Forensic Application-Fingerprinting Based on File System Metadata

IT Security Incident Management and IT Forensics(2013)

引用 14|浏览0
暂无评分
摘要
While much work has been invested in tools for aquisition and extraction of digital evidence, there are only few tools that allow for automatic event reconstruction. In this paper, we present a generic approach for forensic event reconstruction based on digital evidence from file systems. Our approach applies the idea of fingerprinting to changes made by applications in file system metadata. We present a system with which it is possible to automatically compute file system fingerprints of individual actions. Using NTFS timestamps as an example, we show that with our approach it is possible to automatically reconstruct actions performed by different applications even if the set of files accessed by those actions overlap.
更多
查看译文
关键词
file system,generic approach,ntfs timestamps,digital evidence,different application,automatic event reconstruction,file system metadata,forensic event reconstruction,file system fingerprint,individual action,fingerprint recognition,meta data,digital forensics
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要