esi recoveries from solid state drive technology – new challenges

27
DriveSavers Data Recovery Title: ESI Recovery from Solid State Technology ESI Recovery from Solid State Technology New Challenges for eDiscovery Presented by: Presented by: Chris Bross Senior Enterprise Recovery Engineer

Upload: drivesavers-data-recovery

Post on 07-Jul-2015

526 views

Category:

Technology


0 download

DESCRIPTION

Chris Bross, DriveSavers - Speaker at the Chief Litigation Officer Summit Fall 2012, held in Las Vegas, NV, September 13-15, 2012, delivered his presentation entitled ESI Recoveries from Solid State Drive Technology – New Challenges

TRANSCRIPT

Page 1: ESI Recoveries from Solid State Drive Technology – New Challenges

DriveSavers Data RecoveryTitle:

ESI Recovery from Solid State TechnologyESI Recovery from Solid State TechnologyNew Challenges for eDiscovery

Presented by:Presented by:Chris BrossSenior Enterprise Recovery Engineer

Page 2: ESI Recoveries from Solid State Drive Technology – New Challenges

Survey

How many of you own a Solid State Device?y ySmart Phone, Camera, Tablet, Ultrabook?

Page 3: ESI Recoveries from Solid State Drive Technology – New Challenges

NAND flash

Page 4: ESI Recoveries from Solid State Drive Technology – New Challenges

Who is DriveSavers?

Corporate ProfilePi d th d t i d t 27Pioneered the data recovery industry 27 years agoGlobal leader in secure data recovery services

Who We ServeDi d L fi fi i l i ti F t 500 ieDiscovery and Law firms, financial organizations, Fortune 500 companies,

healthcare institutions, government agencies, universities and consumersCompliance and security dependent clients

CapabilitiesCapabilitiesFastest, most reliable, and most secure providerAll storage devices — All OS supportedForensic imaging, eDiscovery and Data Sanitization

Page 5: ESI Recoveries from Solid State Drive Technology – New Challenges

Data Recovery & Imaging Defined

SoftwareUser and professional tools availableIneffective with hardware failure

Professional Data Recovery ServiceReverse engineering laboratory and clean roomsResolve hardware and more complicated failuresp

Forensic ImagingData as evidenceAcquisition, analysis and reporting process

Page 6: ESI Recoveries from Solid State Drive Technology – New Challenges

The Data Storage Market

Hard Disk Drive History and market dominanceCurrent and projected growth

Solid State DrivesGrowth in Ultrabooks, MacBooks, premium laptopsIn the Enterprise and in the Cloudp

Smart Devices2007 birth of the iPhoneExplosive global growth

Page 7: ESI Recoveries from Solid State Drive Technology – New Challenges

Solid State Storage Defined

Page 8: ESI Recoveries from Solid State Drive Technology – New Challenges

Solid State Storage Defined

Data Storage on (NVM) Non-Volatile Memoryg ( ) ySemiconductor chip based cellular data storage

NAND flash TechnologyMost common NVM todayCosts decreasing, capacity increasingScalability, density and reliability challengesy y y g

Advantages over traditional hard disk drivesNo mechanical points of failurePerformance, reliability, power efficiency, security

Page 9: ESI Recoveries from Solid State Drive Technology – New Challenges

Reliability of Solid State Devices

Reliability Expectationsy pNo mechanical failures, no moving partsHigher MTBF and lower AFR

Reality in the Data Recovery LabFailure does occur, volume increasing with installed baseRecovery can be more challenging than with HDDy g g

Storage Industry & Technology EvolvingEach generation more reliableIntel as an example

Page 10: ESI Recoveries from Solid State Drive Technology – New Challenges

Why Data Recovery from SSD?

Physical & Environmental IssuesyImpact or physical trauma to deviceEnvironmental or liquid exposure

Device FailureElectro-logical failureController/firmware or NAND flash

User Fault or Malicious AttackData deletion, accidental formatEncryption issues

Page 11: ESI Recoveries from Solid State Drive Technology – New Challenges

The Issue: Imaging of ESI from SSD

Hard Disk Drive (HDD)( )Data stored magnetically on plattersLong data retention, proven imaging methods

Solid State Drive (SSD)Data stored electronically in cells, within pages, on chipsShorter data retention, more imaging challengesg g g

Data Lost Due to Self Maintenance of SSDRoutines like TRIM and garbage collection can result in automatic destruction of data

Page 12: ESI Recoveries from Solid State Drive Technology – New Challenges

The Story: Mat Honan @ Wired

Photo: Ariel Zambelich/Wired. Illustration: Ross Patton/Wired

Page 13: ESI Recoveries from Solid State Drive Technology – New Challenges

Data in Cloud and Solid State

Page 14: ESI Recoveries from Solid State Drive Technology – New Challenges

The Challenges in this Case

Secure Remote Wipe via iCloud hack of 3 DevicespPhysical layer overwrite of all dataAll storage devices were solid state, no magnetic HDD

iOS Devices Not RecoverableRemote secure wipe was completedApple iOS and hardware encryption complicationpp yp p

