Vis enkel innførsel

dc.contributor.authorPorter, Kyle
dc.date.accessioned2020-10-28T10:30:15Z
dc.date.available2020-10-28T10:30:15Z
dc.date.created2020-10-01T11:14:51Z
dc.date.issued2020
dc.identifier.citationDigital Investigation. The International Journal of Digital Forensics and Incident Response. 2020, 33 .en_US
dc.identifier.issn1742-2876
dc.identifier.urihttps://hdl.handle.net/11250/2685461
dc.description.abstractRecovery of files can be a challenging task in file system investigations, and most carving techniques are based on file signatures or semantics within the file. However, these carving techniques often only recover the files, but not the metadata associated with the file. In this paper, we propose a novel, generic approach for carving metadata by searching for equal and co-located timestamps. The rationale is that there are some common metadata for files and directories within each file system. Our generic time carver provides potential timestamp locations for repeated timestamps in each metadata structure, identifying potential metadata for files. A semantic parser then filters the results with respect to the specific file system type. In our experiments, extraction of MFT entries in NTFS and inodes in Ext4 had near perfect precision for metadata entries with multiple equivalent timestamps, and for such metadata structures we obtained perfect recall for NTFS. For known file systems, we use the information found within identified metadata to recover files, and by recovering files and their associated metadata we increase the evidential value of recovered files.en_US
dc.language.isoengen_US
dc.publisherElsevieren_US
dc.relation.urihttps://github.com/reviewscientific2020/cPTS
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/deed.no*
dc.titleGeneric Metadata Time Carvingen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionpublishedVersionen_US
dc.source.pagenumber10en_US
dc.source.volume33en_US
dc.source.journalDigital Investigation. The International Journal of Digital Forensics and Incident Responseen_US
dc.identifier.doihttps://doi.org/10.1016/j.fsidi.2020.301005
dc.identifier.cristin1836068
dc.relation.projectNorges forskningsråd: ArsForensica project number 248094/O70en_US
dc.description.localcodehttps://doi.org/10.1016/j.fsidi.2020.301005 2666-2817/© 2020 The Author(s). Published by Elsevier Ltd on behalf of DFRWS. All rights reserved. This is an open access article under the CC BY-NC-ND license (http:// creativecommons.org/licenses/by-nc-nd/4.0/).en_US
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Attribution-NonCommercial-NoDerivatives 4.0 Internasjonal