Vis enkel innførsel

dc.contributor.authorWillassen, Svein Yngvarnb_NO
dc.date.accessioned2014-12-19T14:11:30Z
dc.date.available2014-12-19T14:11:30Z
dc.date.created2008-04-29nb_NO
dc.date.issued2008nb_NO
dc.identifier124235nb_NO
dc.identifier.isbn978-82-471-6230-9nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/261472
dc.description.abstractThis work explores how the evidential value of digital timestamps can be enhanced by taking a hypothesis based approach to the investigation of digital timestamps. It defines the concepts of clock hypotheses, timestamps and causality in digital systems. These concepts are utilized to develop methods that can be used in an investigation to test a clock hypothesis for consistency with timestamps found in an actual investigation, given causality between specific events occurring in the investigated system. Common storage systems are explored for the identification of causality between the events of information storage. By using a logic programming variant of predicate calculus, a formalism for modelling the relationship between events and timestamp updating is defined. This formalism can be used to determine invariants in digital systems. Invariants and causality relations can be used to check a clock hypothesis for consistency with timestamp evidence. These methods can be utilized in software for digital investigation. By checking the large number of timestamps typically occurring on a digital medium, the methods can assist with the justification of a clock hypothesis, and thereby increase the confidence in specific timestamps found during the investigation. Previously, the checking of timestamps has relied upon the existence of timestamps from other evidence sources. With the methods defined in this work, justification of timestamp interpretation can be achieved without having to rely on timestamps from other sources of evidence. The methods developed in this work were implemented in a clock hypothesis consistency checker. This checker was tested in an experiment where subjects were asked to antedate a document. The checker was found to be able to produce evidence supporting a hypothesis that the document was antedated.nb_NO
dc.languageengnb_NO
dc.publisherFakultet for informasjonsteknologi, matematikk og elektroteknikknb_NO
dc.relation.ispartofseriesDoktoravhandlinger ved NTNU, 1503-8181; 2008:19nb_NO
dc.titleMethods for Enhancement of Timestamp Evidence in Digital Investigationsnb_NO
dc.typeDoctoral thesisnb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel