Reconstructing Timelines: From NTFS Timestamps to File Histories

被引:1
|
作者
Bouma, Jelle [1 ]
Jonker, Hugo [1 ]
van der Meer, Vincent [2 ]
van den Aker, Eddy [2 ]
机构
[1] Open Univ Netherlands, Heerlen, Netherlands
[2] Zuyd Univ Appl Sci, Heerlen, Netherlands
关键词
Digital forensics; Timestamps; File history; Timelines;
D O I
10.1145/3600160.3605027
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
File history facilitates the creation of a timeline of attributed events, which is crucial in digital forensics. Timestamps play an important role for determining what happened to a file. Previous studies into leveraging timestamps to determine file history focused on identification of the last operation applied to a file. In contrast, in this paper, we determine all possible file histories given a file's current NTFS timestamps. That is, we infer all possible sequences of file system operations which culminate in the file's current NTFS timestamps. This results in a tree of timelines, with root node the current file state. Our method accounts for various forms of timestamp forgery. We provide an implementation of this method that depicts possible histories graphically.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] De-Wipimization: Detection of data wiping traces for investigating NTFS file system
    Oh, Dong Bin
    Park, Kyung Ho
    Kim, Huy Kang
    COMPUTERS & SECURITY, 2020, 99
  • [42] RECONSTRUCTING REPRODUCTIVE HISTORIES OF BLACK BEARS FROM THE INCREMENTAL LAYERING IN DENTAL CEMENTUM
    COY, PL
    GARSHELIS, DL
    CANADIAN JOURNAL OF ZOOLOGY-REVUE CANADIENNE DE ZOOLOGIE, 1992, 70 (11): : 2150 - 2160
  • [43] Reconstructing taphonomic histories using histological analysis
    Turner-Walker, Gordon
    Jans, Miranda
    PALAEOGEOGRAPHY PALAEOCLIMATOLOGY PALAEOECOLOGY, 2008, 266 (3-4) : 227 - 235
  • [44] POPULATION PROFILES AS A MEANS FOR RECONSTRUCTING DEMOGRAPHIC HISTORIES
    VALAORAS, VG
    POPULATION, 1959, 14 (04): : 616 - 616
  • [45] Shattered past: Reconstructing German histories.
    Black, P
    GERMAN STUDIES REVIEW, 2004, 27 (03) : 669 - 670
  • [46] Reconstructing Histories of Complex Gene Clusters on a Phylogeny
    Vinar, Tomas
    Brejova, Brona
    Song, Giltae
    Siepel, Adam
    COMPARATIVE GENOMICS, PROCEEDINGS, 2009, 5817 : 150 - +
  • [47] Reconstructing Histories of Complex Gene Clusters on a Phylogeny
    Vinar, Tomas
    Brejova, Brona
    Song, Giltae
    Siepel, Adam
    JOURNAL OF COMPUTATIONAL BIOLOGY, 2010, 17 (09) : 1267 - 1279
  • [48] Shattered past: Reconstructing German histories.
    Weitz, ED
    SLAVIC REVIEW, 2004, 63 (01) : 150 - 151
  • [49] Comparative Study of Wear-leveling in Solid-State Drive with NTFS File System
    Neyaz, Ashar
    Zhou, Bing
    Karpoor, Narasimha
    2019 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2019, : 4294 - 4298
  • [50] Learning from Contagion (Without Timestamps)
    Amin, Kareem
    Heidari, Hoda
    Kearns, Michael
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 32 (CYCLE 2), 2014, 32 : 1845 - 1853