Spotlight is a proprietary desktop search technology released by Apple in 2004 for its Macintosh operating system Mac OS X 10.4 (Tiger) and remains as a feature in current releases of macOS. Spotlight allows users to search for files or information by querying databases populated with filesystem attributes, metadata, and indexed textual content. Existing forensic research into Spotlight has provided an understanding of the metadata attributes stored within the metadata store database. Current approaches in the literature have also enabled the extraction of metadata records for extant files, but not for deleted files. The objective of this paper is to research the persistence of records for deleted files within Spotlight's metadata store, identify if deleted database pages are recoverable from unallocated space on the volume, and to present a strategy for the processing of discovered records. In this paper, the structure of the metadata store database is outlined, and experimentation reveals that records persist for a period of time within the database but once deleted, are no longer recoverable. The experimentation also demonstrates that deleted pages from the database (containing metadata records) are recoverable from unused space on the filesystem.
翻译:焦点是2004年苹果公司为其Macintosh操作系统Mac OS X 10.4(Tiger)释放的一种专有的桌面搜索技术,它仍然是目前macOS发布的一个特点。焦点使用户能够通过查询含有文件系统属性、元数据和索引文本内容的数据库来搜索文件或信息。对焦点的现有法证研究使人们了解元数据存储数据库中储存的元数据属性。文献中的当前方法也使得能够提取剩余文件的元数据记录,而不是被删除的文件。本文的目的是研究Spointlight元数据存储中被删除文件的记录的持久性,确定被删除的数据库页面是否可从数量上未分配的空间中回收,并提出处理已发现记录的战略。在本文件中,概述了元数据存储数据库的结构,并实验显示,在数据库内持续了一段时间但被删除的记录不再可以恢复。实验还表明,数据库中删除的网页(含有元数据记录)可以从文件系统中的未使用的空间中恢复。