A method for reading volume shadow backup data
By analyzing the shadow backup data structure and judging the relevant descriptors, extracting and merging the shadow backup data, the problem of the inability to read the shadow backup data in the existing technology is solved, and data reading is realized independent of the functional interface of the Windows operating system.
Patent Information
- Application Number
- CN202210735162.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-27
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-06-27
AI Technical Summary
The prior art cannot read data from shadow backup files without using the functional interface of the Windows operating system itself, especially when shadow backup files are encountered in disk image files.
By analyzing the file format and data structure of shadow backup storage, the shadow backup data is judged and extracted, including judging data block descriptors, superimposing data blocks, jumping data blocks, snapshot stack top, bitmap marks, etc., and output shadow backup data after merging.
It realizes the effective reading of shadow backup data without relying on the functional interface of the Windows operating system, solving the problem that the existing technology cannot read shadow backup data.
Smart Images

Figure CN115373897B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the field of electronic evidence collection and relates to a method for reading volume shadow backup data. Background Art
[0002] Although there are many tools and papers that study volume shadow technology and extract data from volume shadow backup files, they are all done with the help of the functional interface (API) provided by the Windows operating system itself. The existing technology does not know the file format and data structure of the volume shadow backup, nor does it know how to read data from the volume shadow backup without the help of the functional interface of the Windows operating system itself.
[0003] In electronic evidence collection, disk image files are often analyzed, and there will be cases where disk image files contain shadow backup files. In this case, the function interface provided by the Windows operating system itself cannot be used to read the data in the shadow backup file in the disk image, because the shadow backup file can only be read by the shadow file system. Therefore, the only way is to analyze the format of the shadow backup file to figure out the data reading method and further read data from the shadow backup. Summary of the invention
[0004] In view of the technical problems of the prior art, the present invention provides a method for reading volume shadow backup data:
[0005] By analyzing the file format and data structure of the shadow backup storage, it is determined whether there is a data block descriptor corresponding to the current data block, whether the current data block is superimposed and whether the current backup storage is at the top of the snapshot stack, whether the current data block is a jump data block and there is a next backup storage, whether there is a next backup storage, whether there is a reverse-mapped jump data block descriptor, and whether the current backup storage is at the top of the snapshot stack and whether the current data block is marked by a bitmap. The shadow backup data of each part is extracted accordingly according to the results of each judgment, and finally the shadow backup data is output after being merged.
[0006] Related terms and explanations:
[0007] Block: data block (the size of the shadow value is 16KB)
[0008] Block descriptors: data block descriptors (data structures that describe changes in backup block data)
[0009] Overlay block descriptors: Overlay block descriptors (describes the data structure of smaller area data changes within the backup block, usually 512 bytes of data area data changes)
[0010] Forwarder block descriptors: Jump data block descriptors (describes that the backed-up block is not in the store, but in its original location on the disk volume, which is equivalent to the backed-up block being placed in the store)
[0011] Header: Shadow header data structure (contains some structural information of the shadow)
[0012] Catalog: backup storage directory (stores the index information of backup storage)
[0013] Store: backup storage (where the shadow volume actually stores the backup data)
[0014] Store information: backup storage information (meta-information data structure of backup storage)
[0015] Store block list backup storage data block list (data blocks of backed-up data on disk volumes)
[0016] Store rang list: list of backup storage address ranges (disk data blocks used by the backup storage itself)
[0017] Original offset: original offset (the original offset of the backed-up data block on the disk volume)
[0018] Relative store data offset: relative offset (the storage offset of the backed-up data block in the backup storage)
[0019] GUID Global Identifier: (a data structure unique identifier)
[0020] Current volume: current volume (disk volume currently in use)
[0021] Flags: Flags (indicates how to back up the data block, and the value determines the type of Block descriptors)
[0022] Bimap: Bitmap (indicates which backup storage is backed up in the backup storage)
[0023] Allocation bitmap: Allocated bitmap (identifies data blocks in 512-byte areas that are backed up to backup storage)
[0024] The shadow backup technology is based on disk volumes, not files on disks. So one shadow backup corresponds to one disk volume, and one disk volume corresponds to one shadow backup.
[0025] Volume shadow only supports disk volumes with NTFS file system.
[0026] The shadow volume manages data in the same way as the disk volume, based on 16KB blocks.
