首页> 外文期刊>International journal of digital crime and forensics >A New Timestamp Digital Forensic Method Using a Modified Superincreasing Sequence
【24h】

A New Timestamp Digital Forensic Method Using a Modified Superincreasing Sequence

机译:修改后的超递增序列的新时间戳数字取证方法

获取原文
获取原文并翻译 | 示例
           

摘要

This paper proposes a new digital forensic method using a modified superincreasing sequence. Timestamp changes by file commands in Windows NTFS file system are used for identifying what commands were executed and are a useful and a logical way for performing digital forensics. A superincreasing sequence is modified for the timestamp change patterns to make each timestamp pattern have a distinct value. The method has two functions; one is a timestamp change check function and the other is a forensic evaluation function. The former checks differences of timestamps between before and after command execution, and the latter produces a characteristic output by applying ten kinds of timestamp change patterns. According to the characteristic output, the kind of command that is executed is identified. By virtue of adopting the modified superincreasing sequence, the evaluation function could produce distinct characteristic output values and thereby provides a way to reconstruct executed file commands.
机译:本文提出了一种使用改进的超增序列的新数字取证方法。 Windows NTFS文件系统中文件命令的时间戳更改用于标识执行了哪些命令,并且是执行数字取证的有用且逻辑的方式。修改了时间戳更改模式的超增序列,以使每个时间戳模式都具有不同的值。该方法具有两个功能。一个是时间戳更改检查功能,另一个是法医评估功能。前者检查命令执行前后的时间戳差异,后者通过应用十种时间戳更改模式来产生特征输出。根据特征输出,确定执行的命令的种类。通过采用修改的超增序列,评估函数可以产生不同的特征输出值,从而提供一种重构执行的文件命令的方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号