<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
	<channel>
<title>AFFLIB RSS Feed</title><link>http://afflib.org/index.php</link><description>Information about AFF</description><dc:language>en</dc:language><dc:creator>simsong@acm.org</dc:creator><dc:rights>Copyright 2008 Simson L. Garfinkel and Basis Technology Corp.</dc:rights><dc:date>2008-08-19T14:09:13-07:00</dc:date><admin:generatorAgent rdf:resource="http://www.realmacsoftware.com/" />
<admin:errorReportsTo rdf:resource="mailto:simsong@acm.org" /><sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>
<lastBuildDate>Tue, 19 Aug 2008 14:10:01 -0700</lastBuildDate><item><title>AFFLIB 3.3 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2008-08-19T14:09:13-07:00</dc:date><link>http://afflib.org/./announcements_files/bbfacf3ee66dbc17b19ec49a52d5331c-11.php#unique-entry-id-11</link><guid isPermaLink="true">http://afflib.org/./announcements_files/bbfacf3ee66dbc17b19ec49a52d5331c-11.php#unique-entry-id-11</guid><content:encoded><![CDATA[================================================================<br />SUPPORT FOR VMWARE DISK IMAGES<br /><br />AFFLIB 3.3 incorporates the disk image subsystem from the open-source<br />QEMU processor virtualization project. Although most of QEMU is<br />distributed under the GPL license, the disk subsystem is distributed<br />under a less restrictive license that allows any use. <br /><br />As a result, forensic programs linked with AFFLIB can now<br />transparently access disk images stored in any of the following<br />formats; currently the format is specified with the indicated extension.<br /><br />So far we have only tested with VMWare .vmdk images:<br /><br />	* VMWare VMDK (.vmdk)             (tested)<br /><br />We also have the ability to add additional file types, including:<br />	* Bochs Virtual HD Image<br />	* cloop<br />	* cow<br />	* DMG<br />	* qcow<br />	* qcow2<br />	* VFAT <br />	* Parallels <br />	* Connectix Virtual PC <br /><br />Support for these will be enabled if requested.<br />================================================================<br />SIGNIFICANTLY IMPROVED PERFORMANCE<br /><br />Now that the feature set for AFFLIB is largely complete, we are<br />beginning to pay attention to performance issues. In particular, we<br />found a significant problem in versions 3.0 through 3.2 that would<br />significantly degrade performance of disk images larger than 1GB. This<br />has now been addressed.<br />]]></content:encoded></item><item><title>AFF publications</title><dc:creator>simsong@acm.org</dc:creator><category>publications</category><dc:date>2008-07-20T23:37:12-07:00</dc:date><link>http://afflib.org/./announcements_files/b3372c0b00f54db8b813912b51c9c930-10.php#unique-entry-id-10</link><guid isPermaLink="true">http://afflib.org/./announcements_files/b3372c0b00f54db8b813912b51c9c930-10.php#unique-entry-id-10</guid><content:encoded><![CDATA[We now have a web page listing <a href="../publications.html" rel="self" title="AFF Publications">AFF-related publications</a>.<br />]]></content:encoded></item><item><title>AFFLIB 3.2.3 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2008-07-20T22:29:08-07:00</dc:date><link>http://afflib.org/./announcements_files/2cc8aa0859ce00a98ce9affff86dfd16-9.php#unique-entry-id-9</link><guid isPermaLink="true">http://afflib.org/./announcements_files/2cc8aa0859ce00a98ce9affff86dfd16-9.php#unique-entry-id-9</guid><content:encoded><![CDATA[AFFLIB 3.2.3 is released. <br /><br />This release features a more in-depth regression suite which now automatically validates the AFFLIB encryption and digital signature features. (There are also bugfixes for the bugs that we found as a result of the automated regression testing.) Some of the command-line options for the afsign, afcrypto and afcopy commands have been changed for consistency. XML generation of afxml has been improved.<br /><br />]]></content:encoded></item><item><title>MANDIANT Announces support for AFF</title><dc:creator>simsong@acm.org</dc:creator><dc:subject>Announcements</dc:subject><dc:date>2008-06-05T07:36:44-07:00</dc:date><link>http://afflib.org/./announcements_files/bb0e4b59ab362aab5dd816004c52fe32-8.php#unique-entry-id-8</link><guid isPermaLink="true">http://afflib.org/./announcements_files/bb0e4b59ab362aab5dd816004c52fe32-8.php#unique-entry-id-8</guid><content:encoded><![CDATA[For those of you who may have missed it, on January 28, 2008, Mandiant announced support for AFF.