Analysis of changes in file time attributes with file manipulation
- Authors
- Bang, Jewan; Yoo, Byeongyeong; Lee, Sangjin
- Issue Date
- 4월-2011
- Publisher
- ELSEVIER SCI LTD
- Keywords
- Digital forensics; Timestamp; Windows; NTFS; Filesystem
- Citation
- DIGITAL INVESTIGATION, v.7, no.3-4, pp.135 - 144
- Indexed
- SCIE
SCOPUS
- Journal Title
- DIGITAL INVESTIGATION
- Volume
- 7
- Number
- 3-4
- Start Page
- 135
- End Page
- 144
- URI
- https://scholar.korea.ac.kr/handle/2021.sw.korea/112698
- DOI
- 10.1016/j.diin.2010.12.001
- ISSN
- 1742-2876
- Abstract
- Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results. (C) 2010 Elsevier Ltd. All rights reserved.
- Files in This Item
- There are no files associated with this item.
- Appears in
Collections - School of Cyber Security > Department of Information Security > 1. Journal Articles
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.