• DocumentCode
    2397294
  • Title

    The Rules of Time on NTFS File System

  • Author

    Chow, K.P. ; Law, Frank Y W ; Kwan, Michael Y.K. ; Lai, Pierre K.Y.

  • Author_Institution
    Hong Kong Univ.
  • fYear
    2007
  • fDate
    10-12 April 2007
  • Firstpage
    71
  • Lastpage
    85
  • Abstract
    With the rapid development and popularity of IT technology, criminals and mischievous computer users are given avenues to commit crimes and malicious activities. As forensic science has long been used to resolve legal disputes regarding different branches of science, computer forensics is developed naturally in the aspects of computer crimes or misbehaviors. In computer forensics, temporal analysis plays a significant role in the reconstruction of events or crimes. Indeed, temporal analysis is one of the attractive areas in computer forensics that caused a large number of researches and studies. It is the purpose of this paper to focus on temporal analysis on NTFS file system and to project intuitional rules on the behavioral characteristics of related digital files
  • Keywords
    computer crime; file organisation; operating systems (computers); IT technology; NTFS file system; computer crimes; computer forensics; forensic science; mischievous computer users; Computer crime; Digital forensics; File systems; Information retrieval; Law; Legal factors; Performance analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systematic Approaches to Digital Forensic Engineering, 2007. SADFE 2007. Second International Workshop on
  • Conference_Location
    Bell Harbor, WA
  • Print_ISBN
    0-7695-2808-2
  • Electronic_ISBN
    0-7695-2808-2
  • Type

    conf

  • DOI
    10.1109/SADFE.2007.22
  • Filename
    4155351