[0027] The shadow data structure is contained in the disk volume data structure.
[0028] The data structure of the shadow volume consists of three main parts:
[0029] 1.header
[0030] 2.catalog
[0031] 3.Stores
[0032] The three data structures are all included in the disk volume data structure, and their distribution on the disk volume is intuitively shown as follows: Figure 2 As shown:
[0033] The header is located at the offset 0x1e00 of the disk volume header structure. The shadow header contains a GUID identifier and the location offset of the catalog.
[0034] The Catalog structure consists of the following parts:
[0035] GUID Identifier
[0036] Creation time of the Store structure
[0037] The offset position of the Store structure in the volume
[0038] Store is the place where disk volume backup data is actually stored. A Store is actually a snapshot of a disk volume, but Store does not store all the data of the disk volume. Instead, Store tracks the blocks on each disk volume in the form of 16KB blocks. The blocks of the disk volume are backed up to Store only when the blocks on the disk volume are modified.
[0039] The Store consists of the following parts:
[0040] Store information
[0041] Store the current bitmap
[0042] The bitmap offset of the previous Store
[0043] Store block list
[0044] Store rang list
[0045] Store information contains information:
[0046] Store ID
[0047] Host name and service provider name
[0048] Store the current bitmap:
[0049] Each Store has a current bitmap, which indicates which 16KB block on the disk volume is currently being used (backed up) by this Store. If the bit of the corresponding block is set, it means that the block is not being used (backed up) by this Store.
[0050] The bitmap of the previous Store. This bitmap indicates the 16KB block on the disk volume that is being used (backed up) by the previous Store. If the bit of the corresponding block is set, it means that the block is not being used (backed up) by the previous Store. Not every Store has the bitmap of the previous Store. The first Store created does not have this value.
[0051] When we read the backup data in the Store, these two bitmaps can actually be ignored and the data in the Store block list can be read directly.
[0052] The Store rang list represents the blocks on the disk volume used by the Store itself.
[0053] The Store block list represents the blocks on the backed-up disk volume. The Store block list uses blockdescriptors to describe how to back up the blocks on the disk volume.
[0054] Block descriptors contain the following data parts:
[0055] Original offset (the original position of the backed-up block on the disk volume)
[0056] Relative store data offset (the location where the backup block is stored in the store)
[0057] Flags (flag bit, indicating how to back up the block)
[0058] allocation bitmap (used by Flags overlay)
[0059] Disk snapshot stack:
[0060] A disk volume may have multiple shadow backups, that is, multiple disk snapshots. One snapshot is one store, that is, there are multiple stores. Multiple stores are stored in a stack, that is, the most recent store is at the top of the stack, and the oldest store is at the bottom of the stack. Figure 3 As shown:
[0061] Current volume is the disk volume we are using, Store2 is our most recent snapshot, and Store1 is the oldest snapshot. Figure 3 As shown in the figure, all the changed data in the Current volume are backed up in the front Store. Block descriptors are used to describe how the data is backed up. Only by knowing how the data is backed up can we design an algorithm to read the data. Figure 3 We can also conclude that if we want to get the oldest snapshot Store1, we must apply the snapshot of Store2 to the Current volume, and then apply the snapshot of Store1 to the Current volume, so that we can get the Store1 snapshot.
[0062] Block descriptors have original offset and relative store data offset. We can restore the backed-up data back to the disk volume.
[0063] If the Flags in the block descriptors is set to 2, it means that this is an overlay block descriptors. Overlay is used to describe changes in an area smaller than a 16KB block. Usually it is a data change of a 512byteblock. And the allocation bitmap in the block descriptors is used to indicate that the 512byte block areas in this 16KB block have changed. These 512byte blocks are stored in the Relativestore data offset of the overlay block descriptors. When reading data in the Strore, you need to first apply the overlayblock descriptors to the 16KB blocks.
[0064] Reverse mapping: If the Flags in the block descriptors is set to 1, it means that this is a forwarder block descriptors. This means that the Relative store data offset in the data domain is equivalent to the Original offset. That is, the Original offset is mapped to the Relative store data offset, so the reverse mapping from the Relative store data offset to the Original offset also exists.
[0065] The method provided by the present invention comprises the following steps:
[0066] S000: Determine whether all data blocks of the current disk volume have been read. If yes, execute step S011; otherwise, execute step S001;
[0067] S001: according to the original offset of the current data block in the current disk volume, search in the backup storage data block list whether there is a data block descriptor corresponding to the current data block, if yes, execute step S002, otherwise, execute step S006;
[0068] S002: Determine whether the current data block is superimposed and whether the current backup storage is the top of the snapshot stack. If yes, execute step S003; otherwise, execute step S004;
[0069] S003: Read the data block according to the overlay data block descriptor, and then fill in the data block addressed by the original offset using the 512-byte data block addressed and read according to the mark of the allocated bitmap, and execute step S010;
[0070] S004: Determine whether the current data block is a jump data block and whether there is a next backup storage. If yes, execute step S010; otherwise, execute step S005;
[0071] S005: Read the current data block from the current disk volume according to the original offset, and execute step S010;
[0072] S006: Determine whether there is a next backup storage, if yes, execute step S010, otherwise execute step S007;
[0073] S007: Determine whether there is a reverse mapped jump data block descriptor, if yes, execute step S005, otherwise, execute step S008;
[0074] S008: Determine whether the current backup storage is at the top of the snapshot stack and whether the current data block is marked by the bitmap. If yes, execute step S005. Otherwise, it means that the current data block is in the backup storage and is not used, execute step S009.
[0075] S009: Fill the current data block with zeros and execute step S010;
[0076] S010: Read the next backup storage data block and execute step S000;
[0077] S011: Output the read volume shadow backup data.
[0078] Preferably, in step S002, the step of determining whether the current data block is superimposed comprises the following steps: determining whether the identification bit of the data block descriptor is 2, if so, indicating superposition, and vice versa.
[0079] Preferably, in step S003, the step of reading the data block according to the overlay data block descriptor comprises the following steps: using the original offset in the backup storage to address and read the data block.
[0080] Preferably, in step S003, the mark of the allocated bitmap is 1, indicating that the corresponding 512 bytes of data are backed up in the backup storage; the mark of the allocated bitmap is 0, indicating that the corresponding 512 bytes of data are not backed up in the backup storage.
[0081] Preferably, in step S004, the step of judging whether the current data block is a jump data block comprises the following steps: judging whether the identification bit of the data block descriptor is 1, if so, it indicates a jump data block, and vice versa.
[0082] The present invention has the following beneficial effects: it solves the technical problem in the prior art that the function interface provided by the Windows operating system itself cannot be used to read the volume shadow backup data in the disk image. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] Figure 1 A flow chart of the method provided by the present invention;
[0084] Figure 2 It is a schematic diagram of the data structure of header, catalog and Stores in the volume shadow of the present invention;
[0085] Figure 3 It is a schematic diagram of the data structure of the disk snapshot stack in the present invention. DETAILED DESCRIPTION
[0086] Figure 1 The flow chart of the method provided by the present invention is shown. Figure 1 As shown, the method of the present invention comprises the following steps:
[0087] S000: Determine whether all data blocks (Block) of the current disk volume have been read. If yes, execute step S011; otherwise, execute step S001;
[0088] S001: According to the original offset of the current data block in the current disk volume, search in the backup storage data block list whether there is a data block descriptor corresponding to the current data block; if yes, execute step S002; otherwise, execute step S006;
[0089] S002: Determine whether the current data block (Block) is superimposed and whether the current backup storage (Store) is the top of the snapshot stack. If yes, execute step S003; otherwise, execute step S004;
[0090] Specifically, the step of determining whether the current data block (Block) is superimposed includes the following steps: determining whether the flags of the data block descriptor (Block descriptors) is 2, if so, it indicates superposition, and vice versa.
[0091] S003: Read the data block (Block) according to the overlay block descriptors, and then fill in the data block (Block) addressed by the original offset (Original offset) according to the mark of the allocated bitmap (Allocation bitmap);
[0092] Specifically, the step of reading a data block (Block) according to the overlay block descriptors (Overlay block descriptors) includes the following steps: using the original offset (Original offset) in the backup storage (Store), addressing and reading the data block (Block).
[0093] In addition, the mark of the allocated bitmap is 1, indicating that the corresponding 512 bytes of data are backed up in the backup storage (Store); the mark of the allocated bitmap is 0, indicating that the corresponding 512 bytes of data are not backed up in the backup storage (Store).
