Pamungkas, Anggada Sakti (2019) Analisis Forensika Digital Pada Recovery Data Di Media Penyimpana HDD, SSD, Dan SD Card Dalam Sistem Operasi Windows 10. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
05211440000190-Undergraduate_Thesis.pdf Restricted to Repository staff only Download (20MB) | Request a copy |
Abstract
Seiring dengan terjadinya digitalisasi, kasus kejahatan siber (cyber crime) di Indonesia juga turut meningkat. Dalam penanganan kasus-kasus kejahatan siber, tidak jarang pelaku menghapus bukti maupun jejak kejahatan siber yang dilakukan sehingga diperlukan forensik digital untuk menemukan bukti tersebut. Salah satu forensik digital adalah forensik komputer yang terfokus pada data di dalam atau terkait dengan komputer itu sendiri. Data yang di forensik umumnya tersimpan pada Computer Data Storage (Penyimpanan Data Komputer), yang dapat berupa Hard Disk Drive (HDD), Solid State Drive (SSD), serta SD Card. Ketiga jenis media penyimpanan tersebut memiliki karakteristik yang berbeda sehingga perilaku ketiga media tersebut saat recovery data pada proses forensik juga berbeda.
Skenario penghapusan data umum terjadi di dunia forensik digital. Namun, data yang terhapus belum tentu sepenuhnya hilang. Melalui proses delete normal, ruang yang ditempati data tersebut ditandai oleh sistem bahwa ruang dapat ditempati oleh data baru. Berbeda dengan delete, secure delete merupakan proses penghapusan data sedemikian rupa sehingga data tidak bisa dikembalikan. Salah satu cara untuk secure delete adalah dengan menggunakan software Eraser yang menimpa (overwrite) data dengan pola tertentu. Oleh karena itu, penulis berinisiatif melakukan penelitian mengenai tingkat
v keberhasilan recovery data yang dihapus dengan delete maupun secure delete pada tiga Computer Data Storage berupa HDD, SSD, dan SD Card pada sistem operasi Windows 10.
Penelitian dilakukan dengan merencanakan skenario yang kemudian diikuti oleh penghapusan data dengan delete dan secure delete pada HDD, SSD, serta SD Card. Setelahnya, dilakukan imaging, mounting dan validasi image dengan menyesuaikan hash pada image dan file asli. Apabila image telah valid, dilaksanakan recovery data dengan Recuva. Kemudian hasil recovery data dianalisis dan ditarik kesimpulan. Dari enam skenario yang dieksekusi, tiga skenario merupakan skenario delete biasa, yaitu skenario dengan tombol delete, skenario Quick Format, dan Full Format dan skenario secure delete, yaitu skenario Russian GOST, skenario AFSSI-5020 dan skenario German VSITR. Dalam skenario delete biasa, data dapat di-recover dengan persentase rata-rata di atas 56%. Sementara dalam ketiga skenario secure delete, data tidak ada yang dapat di-recover.
==============================================================================================================================
Along with digitalization, cyber crime cases in Indonesia also increased. In handling cyber crime cases, it is not uncommon for perpetrators to erase evidence as well as traces of cyber crimes committed so digital forensics are needed to find the evidence. One of the digital forensics is computer forensics that focuses on data inside or related to the computer itself. Forensic data is generally stored in Computer Data Storage, which can be Hard Disk Drive (HDD), Solid State Drive (SSD), and SD Card. The three types of storage media have different characteristics so that the behavior of the three media when data recovery is done in forensic processes is also different. Data deletion scenarios are common in the world of digital forensics. However, data that is deleted is not necessarily completely lost. Through the normal delete process, the space occupied by the data is marked by the system so that space can be occupied by new data. Unlike delete, secure delete is the process of deleting data in such a way that data cannot be returned. One way to secure delete is to use Eraser software that overwrites data with a certain pattern. Therefore, the author took the initiative to conduct a study on the success rate of data recovery that was deleted with delete and secure delete on three Computer Data Storage in the form of HDD, SSD and SD Card on the Windows 10 operating system. The study was conducted by planning a scenario which was then followed by deleting data with delete and secure delete on the HDD, SSD, and SD Card. After that, imaging and validation is done by adjusting the hash on the original image and file. If the image is valid, data recovery is performed with Recuva. Then the data recovery results are analyzed and conclusions drawn. Of the six scenarios executed, three scenarios are the normal delete scenario, namely the scenario with the delete button, the Quick Format scenario, and Full Format and the secure delete scenario, namely the Russian GOST scenario, AFSSI-5020 scenario and the German VSITR scenario. In the normal delete scenario, data can be recovered with an average percentage above 56%. While in the three secure delete scenarios, there is no data that can be recovered.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | Secure Delete, Recovery Data, Hard Disk Drive (HDD), Solid State Drive (SSD), SD Card, Recuva |
| Subjects: | Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science) T Technology > T Technology (General) |
| Divisions: | Faculty of Information and Communication Technology > Information Systems > 57201-(S1) Undergraduate Thesis |
| Depositing User: | Anggada Sakti Pamungkas |
| Date Deposited: | 23 Jul 2026 08:56 |
| Last Modified: | 23 Jul 2026 08:56 |
| URI: | http://repository.its.ac.id/id/eprint/65444 |
Actions (login required)
![]() |
View Item |
