Back to Search
Start Over
Deleted file fragment dating by analysis of allocated neighbors.
- Source :
- Digital Investigation; Apr2019 Supplement, Vol. 28, pS60-S67, 8p
- Publication Year :
- 2019
-
Abstract
- Timestamps play a substantial role during digital forensic investigations and address two main objectives. First, they serve as a primary culling criterion to reduce the amount of digital evidence subject to analysis. Second, timestamps are the sole feature that allows reliable reconstruction of time-lines and they assist in locating temporal anomalies. File fragments, typically from previously deleted or relocated content, are often useful, especially when intact files are unavailable. Such fragments rarely contain embedded timestamps or have file-system timestamp information, which renders them less useful. In this work, we investigate and propose a framework for determining a time-window for deleted file fragments that are typically found in un-allocated space and file slack. We hypothesize that using the known temporal state of neighboring clusters allows us to derive a date-and-time range for when the file fragment was first written to media until it was subsequently deleted. [ABSTRACT FROM AUTHOR]
- Subjects :
- ELECTRONIC evidence
FORENSIC sciences
TIMESTAMPS
CONTENT analysis
FILES (Records)
Subjects
Details
- Language :
- English
- ISSN :
- 17422876
- Volume :
- 28
- Database :
- Supplemental Index
- Journal :
- Digital Investigation
- Publication Type :
- Academic Journal
- Accession number :
- 136071070
- Full Text :
- https://doi.org/10.1016/j.diin.2019.01.015