首页 | 本学科首页   官方微博 | 高级检索  
     检索      


Digital Stratigraphy: Contextual Analysis of File System Traces in Forensic Science
Authors:Eoghan Casey PhD
Institution:Ecole des Sciences Criminelles (ESC), Université de Lausanne, Lausanne‐Dorigny, Switzerland
Abstract:This work introduces novel methods for conducting forensic analysis of file allocation traces, collectively called digital stratigraphy. These in‐depth forensic analysis methods can provide insight into the origin, composition, distribution, and time frame of strata within storage media. Using case examples and empirical studies, this paper illuminates the successes, challenges, and limitations of digital stratigraphy. This study also shows how understanding file allocation methods can provide insight into concealment activities and how real‐world computer usage can complicate digital stratigraphy. Furthermore, this work explains how forensic analysts have misinterpreted traces of normal file system behavior as indications of concealment activities. This work raises awareness of the value of taking the overall context into account when analyzing file system traces. This work calls for further research in this area and for forensic tools to provide necessary information for such contextual analysis, such as highlighting mass deletion, mass copying, and potential backdating.
Keywords:forensic science  digital forensics  digital evidence  digital stratigraphy  contextual forensic analysis  file system analysis  file allocation strategies  next‐available file allocation  best‐fit file allocation  valid data length slack  file initialization  file tunneling
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号