Time for Truth: Forensic Analysis of NTFS Timestamps

被引:5
|
作者
Galhuber, Michael [1 ]
Luh, Robert [1 ,2 ]
机构
[1] St Polten Univ Appl Sci, Polten, Austria
[2] Univ Vienna, Vienna, Austria
关键词
digital forensics; windows; NTFS; timestamps; anti-forensics;
D O I
10.1145/3465481.3470016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Timeline forgery a widely employed technique in computer antiforensics. Numerous freely available and easy-to-use tampering tools make it difficult for forensic scientists to collect legally valid evidence and reconstruct a credible timeline. At the same time, the large number of possible file operations performed by a genuine user can result in a wide variety of timestamp patterns that pose a challenge when reconstructing a chain of events, especially since application-specific discrepancies are often disregarded. In this paper, we investigate timestamp patterns resulting from common user operations in NTFS, providing a much needed update to the Windows time rules derived from older experiments. We show that specific applications can cause deviations from expected behavior and provide analysts with a comprehensive set of behavioral rules for all permissible NTFS file operations. Finally, we analyze the effect and efficacy of 7 third party timestamp forgery tools as well as a custom PowerShell solution, and highlight forensic artifacts pointing at data falsification.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Moving Beyond Formal Truth Practices and Forensic Truth in the Syrian Conflict: How Informal Truth Practices Contribute to Thicker Understandings of Truth
    Herremans, Brigitte
    Destrooper, Tine
    SOCIAL & LEGAL STUDIES, 2023, 32 (04) : 519 - 539
  • [42] Truth in forensic psychiatry: A cultural response to Gutheil and colleagues
    Griffith, EEH
    JOURNAL OF THE AMERICAN ACADEMY OF PSYCHIATRY AND THE LAW, 2003, 31 (04): : 428 - 431
  • [43] A Regular Pattern of Timestamps Between Machines with Built-in System Time
    Wirastuti, Ni Made Ary Esta Dewi
    Saputra, Komang Oka
    Teng, Wei -Chung
    JOURNAL OF COMMUNICATIONS SOFTWARE AND SYSTEMS, 2023, 19 (02) : 126 - 135
  • [44] A Time of Arrival Estimator Based on Multiple Timestamps for Digital PET Detectors
    Braga, Leo H. C.
    Gasparini, Leonardo
    Stoppa, David
    2012 IEEE NUCLEAR SCIENCE SYMPOSIUM AND MEDICAL IMAGING CONFERENCE RECORD (NSS/MIC), 2012, : 1250 - 1252
  • [45] Dickens's Forensic Realism: Truth, Bodies, Evidence
    Nogue, Kathryn
    VICTORIOGRAPHIES-A JOURNAL OF NINETEENTH-CENTURY WRITING 1790-1914, 2020, 10 (02): : 208 - 211
  • [46] Dickens's Forensic Realism: Truth, Bodies, Evidence
    Schramm, Jan-Melissa
    DICKENS QUARTERLY, 2017, 34 (04) : 361 - 363
  • [47] Dickens's Forensic Realism: Truth, Bodies, Evidence
    Tambling, Jeremy
    DICKENSIAN, 2017, 113 (502): : 178 - 180
  • [48] Dickens's Forensic Realism: Truth, Bodies, Evidence
    Pond, Kristen
    VICTORIAN STUDIES, 2018, 60 (04) : 682 - 684
  • [49] Time Synchronization between SOKUIKI Sensor and Host Computer using Timestamps
    Carballo, Alexander
    Hara, Yoshitaka
    Kawata, Hirohiko
    Yoshida, Tomoaki
    Ohya, Akihisa
    Yuta, Shin'ichi
    2008 IEEE INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INTEGRATION FOR INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2008, : 416 - +
  • [50] The time shift between the neutron and γ-ray timestamps in organic stilbene scintillator
    Prusachenko, P. S.
    Bobrovsky, T. L.
    Bondarenko, I. P.
    Gurbich, A. F.
    Ketlerov, V. V.
    Khromyleva, T. A.
    Khryachkov, V. A.
    Poryvaev, V. J.
    Kobets, U. A.
    NUCLEAR INSTRUMENTS & METHODS IN PHYSICS RESEARCH SECTION A-ACCELERATORS SPECTROMETERS DETECTORS AND ASSOCIATED EQUIPMENT, 2021, 1002