MacBook Air w SSD Successful Recovery“Perfect Storm” of eventsComplications of image and recovery processdue to SSD self maintenance

Page 15: ESI Recoveries from Solid State Drive Technology – New Challenges

Challenges in Forensic Imaging

Page 16: ESI Recoveries from Solid State Drive Technology – New Challenges

Challenges in Forensic Imaging

Proprietary Technologies From OEMp y gHighly protected trade secrets may prevent data accessRapid competitive technology advances

EncryptionDefault built in to SSD hardware controllerCorporate software encryption deployments p yp p y

TRIM & Garbage CollectionSelf maintenance and performance routinesDetrimental to recovery and forensic imaging

Page 17: ESI Recoveries from Solid State Drive Technology – New Challenges

Encryption

In SoftwareCommon in large corporate or government deploymentsNo imaging issues if keys/credentials are providedPhysical failure can produce partial corrupt imagePhysical failure can produce partial corrupt image

In HardwareController or firmware failure can prevent imagingp g gEncryption key unknown to user Firmware reload can trigger key regenerationLinked via TPM to software encryptionLinked via TPM to software encryption

Page 18: ESI Recoveries from Solid State Drive Technology – New Challenges

TRIM

TRIM definedOperating system command to remove data at device level

TRIM supportMust be enabled in hardware and supported in softwareCurrent Windows, MacOS and Linux full implementation

O ti d R ltOperation and ResultsRuns immediately upon empty of recycle binResets (programs) cells to 1 (erased)Data is unrecoverable

Page 19: ESI Recoveries from Solid State Drive Technology – New Challenges

Garbage Collection

Background Garbage Collection (BGC) definedg g ( )Automatic controller function for maintenance

BGC supportAll current SSDs support in hardwareOS independent operation

O ti d R ltOperation and ResultsRuns indeterminately and quickly in the backgroundDefragments and optimizes saved dataResets (programs) cells to 1 (erased)Prior data is unrecoverable

Page 20: ESI Recoveries from Solid State Drive Technology – New Challenges

Process in the Recovery Lab

Page 21: ESI Recoveries from Solid State Drive Technology – New Challenges

Process in the Recovery Lab

Capture & Acquire Image ASAPp q gSource is a moving target that may degrade/purge dataDisabling BGC impossible without help from OEMUsing a write-blocker DOES NOT stop these processesUsing a write blocker DOES NOT stop these processes

Image Access Via Controller & Data InterfaceIdeal to work with device intact and functionalImperative for encrypting devices

NAND Chip Extraction and ImagingOnly on non-encrypting devicesComplicated reverse engineering of write algorithm

Page 22: ESI Recoveries from Solid State Drive Technology – New Challenges

Advantages at DriveSavers Lab

Engineering and Experienceg g pHundreds of thousands of cases completedSpecialized SSD and NAND engineers

Strategic Industry AlliancesTrusted exchange of field failure analysisDevelopment of OEM specific toolsp p

R&DNon-stop commitment to new tools and techActing as “thought leaders” for the industry

Page 23: ESI Recoveries from Solid State Drive Technology – New Challenges

Forensic and eDiscovery Services

Data Collection

Data Processing

Data Exportp

Data Review and Hosting

Expert Witness TestimonyExpert Witness Testimony

Litigation Management

Data Analytics

Page 24: ESI Recoveries from Solid State Drive Technology – New Challenges

Best Practices To Follow

Understand the Differences of HDD vs SSD Imagingg gFirst chance may be only chanceUnderstand the limitations of the technology

Litigation Hold LettersConsider specific instructions for SSD ESI requestsRequire immediate imaging of devicesq g g

If Unable to Image SSDSTOP, power off and engage a professional labESI will potentially degrade with any attempts

Page 25: ESI Recoveries from Solid State Drive Technology – New Challenges

Looking Forward

Greater Market Adoption of Solid State Storagep gEverything mobile, corporate and enterprise

Solid State now in the Cloud!SandForce/LSI example

New Technologies = New ChallengesMore security, encryption & “secret sauce”Compression, de-duplication, FTLSanitization of SSD

Imaging and Recovery Challenges Continue

Page 26: ESI Recoveries from Solid State Drive Technology – New Challenges

DriveSavers Data RecoveryQ&A

Page 27: ESI Recoveries from Solid State Drive Technology – New Challenges

DriveSavers Data RecoveryThank You!

Chris BrossSenior Enterprise Recovery Engineerchris bross@drivesavers [email protected]