DocumentCode :
3025793
Title :
A framework for computer forensics investigations involving Microsoft Vista
Author :
Hayes, Darren R. ; Qureshi, Shareq
Author_Institution :
Univ. of Pace, New York, NY
fYear :
2008
fDate :
2-2 May 2008
Firstpage :
1
Lastpage :
8
Abstract :
The technical environment continues to change and impact the work of digital investigations. This research provides a framework within which computer forensics investigators can take advantage of new or different types of evidence from Microsoftpsilas Vista operating system (ldquoVistardquo). Moreover, this paper will also indicate the many challenges that investigators will encounter when faced with the Vista platform. The focus herein will be on changes associated with new security, encryption and file restoration features. These features vary according to the version of Vista and these differences will also be discussed. This research will also detail the integrity of data recovery procedures through detailed experiments used to identify how data could be manipulated by a perpetrator in Vista as compared to previous versions of Microsoftpsilas operating systems. Ultimately, this paper will indicate that enhancements in security and encryption associated with Encrypted File System (EFS) as well as BitLocker Drive Encryption are very problematic for investigators. Vista has serious implications for computer forensics investigations. Nevertheless, this research will guide the digital investigator through the labyrinth of new challenges, to effect a more thorough investigation of digital evidence.
Keywords :
cryptography; operating systems (computers); BitLocker Drive Encryption; Encrypted File System; computer forensics investigations; computer security; data recovery procedures; encryption; Computer security; Cryptography; Data security; File systems; Forensics; Internet; Operating systems; Postal services; Protection; Universal Serial Bus; BitLocker; Computer Forensics; Computer Security; Encryption; Operating Systems; Vista;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems, Applications and Technology Conference, 2008 IEEE Long Island
Conference_Location :
Farmingdale, NY
Print_ISBN :
978-1-4244-1731-5
Electronic_ISBN :
978-1-4244-1732-2
Type :
conf
DOI :
10.1109/LISAT.2008.4638951
Filename :
4638951
Link To Document :
بازگشت