a professional lab ESI will potentially degrade with any attempts
  • 25. Looking Forward Greater Market Adoption of Solid State Storage p g Everything mobile, corporate and enterprise Solid State now in the Cloud! SandForce/LSI example New Technologies = New Challenges More security, encryption & “secret sauce” Compression, de-duplication, FTL Sanitization of SSD Imaging and Recovery Challenges Continue
  • 27. DriveSavers Data Recovery Thank You! Chris Bross Senior Enterprise Recovery Engineer chris.bross@drivesavers.com chris bross@drivesavers com