Time for Truth: Forensic Analysis of NTFS Timestamps

被引:5
|
作者
Galhuber, Michael [1 ]
Luh, Robert [1 ,2 ]
机构
[1] St Polten Univ Appl Sci, Polten, Austria
[2] Univ Vienna, Vienna, Austria
关键词
digital forensics; windows; NTFS; timestamps; anti-forensics;
D O I
10.1145/3465481.3470016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Timeline forgery a widely employed technique in computer antiforensics. Numerous freely available and easy-to-use tampering tools make it difficult for forensic scientists to collect legally valid evidence and reconstruct a credible timeline. At the same time, the large number of possible file operations performed by a genuine user can result in a wide variety of timestamp patterns that pose a challenge when reconstructing a chain of events, especially since application-specific discrepancies are often disregarded. In this paper, we investigate timestamp patterns resulting from common user operations in NTFS, providing a much needed update to the Windows time rules derived from older experiments. We show that specific applications can cause deviations from expected behavior and provide analysts with a comprehensive set of behavioral rules for all permissible NTFS file operations. Finally, we analyze the effect and efficacy of 7 third party timestamp forgery tools as well as a custom PowerShell solution, and highlight forensic artifacts pointing at data falsification.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Development of an Anti-Forensic Tool for Hiding Message in a Directory Index of NTFS
    Cho, Gyu-Sang
    2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2015, : 144 - 145
  • [22] On Real-Time Monitoring with Imprecise Timestamps
    Basin, David
    Klaedtke, Felix
    Marinovic, Srdjan
    Zéalinescu, Eugen
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2014, 8734 : 193 - 198
  • [23] Timestamps-Based Multichannel Time Interval Counter
    Szplet, R.
    Kwiatkowski, P.
    Rozyc, K.
    Jachna, Z.
    Sondej, T.
    Sawicki, M.
    PROCEEDINGS OF THE 45TH ANNUAL PRECISE TIME AND TIME INTERVAL SYSTEMS AND APPLICATIONS MEETING, 2013, : 158 - 162
  • [24] Commentary: Forensic Education and the Quest for Truth
    Ciccone, J. Richard
    JOURNAL OF THE AMERICAN ACADEMY OF PSYCHIATRY AND THE LAW, 2013, 41 (01): : 33 - 37
  • [25] Veterinary Forensic Pathology: The Search for Truth
    McDonough, S. P.
    McEwen, B. J.
    VETERINARY PATHOLOGY, 2016, 53 (05) : 875 - 877
  • [26] Empire on trial: the forensic appearance of truth
    Gordillo, Gaston
    ENVIRONMENT AND PLANNING D-SOCIETY & SPACE, 2015, 33 (02): : 382 - 388
  • [27] Multivariate time series classification with crucial timestamps guidance
    Zhang, Da
    Gao, Junyu
    Li, Xuelong
    EXPERT SYSTEMS WITH APPLICATIONS, 2024, 255
  • [28] The time is now for ubiquitous forensic mtMPS analysis
    Canale, Lauren C.
    Parson, Walther
    Holland, Mitchell M.
    WILEY INTERDISCIPLINARY REVIEWS: FORENSIC SCIENCE, 2022, 4 (01):
  • [29] Handling exp, x (and timestamps) in protocol analysis
    Zunino, Roberto
    Degano, Pierpaolo
    FOUNDATIONS OF SOFTWARE SCIENCE AND COMPUTATION STRUCTURES, PROCEEDINGS, 2006, 3921 : 413 - 427
  • [30] NTFS Directory Index Analysis for Computer Forensics
    Cho, Gyu-Sang
    2015 9TH INTERNATIONAL CONFERENCE ON INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING IMIS 2015, 2015, : 441 - 446