Time for Truth: Forensic Analysis of NTFS Timestamps

被引:5
|
作者
Galhuber, Michael [1 ]
Luh, Robert [1 ,2 ]
机构
[1] St Polten Univ Appl Sci, Polten, Austria
[2] Univ Vienna, Vienna, Austria
关键词
digital forensics; windows; NTFS; timestamps; anti-forensics;
D O I
10.1145/3465481.3470016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Timeline forgery a widely employed technique in computer antiforensics. Numerous freely available and easy-to-use tampering tools make it difficult for forensic scientists to collect legally valid evidence and reconstruct a credible timeline. At the same time, the large number of possible file operations performed by a genuine user can result in a wide variety of timestamp patterns that pose a challenge when reconstructing a chain of events, especially since application-specific discrepancies are often disregarded. In this paper, we investigate timestamp patterns resulting from common user operations in NTFS, providing a much needed update to the Windows time rules derived from older experiments. We show that specific applications can cause deviations from expected behavior and provide analysts with a comprehensive set of behavioral rules for all permissible NTFS file operations. Finally, we analyze the effect and efficacy of 7 third party timestamp forgery tools as well as a custom PowerShell solution, and highlight forensic artifacts pointing at data falsification.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] What is Truth? The Spiritual Quest of Forensic Psychiatry
    Norko, Michael A.
    JOURNAL OF THE AMERICAN ACADEMY OF PSYCHIATRY AND THE LAW, 2018, 46 (01): : 10 - 22
  • [32] Who's Time Is It Anyway? Investigating the Accuracy of Camera Timestamps
    Thomee, Bart
    Moreno, Jose G.
    Shamma, David A.
    PROCEEDINGS OF THE 2014 ACM CONFERENCE ON MULTIMEDIA (MM'14), 2014, : 909 - 912
  • [33] The Analysis of Post Sound through meaningful Experiences triggered by Feelings for the forensic Truth Determination
    Leonhardt, Curt
    ARCHIV FUR DIE GESAMTE PSYCHOLOGIE, 1941, 109 (2-3): : 297 - 311
  • [34] Time-Discounting Convolution for Event Sequences with Ambiguous Timestamps
    Katsuki, Takayuki
    Osogami, Takayuki
    Koseki, Akira
    Ono, Masaki
    Kudo, Michiharu
    Makino, Masaki
    Suzuki, Atsushi
    2018 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2018, : 1085 - 1090
  • [35] Securing the Precision Time Protocol (PTP) Against Fake Timestamps
    Moussa, Bassam
    Robillard, Chantale
    Zugenmaier, Alf
    Kassouf, Marthe
    Debbabi, Mourad
    Assi, Chadi
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (02) : 278 - 281
  • [36] An Empirical Study of the NTFS Cluster Allocation Behavior Over Time
    Karresand, Martin
    Dyrkolbotn, Geir Olav
    Axelsson, Stefan
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2020, 33 (33):
  • [37] Time for truth
    不详
    NATION, 2004, 278 (14) : 3 - 3
  • [38] TIME FOR TRUTH
    不详
    NEW REPUBLIC, 1967, 156 (24) : 7 - 7
  • [39] A 'time for truth'
    Reeves, R
    AMERICAN HERITAGE, 2004, 55 (06) : 73 - 73
  • [40] Truth and time
    Misiuna, K
    LVOV-WARSAW SCHOOL AND CONTEMPORARY PHILOSOPHY, 1998, 273 : 199 - 208