<br /><br /><ul class="disc"><li><a href="http://www.reuters.com/article/pressRelease/idUS109483+28-Jan-2008+PRN20080128" rel="self">January 28, 2008 Press Release</a></li><li><a href="http://mandiant.com/documents/mirdatasheet.pdf" rel="self">Data Sheet</a></li></ul>]]></content:encoded></item><item><title>AFFLIB 3.2.1 Released with signatures</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2008-05-29T22:55:48-07:00</dc:date><link>http://afflib.org/./announcements_files/dba7644cdb14a8740646e4e2a08ce8d5-7.php#unique-entry-id-7</link><guid isPermaLink="true">http://afflib.org/./announcements_files/dba7644cdb14a8740646e4e2a08ce8d5-7.php#unique-entry-id-7</guid><content:encoded><![CDATA[AFFLIB 3.2.1 has been released. This version is now cryptographically signed by the AFFLIB <a href="../pgp.php" rel="self" title="PGP Public Key">public key</a>. It also includes improved support for libewf when compiled with multibyte string support.<br /><br /> ]]></content:encoded></item><item><title>AFFLIB 3.2 Released with full support for public key cryptography</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2008-05-12T11:17:59-07:00</dc:date><link>http://afflib.org/./announcements_files/6231d11be14a0de358f6bc9cb3ca74c7-6.php#unique-entry-id-6</link><guid isPermaLink="true">http://afflib.org/./announcements_files/6231d11be14a0de358f6bc9cb3ca74c7-6.php#unique-entry-id-6</guid><content:encoded><![CDATA[We are happy to announce the release of AFFLIB 3.2, the first support of AFFLIB with full support for public key cryptography. <br /><br />AFFLIB now supports the following features:<br /><ul class="disc"><li>Images in AFF or AFD format can be digitally signed. </li><li>Raw files and split/raw files can be digitally signed using the AFM format.</li><li>Images in the AFF or AFD format can be encrypted with a passphrase.</li><li>Images in the AFF or AFD format can be encrypted with a public key; once encrypted, the image can only be accessed by someone with the corresponding private key.</li></ul><br />Encryption keys and passphrases can be specified either in filenames or in environment variables, allowing for transparent operating with existing AFF-compliant programs such as SleuthKit.  Encryption is fully operable in the affuse program, allowing an encrypted AFF image to be mounted as an unencrypted, raw image in a Linux file system. This can be used in conjunction with VMWare player and Windows XP, allowing programs such as EnCase and FTK to access AFF-encrypted images.<br /><br />The draft of a journal article that describes AFF encryption appears at <a href="http://www.afflib.org/affcrypto.pdf" rel="self">http://www.afflib.org/affcrypto.pdf</a>.<br />]]></content:encoded></item><item><title>AFFLIB 3.1 and AIMAGE 3.1 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2007-11-28T11:58:18-08:00</dc:date><link>http://afflib.org/./announcements_files/d433bd78050cd544c91dc32957d21955-5.php#unique-entry-id-5</link><guid isPermaLink="true">http://afflib.org/./announcements_files/d433bd78050cd544c91dc32957d21955-5.php#unique-entry-id-5</guid><content:encoded><![CDATA[We are pleased to announce the release of AFFLIB 3.1 and AIMAGE 3.1. <br /><br />With this release we have separated out AIMAGE from the AFFLIB code base to allow for more rapid development of AIMAGE without continually producing new AFF releases.<br /><br />Other improvements with AFFLIB 3.1 include:<br /><br />* Better support for compiling on different versions of Linux<br />* Better error reporting in the afsign and afverify <br /><br />This is a minor release which does not offer improved performance, but if you are using the digital signature features you should upgrade.<br />]]></content:encoded></item><item><title>AFFLIB 3.0 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2007-11-11T05:46:37-08:00</dc:date><link>http://afflib.org/./announcements_files/c9253ff23419749be4612e4ede62bb5d-4.php#unique-entry-id-4</link><guid isPermaLink="true">http://afflib.org/./announcements_files/c9253ff23419749be4612e4ede62bb5d-4.php#unique-entry-id-4</guid><content:encoded><![CDATA[			ANNOUNCING AFFLIB 3.0<br />Version 3.0 is a significant upgrade to AFFLIB which introduces the<br />following features:<br /><br /><ul class="disc"><li>  STRONG DIGITAL SIGNATURES WITH X.509 CERTIFICATES</li><li>  SIGNED BILL-OF-MATERIALS AND CHAIN OF CUSTODY</li><li>  SIGNED ISO FILES</li><li>  PARITY PAGES ALLOW RECONSTRUCTION OF DAMAGED DISK IMAGES</li></ul><br /><h2>STRONG ENCRYPTION FOR AFF FILES.</h2><br />  With Version 3.0 we are introducing the ability to encrypt AFF evidence files with the AES-256 algorithm, the strongest encryption algorithm available today.<br /><br />  Each AFF 3.0 file can be encrypted with a unique AES-256 key. This key is  can then itself be encrypted using a passphrase provided by the  user, or using an X.509 public key.  