首页 | 本学科首页   官方微博 | 高级检索  
     检索      


Structure and application of IconCache.db files for digital forensics
Institution:1. Oncology Department, Shanghai Ninth People''s Hospital, Shanghai Jiaotong University School of Medicine, Shanghai 201900, China;2. Rutgers Cancer Institute of New Jersey, New Brunswick, NJ 08903, USA
Abstract:Anti-forensics has developed to prevent digital forensic investigations, thus forensic investigations to prevent anti-forensic behaviors have been studied in various area. In the area of user activity analysis, “IconCache.db” files contain icon cache information related to applications, which can yield meaningful information for digital forensic investigations such as the traces of deleted files. A previous study investigated the general artifacts found in the IconCache.db file. In the present study, further features and structures of the IconCache.db file are described. We also propose methods for analyzing anti-forensic behaviors (e.g., time information related to the deletion of files). Finally, we introduce an analytical tool that was developed based on the file structure of IconCache.db. The tool parses out strings from the IconCache.db to assist an analyst. Therefore, an analyst can more easily analyze the IconCache.db file using the tool.
Keywords:Anti-forensics  Digital forensics  Icon  IconCache  db  User behavior
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号