...
首页> 外文期刊>Computers & Security >A computer forensic method for detecting timestamp forgery in NTFS
【24h】

A computer forensic method for detecting timestamp forgery in NTFS

机译:在NTFS中检测时间戳伪造的计算机取证方法

获取原文
获取原文并翻译 | 示例
           

摘要

In this paper, we present a computer forensic method for detecting timestamp forgeries in the Windows NTFS file system. It is difficult to know precisely that the timestamps have been changed by only examining the timestamps of the file itself. If we can find the past timestamps before any changes to the file are made, this can act as evidence of file time forgery. The log records operate on files and leave large amounts of information in the $LogFile that can be used to reconstruct operations on the files and also used as forensic evidence. Log record with 0x07/0x07 opcode in the data part of Redo/Undo attribute has timestamps which contain past-and-present timestamps. The past-and-present time-stamps can be decisive evidence to indicate timestamp forgery, as they contain when and how the timestamps were changed. We used file time change tools that can easily be found on Internet sites. The patterns of the timestamp change created by the tools are different compared to those of normal file operations. Seven file operations have ten timestamp change patterns in total by features of timestamp changes in the $STAND-ARD_INFORMATION attribute and the $FILE_NAME attribute. We made rule sets for detecting timestamp forgery based on using difference comparison between changes in timestamp patterns by the file time change tool and normal file operations. We apply the forensic rule sets for ".txt", ".docx" and ".pdf" file types, and we show the effectiveness and validity of the proposed method. The importance of this research lies in the fact that we can find the past time in $LogFile, which gives decisive evidence of timestamp forgery. This makes the timestamp active evidence as opposed to simply being passive evidence.
机译:在本文中,我们提出了一种用于检测Windows NTFS文件系统中时间戳伪造的计算机取证方法。仅通过检查文件本身的时间戳就很难准确知道时间戳是否已更改。如果我们可以在对文件进行任何更改之前找到过去的时间戳,则可以作为伪造文件时间的证据。日志记录对文件进行操作,并在$ LogFile中保留大量信息,这些信息可用于重建文件操作并用作法医证据。重做/撤消属性的数据部分中操作码为0x07 / 0x07的日志记录具有包含过去和现在时间戳记的时间戳记。过去和现在的时间戳可以作为指示时间戳伪造的决定性证据,因为它们包含时间戳的更改时间和更改方式。我们使用了可以在Internet站点上轻松找到的文件时间更改工具。与普通文件操作相比,这些工具创建的时间戳更改模式不同。通过$ STAND-ARD_INFORMATION属性和$ FILE_NAME属性中的时间戳更改功能,七个文件操作总共具有十个时间戳更改模式。我们基于文件时间更改工具对时间戳模式的更改与正常文件操作之间的差异比较,制定了用于检测时间戳伪造的规则集。我们对“ .txt”,“。docx”和“ .pdf”文件类型应用取证规则集,并证明了该方法的有效性和有效性。这项研究的重要性在于,我们可以在$ LogFile中找到过去的时间,这为伪造时间戳提供了决定性的证据。这使时间戳记成为主动证据,而不是简单地成为被动证据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号