Because of this two-step  process, the passphraseor public key can be changed in just a few  seconds without having to decrypt and re-encrypt the entire disk  image.<br /><br />  Whereas some other forensic programs provide the ability to put a  "password" on an evidence file, those passwords can be disregarded  by non-conformant programs. (For example, GetData claims that it's  MountImage Pro program can "open EnCase password protected image  files without the password.)  AFF 3.0 uses true encryption: if you  do not know the correct decryption key, the only way to access the  evidence is to brute-force the encryption passphrase (if there is  one). THERE IS NO BACK DOOR.<br /><br /><br /><h2>STRONG DIGITAL SIGNATURES WITH X.509 CERTIFICATES</h2><br />  Version 3.0 introduces strong digital signatures (SHA-256) signed  with X.509 certificates. <br /><br />  Digital signatures represents a significant improvement for evidence  integrity over today's standard practice of recording the MD5 or  SHA-1 of an imaged disk in an investigator's notebook. <br /><br />  AFF Digital Signatures, signatures are written for the entire disk   image, all of the disk's metadata, and every 16-megabyte AFF "page."  Because digital signatures are written after each "page" is  acquired, the integrity of these pages can be established in court  even if the entire disk cannot be images (for example, because the  device is fault, or because there is insufficient time).<br /><br />  AFF Digital Signatures complement existing integrity  measures. Because the signature is stored in its own metadata  segment, the signature does not change the content of the acquired  disk image.<br /><br />  Signatures can be written with either self-signed certificates or  with X.509 certificates that are issued as part of an organization's  PKI.  Using X.509 certificates means that AFF can support RSA or DSA  algorithms with 1024, 2048 or larger keys.<br /><br /><br /><h2>SIGNED BILL-OF-MATERIALS AND CHAIN OF CUSTODY</h2><br />  Version 3.0 introduces a special XML structure that contains a list  of every AFF segment in the file, a signature for each segment, a  set of "notes," and a public key. This structure is called an "AFF  Bill Of Materials" (AFFBOM).<br /><br />  When an AFF image is created with AIMAGE, the AFFBOM is created and  signed with the private key belonging to the person who did the  acquisiton. Thereafter, each time a signed AFF file is copied, a new  AFFBOM can be created which includes a new AFFBOM which covers all  of the original segments and all of the previous AFFBOMs. In this  manner the sequence of signed bill-of-materials becomes a custody  chain, showing who has copied the image and verifying that no  evidentuary segments have been added, deleted, or modified.<br /><br /><br /><h2>SIGNED ISO FILES</h2><br />  AFF's "AFM" format allows a disk image to be stored in an uncompressed  raw file (eg "file.iso") and the associated metadata to be stored in a  ".afm" file. The AFM format can also handle raw data stored as a  series of "split" raw files (eg "file.001", "file.002", "file.003"  etc.)<br /><br />  Beacuse AFF tools operating on named segments that are independent  of the underlying storage container, the AFM format allows any  ISO-file to be signed using the "afsign" command. When filename.iso  is signed, the afsign create a new file called filename.afm which  contains the signatures, the signed bill of materials, and other  metadata.<br /><br />  Although it is also possible sign ISO files using existing tools  such as PGP with detached signatures, afsign has several advantages:<br /><br /><ul class="disc"><li>afsign will sign every 16-megabytes chunk of the ISO file. In this    way, if the file is corrupted, you will be able to pinpoint what data is invalid and what data is still good.</li><li>Unlike PGP, afsign allows you to add arbitrary metadata and  maintain chain-of-custody information.</li><li>You can sign with X.509 certificates</li></ul><br /><br /><h2>PARITY PAGES ALLOW RECONSTRUCTION OF DAMAGED DISK IMAGES</h2><br />  Because every 16-megabyte chunk of an AFF or AFM file is signed,  it is easy to detect when a page has been modified or accidently  corrupted. The BoM allows missing pages to be detected.<br /><br />  Similar to RAID5 on hard drives, an AFF parity page makes possible  to reconstruct damaged or missing AFF data segments. Once repaired  or reconstructed, the signature (which is stored in a differnet  location) can be used to determine if the reconstruction is correct. <br /><br />  Partiy Pages are automatically created when an image is signed with   afsign. The rewritten aimage that will be part of AFFLIB 3.1 will   create parity pages as the drive is imaged.