TY - GEN
T1 - Analysis of time information for digital investigation
AU - Bang, Jewan
AU - Yoo, Byeongyeong
AU - Kim, Jongsung
AU - Lee, Sangjin
PY - 2009
Y1 - 2009
N2 - In digital forensics, the creation time, last written time, and last accessed time of a file or folder are important factors that can indicate events that have affected a computer system. The form of the time information varies with the file system, and the information changes the features, depending on the users actions such as copy, transfer, or network transport of files. Specific changes in the time information may be of considerable help in analyzing the users actions in the computer system. This paper analyzes changes in the time information of files and folders for different operations of the FAT and NTFS file systems and attempts to reconstruct the users actions. Further, it demonstrates the use of time information for digital evidence analysis by presenting a case study.
AB - In digital forensics, the creation time, last written time, and last accessed time of a file or folder are important factors that can indicate events that have affected a computer system. The form of the time information varies with the file system, and the information changes the features, depending on the users actions such as copy, transfer, or network transport of files. Specific changes in the time information may be of considerable help in analyzing the users actions in the computer system. This paper analyzes changes in the time information of files and folders for different operations of the FAT and NTFS file systems and attempts to reconstruct the users actions. Further, it demonstrates the use of time information for digital evidence analysis by presenting a case study.
KW - Digital investigation
KW - File system
KW - Time
KW - Windows
UR - http://www.scopus.com/inward/record.url?scp=73549099132&partnerID=8YFLogxK
U2 - 10.1109/NCM.2009.258
DO - 10.1109/NCM.2009.258
M3 - Conference contribution
AN - SCOPUS:73549099132
SN - 9780769537696
T3 - NCM 2009 - 5th International Joint Conference on INC, IMS, and IDC
SP - 1858
EP - 1864
BT - NCM 2009 - 5th International Joint Conference on INC, IMS, and IDC
T2 - NCM 2009 - 5th International Joint Conference on Int. Conf. on Networked Computing, Int. Conf. on Advanced Information Management and Service, and Int. Conf. on Digital Content, Multimedia Technology and its Applications
Y2 - 25 August 2009 through 27 August 2009
ER -