File System Forensic Analysis
The Rules of Time on NTFS File System
SADFE '07 Proceedings of the Second International Workshop on Systematic Approaches to Digital Forensic Engineering
Analysis of Time Information for Digital Investigation
NCM '09 Proceedings of the 2009 Fifth International Joint Conference on INC, IMS and IDC
Time and date issues in forensic computing-a case study
Digital Investigation: The International Journal of Digital Forensics & Incident Response
Hi-index | 0.00 |
Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.