首页> 外文会议>Systems, Applications and Technology Conference, 2009. LISAT '09 >Implications of Microsoft Vista operating system for computer forensics investigations
【24h】

Implications of Microsoft Vista operating system for computer forensics investigations

机译:Microsoft Vista操作系统对计算机取证调查的影响

获取原文

摘要

With the growing importance of computer-related evidence today, it is important for law enforcement, prosecutors and computer forensics investigators to understand changes in their technical environment that are impacting the discovery and nature of evidence. Microsoft's Vista (ldquoVistardquo) is one change that has brought new challenges for digital investigations, particularly relating to new mechanisms of encryption and general security. This paper will identify those challenges and prescribe possible solutions. More specifically this research proposes practical ways in which the digital investigator can retrieve critical file metadata, explore file systems and record log files. The focus of this paper will be on the changes to Microsoft's new technology file system (NTFS). In general, Vista has placed a greater emphasis on file sharing across the Internet so XML file formats are more pervasive. Security, and more specifically encryption, is more prevalent in Vista and so this paper will focus on changes to Windows Mail. Although there is no empirical evidence, it appears as though prosecutors heavily rely on electronic mail evidence. With the continuous expansion in size of flash memory, it was imperative to note changes to the digital footprint left by USB thumbdrives as well as the impact of Microsoft's new volatile memory expansion tool - readyboost. Log files are also a crucial source of evidence in computer forensics investigations and these are discussed in great detail as changes in Vista have changed the nature of this evidence. This research paper will discuss the relevance of changes to evidence in Vista by highlighting the use of certain evidentiary files in court cases. Finally, the implications of changes brought about by Vista will be made apparent through experiments conducted with bit-stream imaging tools utilized by law enforcement and other computer forensics examiners. Vista has notable implications for computer forensics investigations. H-nowever, this research will prepare the digital investigator for the transition to the Vista operating system and the transformation of digital evidence associated with this new platform.
机译:随着当今与计算机有关的证据的重要性日益提高,对于执法人员,检察官和计算机法证研究人员来说,了解其技术环境的变化会影响证据的发现和性质至关重要。微软的Vista(ldquovistardquo)是一项变化,它给数字调查带来了新的挑战,特别是与新的加密机制和一般安全性有关。本文将确定这些挑战并提出可能的解决方案。更具体地说,这项研究提出了一些实用的方法,使数字调查人员可以检索关键文件元数据,浏览文件系统并记录日志文件。本文的重点将放在对Microsoft新技术文件系统(NTFS)的更改上。通常,Vista更加注重通过Internet进行文件共享,因此XML文件格式更加普及。安全性,尤其是加密,在Vista中更为普遍,因此,本文将重点讨论Windows Mail的更改。尽管没有经验证据,但检察官似乎严重依赖电子邮件证据。随着闪存大小的不断扩展,必须注意USB拇指驱动器留下的数字占用空间的变化以及Microsoft新型易失性内存扩展工具readyboost的影响。日志文件也是计算机取证研究中重要的证据来源,随着Vista的更改改变了该证据的性质,对日志文件进行了详细讨论。本研究论文将重点介绍在法庭案件中某些证据档案的使用,从而讨论Vista中证据变更的相关性。最后,通过使用由执法机构和其他计算机取证检查员使用的位流成像工具进行的实验,可以清楚地看到Vista带来的变化的含义。 Vista对于计算机取证调查具有显着意义。从现在开始,这项研究将为数字调查人员为过渡到Vista操作系统和与此新平台相关的数字证据的转换做准备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号