DocumentCode
2397294
Title
The Rules of Time on NTFS File System
Author
Chow, K.P. ; Law, Frank Y W ; Kwan, Michael Y.K. ; Lai, Pierre K.Y.
Author_Institution
Hong Kong Univ.
fYear
2007
fDate
10-12 April 2007
Firstpage
71
Lastpage
85
Abstract
With the rapid development and popularity of IT technology, criminals and mischievous computer users are given avenues to commit crimes and malicious activities. As forensic science has long been used to resolve legal disputes regarding different branches of science, computer forensics is developed naturally in the aspects of computer crimes or misbehaviors. In computer forensics, temporal analysis plays a significant role in the reconstruction of events or crimes. Indeed, temporal analysis is one of the attractive areas in computer forensics that caused a large number of researches and studies. It is the purpose of this paper to focus on temporal analysis on NTFS file system and to project intuitional rules on the behavioral characteristics of related digital files
Keywords
computer crime; file organisation; operating systems (computers); IT technology; NTFS file system; computer crimes; computer forensics; forensic science; mischievous computer users; Computer crime; Digital forensics; File systems; Information retrieval; Law; Legal factors; Performance analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Systematic Approaches to Digital Forensic Engineering, 2007. SADFE 2007. Second International Workshop on
Conference_Location
Bell Harbor, WA
Print_ISBN
0-7695-2808-2
Electronic_ISBN
0-7695-2808-2
Type
conf
DOI
10.1109/SADFE.2007.22
Filename
4155351
Link To Document