De-Wipimization: Unmasking Anti-Forensic Traces with Machine Learning

De-Wipimization: Detection of data wiping traces for investigating NTFS file system

2020-09-09
Dong Bin Oh, Kyung Ho Park, Huy Kang Kim
Summary
Problem
Method
Results
Takeaways
Abstract

The paper introduces "De-Wipimization," a forensic framework using machine learning and entropy analysis to detect data wiping traces in NTFS file systems. By analyzing NTFS transaction logs (UsnJrnl, LogFile, and MFT), the method achieves over 99% accuracy in identifying specific wiping tools and distinguishes wiped files from normally deleted ones with 96% accuracy.

TL;DR

Data wiping is the ultimate weapon for anti-forensics, designed to make evidence unrecoverable. However, "De-Wipimization" proves that even the most thorough wiping tools leave a "digital footprint" in the low-level transactions of the NTFS file system. By training machine learning models on metadata like the USN Journal, researchers can now identify which files were wiped, which tool was used, and what security standard was applied—with up to 99% accuracy.

The Motivation: When the "Smoking Gun" is Wiped

In a typical investigation, a forensic analyst looks at the Windows Registry or Prefetch files to see if a wiping tool (like CCleaner) was executed. But there is a catch: modern wiping tools are designed to wipe their own tracks.

If a criminal wipes the prefetch files and the registry, the investigator is left in the dark. The authors of this paper realized that while a tool can hide its execution history, it cannot hide the physical behavior it imposes on the file system. Every time a tool overwrites a file seven times (DoD standard), it generates a unique sequence of NTFS transactions that are vastly different from a simple "Right-Click -> Delete" action.

Methodology: The Core of De-Wipimization

The researchers focused on three persistent NTFS sources: MFT (UsnJrnl), and LogFile ($LogFile). Unlike user files, these transaction logs are managed by the kernel and are difficult for standard applications to modify without corrupting the volume.

1. Entropy-Based Partition Detection

Before looking for individual files, the authors use entropy graphs to detect wiped or encrypted partitions.

  • Wiped Partitions: Show extremely high entropy (close to 1.0) if filled with random patterns, or extremely low (close to 0) if zeroed out.
  • Encrypted Partitions: Look similar to random wiping but often retain a Volume Boot Record (VBR) with specific structural signatures.

Partition Wiping Rule Logic

2. Feature Engineering: The "Timedelta" Hack

The study's most brilliant insight is the Timedelta feature. Wiping a 1GB file requires overwriting the actual disk sectors multiple times, whereas a normal Windows deletion only marks a record in the MFT as "unused."

  • Insight: Wiping actions take significantly more time and generate a massive volume of "Reason Flags" in the UsnJrnl.

Feature difference within file wiping actions

Experiments & SOTA Results

The team tested five popular tools: BCWipe, Eraser, Moo0, Sdelete, and CCleaner. They used 11 types of media and document files from the NPS filetypes1 dataset.

Key Results:

  • File Wiping Detection: Using a Random Forest model with "All Features," they achieved an accuracy of 96.3% in distinguishing wiped files from normal deletions.
  • Tool Identification: Once a wipe was detected, the model identified the specific tool (e.g., Sdelete vs. Eraser) with 100% accuracy in most test cases.
  • Sanitization Standard Detection: They successfully grouped tools by how they implement standards like US DoD 5220.22-M and Peter Gutmann (35-pass).

Table 4: Result of File Wiping Detection

Depth & Insight: Why This Works

The reason Random Forest performs so well here is that wiping tools are essentially state machines. For example, one tool might rename a file to "ZZZZZZ" before deleting it, while another might overwrite the file and then change the timestamp. These "procedural signatures" are captured perfectly by the UsnJrnl transaction sequence.

Limitations

While highly effective on NTFS, the authors note that SSD TRIM commands can complicate the process by re-arranging unallocated space, potentially clearing transaction info. Additionally, the study is currently limited to the Windows environment (NTFS), requiring future adaptation for APFS (macOS) or ext4 (Linux).

Conclusion

"De-Wipimization" proves that in the digital world, perfect deletion is nearly impossible. By analyzing the "shutter speed" of file system transactions rather than just the end state of the data, forensic investigators can bypass anti-forensic barriers and reconstruct the intent and methods of a suspect with mathematical certainty.

Final Decision Process

Find Similar Papers

Try Our Examples

  • Search for recent studies that apply machine learning to detect data wiping or anti-forensic activities in APFS (Apple File System) or ext4 (Linux).
  • Which paper first established the concept of "Digital Tool Marks" (DTM) in file system forensics, and how does this paper automate that concept?
  • Explore how SSD-specific features, such as TRIM commands and wear leveling, affect the persistence of NTFS transaction logs in forensic investigations.
Contents
De-Wipimization: Unmasking Anti-Forensic Traces with Machine Learning
1. TL;DR
2. The Motivation: When the "Smoking Gun" is Wiped
3. Methodology: The Core of De-Wipimization
3.1. 1. Entropy-Based Partition Detection
3.2. 2. Feature Engineering: The "Timedelta" Hack
4. Experiments & SOTA Results
4.1. Key Results:
5. Depth & Insight: Why This Works
5.1. Limitations
6. Conclusion