[0094] S004: Determine whether the current data block (Block) is a forwarder block (Forwarder block) and whether there is a next backup storage (Store). If yes, execute step S010; otherwise, execute step S005;
[0095] Specifically, the step of determining whether the current data block (Block) is a forwarding data block (Forwarder block) includes the following steps: determining whether the flags of the data block descriptor (Block descriptors) is 1, if so, it indicates a forwarding data block (Forwarder block), and vice versa.
[0096] S005: Read the current data block (Block) from the current disk volume according to the original offset (Original offset), and execute step S010;
[0097] S006: Determine whether there is a next backup storage (Store), if yes, execute step S010, otherwise execute step S007;
[0098] S007: Determine whether there are forwarder block descriptors with reverse mapping, if yes, execute step S005, otherwise, execute step S008;
[0099] S008: Determine whether the current backup storage (Store) is at the top of the snapshot stack and whether the current data block (Block) is marked by the bitmap. If yes, execute step S005. Otherwise, it means that the current data block (Block) is in the backup storage (Store) and is not used, and execute step S009.
[0100] S009: Fill the current data block (Block) with zeros and execute step S010;
[0101] S010: Read the data block (Block) of the next backup storage (Store), and execute step S000;
[0102] S011: Output the read volume shadow backup data.
[0103] The method provided by the present invention solves the technical problem that there is no method for reading volume shadow backup data in the prior art.
[0104] It should be understood that the present invention is not limited to the above examples. For those skilled in the art, improvements or changes can be made based on the above description. All these improvements and changes should fall within the scope of protection of the claims attached to the present invention.
Claims
1. A method for reading shadow backup data, Features The following steps are involved: S000: Determine whether all data blocks of the current disk volume have been read. If yes, execute step S011; otherwise, execute step S001; S001: according to the original offset of the current data block in the current disk volume, search in the backup storage data block list whether there is a data block descriptor corresponding to the current data block, if yes, execute step S002, otherwise, execute step S006; S002: Determine whether the current data block is superimposed and whether the current backup storage is the top of the snapshot stack. If yes, execute step S003; otherwise, execute step S004; S003: Read the data block according to the overlay data block descriptor, and then fill in the data block addressed by the original offset using the 512-byte data block addressed and read according to the mark of the allocated bitmap, and execute step S010; S004: Determine whether the current data block is a jump data block and whether there is a next backup storage. If yes, execute step S010; otherwise, execute step S005; S005: Read the current data block from the current disk volume according to the original offset, and execute step S010; S006: Determine whether there is a next backup storage, if yes, execute step S010, otherwise execute step S007; S007: Determine whether there is a reverse mapped jump data block descriptor, if yes, execute step S005, otherwise, execute step S008; S008: Determine whether the current backup storage is at the top of the snapshot stack and whether the current data block is marked by the bitmap. If yes, execute step S005. Otherwise, it means that the current data block is in the backup storage and is not used, execute step S009. S009: Fill the current data block with zeros and execute step S010; S010: Read the next backup storage data block and execute step S000; S011: Output the read volume shadow backup data.
2. A method for reading shadow backup data according to claim 1, It is characterized in that In step S002, the step of determining whether the current data block is superimposed comprises the following steps: determining whether the identification bit of the data block descriptor is 2, if so, it indicates superposition, and vice versa.
3. A method for reading shadow backup data according to claim 1, It is characterized in that In step S003, the step of reading the data block according to the overlay data block descriptor includes the following steps: using the original offset in the backup storage to address and read the data block.
4. A method for reading volume shadow backup data according to claim 1, It is characterized in that In step S003, the mark of the allocated bitmap is 1, indicating that the corresponding 512 bytes of data are backed up in the backup storage; the mark of the allocated bitmap is 0, indicating that the corresponding 512 bytes of data are not backed up in the backup storage.
5. A method for reading shadow backup data according to claim 1, It is characterized in that In step S004, the step of judging whether the current data block is a jump data block includes the following steps: judging whether the identification bit of the data block descriptor is 1, if so, it indicates a jump data block, and vice versa.
Citation Information
Patent Citations
Volume-level backup method and volume-level backup device for ensuring consistency of file system data
CN110188068A
Volume shadow readable and writable disk volume backup method and system
CN114265726A