Vis enkel innførsel

dc.contributor.authorPorter, Kyle
dc.contributor.authorNordvik, Rune
dc.contributor.authorToolan, Fergus
dc.contributor.authorAxelsson, Stefan
dc.date.accessioned2022-10-14T08:13:41Z
dc.date.available2022-10-14T08:13:41Z
dc.date.created2021-08-16T14:51:34Z
dc.date.issued2021
dc.identifier.citationForensic Science International: Digital Investigation. 2021, 38 1-13.en_US
dc.identifier.issn2666-2825
dc.identifier.urihttps://hdl.handle.net/11250/3026085
dc.description.abstractWhile file carving is a popular and effective method for extracting file content from unallocated space in a forensic image, it can be time consuming to carve for the wide variety of possible file signatures. Furthermore, file carving does not connect the discovered file to its filesystem metadata. These limitations of file carving are the advantages of Generic Metadata Time Carving, in which filesystem metadata is searched for by first finding repeated co-located timestamps using a potential timestamp carving algorithm. The potential metadata is verified by a filesystem specific parser, and the pointer within the metadata to the file data may allow for full file recovery. Currently, a limitation of the Generic Metadata Time Carving method is that it will only find metadata records that have multiple equivalent timestamps, thus missing metadata records and files with differing, but very similar, timestamps. Therefore, in order to improve the recall of the Generic Metadata Time Carving methodology, we have designed and implemented a prefix matching potential timestamp carving algorithm. We apply our experiments to realistic NTFS and Ext4 forensic images, in which we compare the precision and recall results for differing prefix lengths. Our results indicate that using prefix-based potential timestamp carving can yield significantly greater recall for extracting filesystem metadata records, with little to no reduction in precision as compared to the original exact potential timestamp carving method.en_US
dc.language.isoengen_US
dc.publisherElsevieren_US
dc.relation.urihttps://github.com/TimestampPrefixCarving/Peer-Review
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.titleTimestamp prefix carving for filesystem metadata extractionen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionpublishedVersionen_US
dc.source.pagenumber1-13en_US
dc.source.volume38en_US
dc.source.journalForensic Science International: Digital Investigationen_US
dc.identifier.doi10.1016/j.fsidi.2021.301266
dc.identifier.cristin1926367
dc.relation.projectNorges forskningsråd: 248094/O70en_US
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode1


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse 4.0 Internasjonal