Analysis of changes in file time attributes with file manipulation

Jewan Bang, Byeongyeong Yoo, Sangjin Lee

    Research output: Contribution to journalArticlepeer-review

    15 Citations (Scopus)

    Abstract

    Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.

    Original languageEnglish
    Pages (from-to)135-144
    Number of pages10
    JournalDigital Investigation
    Volume7
    Issue number3-4
    DOIs
    Publication statusPublished - 2011 Apr

    Bibliographical note

    Funding Information:
    This research was supported by Bio R&D program through the National Research Foundation of Korea funded by the Ministry of Education, Science and Technology (20100020634).

    Keywords

    • Digital forensics
    • Filesystem
    • NTFS
    • Timestamp
    • Windows

    ASJC Scopus subject areas

    • Pathology and Forensic Medicine
    • Information Systems
    • Computer Science Applications
    • Medical Laboratory Technology
    • Law

    Fingerprint

    Dive into the research topics of 'Analysis of changes in file time attributes with file manipulation'. Together they form a unique fingerprint.

    Cite this