Investigating file use and knowledge with Windows 10 artifacts

Investigating file use and knowledge with Windows 10 artifacts
复制标题

通过 Windows 10 工件调查文件使用情况和知识

DOI:
10.23919/mipro.2019.8756877
复制
发表时间:
2019
期刊:
2019 42nd International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)
影响因子:
--
通讯作者:
Damir Delija
Damir Delija
中科院分区:
--
文献类型:
--
作者:
A. Duranec;Davor Topolčić;K. Hausknecht;Damir Delija

文献摘要

被引文献

相似文献

Windows 10操作系统是当今使用最广泛的操作系统,包含许多用于管理计算机硬件和软件的程序和机制。从数字取证的角度来看,这些会产生有价值的用户活动记录。在取证世界中,这样的记录被称为Windows工件,它可以被描述为系统生成的具有取证价值的用户活动记录。深入了解这些记录是如何创建的,以及它们包含哪些信息,可以帮助检查人员获得可用作证据和支持其他证据的有价值的数据。工件可以是一种很好的方法,可以专注于相关数据,并减少对检查人员遇到的不断增加的数据存储进行全面检查的需要。通过本文,重点将放在分析不同的,较少的已知工件,不支持主流的取证工具,因为它们不同的Windows版本,导致需要手动分析。对它们的深刻理解是必要的,以避免误解它们的内容,从而导致错误的结论。此外,本文还介绍了测试过程中使用的Windows 10工件和开源工具的测试结果。
Windows 10 operating system is the most widely used operating system today that contains many programs and mechanisms for managing computer hardware and software. Looking from a digital forensics point of view these produce valuable records of user activities. In a forensic world, such records are known as Windows artifact which can be described as a system generated records of the user activities that have forensic value. Gaining a deep understanding of how these records are created and what information they contain can help the examiner to acquire valuable data that can be used as evidence and support other evidence. The artifacts can be a great way to focus on relevant data and reduce the need for full examination of constantly increasing data storage that examiners encounter. Through this paper, the focus will be on analyzing different, fewer know artifacts, that aren’t supported by mainstream forensic tools because they vary between versions of Windows, resulting in the need for manual analysis. Their deep understanding is necessary to avoid misinterpreting their content which can result in wrong conclusions. Additionally, the paper presents the results of testing Windows 10 artifacts and open-source tools used in the testing process.