FRED_Optimization_EnCase_8
FRED_Optimization_EnCase_8
Optimization
• Build Repository
• 1 million “random” files (GovDocs)
• Enron dataset
• Browsing History
• Process to create Test Disk
• Sample files to get appropriate dataset size
• Prepare base OS install (win10)
• Make users w/”desktops” and other supporting structures
• Copy files to user’s “documents” (round-robin)
• Obfuscate by changing extension periodically
• Copy and delete to “fragment” the drive – create carving challenge
• Put sample Internet Activity into a single user’s browser history files
• https://www.symantec.com/connect/articles/web-browser-forensics-part-1
“ImageDisk7”
21009 .PDF 17 .PST
• 46 file extensions*
• Note some may be obfuscated
3298 .GIF 3 .GLS
4 .PUB
… ...
System Resources and Testing
• CPU/Cores
• X99 (i7 6800K Family)
• Z10 (Xeon E5-2600 Family)
• Memory
• I/O Subsystem Types and Architectures
KFF Low Low None Low Low (Fixed < 40GB) None
Discussion of I/O Architectures
IO Operations /
Type Strengths Weaknesses
Throughput
SATA Mechanical Low/Low Low $$ per GB, High Slow, No Fault-tolerance
Capacity
SATA SSD Medium/Medium Good IOPS and Throughput No Fault-tolerance, Limited
Capacity
RAID 5 Medium/High Good Read Performance, Poor Write Performance,
Fault-tolerant, Good Increased Storage Overhead
Capacity
RAID 10 High/High Good Read/Write High Storage Overhead
Performance, Fault-tolerant
NVMe Very High/High Excellent IOPS and Good No Fault-tolerance, Limited
Read/Write Performance Capacity, High Cost
Single Factor Results
• Benefits
• Maximum Memory
• Affects Pre-Processing
• Increased Clock Speed
• Affects Verify, Indexing, and
Carving
• Surprises
• RAID-5 vs RAID-10
• RAID CACHE Volume
Multi-factor Results
• Benefits
• Confirms decision to
combine CASE and EVIDENCE
volumes
• ~35% overall performance
improvement
• Surprises
• RAID w/SSD’s does not
differentiate itself
Conclusions
• Increased Benefit • Reduced Benefit
• Maximize Memory • Increase # of Cores
• Maximize CPU clock speed • Usually results in lower clock speeds
due to thermal issues
• RAID for read-intensive volumes
• Evidence
• RAID-10 vs RAID-5
• Significant loss of storage capacity
• Case – little or no activity*
with no major performance
• KFF on high IOPS volume improvement
• RAID for write-intensive volumes
• Cache