File Allocation Chronology and its Impact on Digital Forensics

2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC)(2023)

引用 1|浏览0
暂无评分
摘要
Event construction and sequencing are integral to the digital investigation process to build a sound case and admissible evidence. When dealing with deleting files, forged files, or file fragments, an investigator might not be able to consider many key artifacts because of forged or missing timestamps. In this work, we are investigating the applicability of using neighboring files to infer a timestamp of a key artifact using a real data set of over a thousand hard drives focusing on FAT drives. We performed an empirical study using the Real Data Set to understand the adjacent files' chronology and present our findings in this research.
更多
查看译文
关键词
forensic recovery,digital forensics,digital evidence,file slack,file fragment,event reconstruction
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要