Back to Search Start Over

Deleted file fragment dating by analysis of allocated neighbors.

Authors :
Bahjat, Ahmed A.
Jones, Jim
Source :
Digital Investigation; Apr2019 Supplement, Vol. 28, pS60-S67, 8p
Publication Year :
2019

Abstract

Timestamps play a substantial role during digital forensic investigations and address two main objectives. First, they serve as a primary culling criterion to reduce the amount of digital evidence subject to analysis. Second, timestamps are the sole feature that allows reliable reconstruction of time-lines and they assist in locating temporal anomalies. File fragments, typically from previously deleted or relocated content, are often useful, especially when intact files are unavailable. Such fragments rarely contain embedded timestamps or have file-system timestamp information, which renders them less useful. In this work, we investigate and propose a framework for determining a time-window for deleted file fragments that are typically found in un-allocated space and file slack. We hypothesize that using the known temporal state of neighboring clusters allows us to derive a date-and-time range for when the file fragment was first written to media until it was subsequently deleted. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
17422876
Volume :
28
Database :
Supplemental Index
Journal :
Digital Investigation
Publication Type :
Academic Journal
Accession number :
136071070
Full Text :
https://doi.org/10.1016/j.diin.2019.01.015