<br /><br /><h2>AVAILABILITY</h2><br />AFFLIB 3.0.0 is available now. <br /><br /><br /><h2>NEW AND MODIFIED TOOLS IN AFF 3.0:</h2><br />The following tools have been aded for AFF 3.0:<br /><br />* afsign - signs an AFF file.<br /><br />* afverify - verifies the signature and chain-of-custody segments of<br />  an AFF file.  <br /><br />* afcrypto - manipulates the cryptographic properties of an AFF file. <br />  - Can change the passphrase<br /><br />The following tools have been modified:<br /><br />* afcopy - If you provide a signing key, a signed bill-of-materials<br />  will be added to extend the chain-of-custody.<br /><br /><br />Other changes in AFF3.0:<br /><br />* A few bugs have been fixed which caused difficulties in testing. (No<br />  users reported problems with them.)<br /><br /><h2>COMING IN AFFLIB 3.1:</h2><br />I've pushed out Version 3.0 so that people can start to experiment with it now. Meanwhile, I'm now working on the following features which, I'm hoping, will make it into Version 3.1:<br /><br /><ul class="disc"><li>Public key encryption (so agents in the field can encrypt to a public key, and the images can only be decrypted in the lab.)</li><li>Dramatically improved performance when opening AFF files with signed bill-of-materials. (The BOM will be used as a table-of-contents so that large AFF files do not need to be scanned from end-to-end.)</li><li>The ability to image raw and AFF files at the same time will be removed (since AFF can now write raw files directly).</li><li>page-at-a-time imaging, resulting in more compact AFF files (less wasted space) and easier implementation of novel data recovery algorithms. </li><li>Calculation of parity pages while the image is written, rather than afterwards.</li></ul>]]></content:encoded></item><item><title>Scrave Released</title><dc:creator>simsong@acm.org</dc:creator><category>carvers</category><dc:date>2007-08-19T23:24:30-07:00</dc:date><link>http://afflib.org/./announcements_files/089e431b790ae3354c421936b682d39f-3.php#unique-entry-id-3</link><guid isPermaLink="true">http://afflib.org/./announcements_files/089e431b790ae3354c421936b682d39f-3.php#unique-entry-id-3</guid><content:encoded><![CDATA[Scrave, the experimental carver discussed in Simson Garfinkel's DFRWS 2007 presentation, is now available at <a href="http://www.afflib.org/downloads/scrave-0.0.1.tar.gz" rel="self">http://www.afflib.org/downloads/scrave-0.0.1.tar.gz</a><br />]]></content:encoded></item><item><title>Version 2.3 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2007-07-01T18:21:44-07:00</dc:date><link>http://afflib.org/./announcements_files/0c88caed330e75f89a006b0f5cee6855-2.php#unique-entry-id-2</link><guid isPermaLink="true">http://afflib.org/./announcements_files/0c88caed330e75f89a006b0f5cee6855-2.php#unique-entry-id-2</guid><content:encoded><![CDATA[AFFLIB Version 2.3 is out!  This version includes improved support for Windows, including a complete build system for Microsoft Visual C++ and pre-built libraries and executables.  The disk imager <strong>aimage </strong>still doesn't run under Windows, but that is on the list.<br /><br />]]></content:encoded></item><item><title>Version 2.2.22 Released</title><dc:creator>simsong@acm.org</dc:creator><category>releases</category><dc:date>2007-06-10T21:22:19-07:00</dc:date><link>http://afflib.org/./announcements_files/6e55154f30bffb4be92f9d69384f4766-1.php#unique-entry-id-1</link><guid isPermaLink="true">http://afflib.org/./announcements_files/6e55154f30bffb4be92f9d69384f4766-1.php#unique-entry-id-1</guid><content:encoded><![CDATA[We have released version 2.2.22.  This version compiles under Cygwin! We will soon be releasing another version that compiles with VC++ (previous versions did as well). When we release that version, we'll be putting up pre-built libraries that run on Windows.<br /><br />]]></content:encoded></item><item><title>New Website</title><dc:creator>simsong@acm.org</dc:creator><dc:subject>Announcements</dc:subject><dc:date>2007-05-27T17:48:37-07:00</dc:date><link>http://afflib.org/./announcements_files/3996d95ccaca8ccbbadeef02ca151f97-0.php#unique-entry-id-0</link><guid isPermaLink="true">http://afflib.org/./announcements_files/3996d95ccaca8ccbbadeef02ca151f97-0.php#unique-entry-id-0</guid><content:encoded><![CDATA[We have given the AFFLIB website a complete redesign. <br />]]></content:encoded></item></channel>
</rss>