• DocumentCode
    2646572
  • Title

    Design and Implementation of a Tool for System Restore Point Analysis

  • Author

    Yun, Sun-Mi ; Savoldi, Antonio ; Gubian, Paolo ; Kim, Yeog ; Lee, Seokhee ; Lee, Sangjin

  • Author_Institution
    Center for Inf. Security Technol., Korea Univ., Seoul
  • fYear
    2008
  • fDate
    15-17 Aug. 2008
  • Firstpage
    542
  • Lastpage
    546
  • Abstract
    When a digital investigation is carried out, the main goal of the forensic practitioner is to find out evidence related to a digital crime on the computer under examination. To make the situation more severe, the perpetrator might have destroyed the evidence, for instance, by deleting the software which has been used to commit illicit actions. Moreover, he/she might have used sophisticated anti-forensic techniques to deceive the forensic examination. Fortunately, on Windows XP-based computer systems, it is possible to observe such attack methods by means of system restore point (SRP) analysis. Although the suspect might have removed files or uninstalled applications related to a digital crime, it will be possible to find out traces by analyzing such SRP data structure. We have, therefore, developed an analysis tool that acquires information from the SRP database and analyzes it, by presenting results in a useful format for the forensic examiner. Finally, we have provided a case of study which exemplifies the implemented tool.
  • Keywords
    computer crime; operating systems (computers); systems analysis; Windows XP-based computer systems; digital crime; digital investigation; forensic practitioner; system restore point analysis; Data analysis; Data structures; Digital forensics; Digital signal processing; Information analysis; Multimedia systems; Process design; Random access memory; Signal design; Signal restoration;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligent Information Hiding and Multimedia Signal Processing, 2008. IIHMSP '08 International Conference on
  • Conference_Location
    Harbin
  • Print_ISBN
    978-0-7695-3278-3
  • Type

    conf

  • DOI
    10.1109/IIH-MSP.2008.256
  • Filename
    4604116