Digital Stratigraphy: Contextual Analysis of File System Traces in Forensic Science

被引:14
作者
Casey, Eoghan [1 ]
机构
[1] Univ Lausanne, ESC, CH-1015 Lausanne, Switzerland
关键词
forensic science; digital forensics; digital evidence; digital stratigraphy; contextual forensic analysis; file system analysis; file allocation strategies; next-available file allocation; best-fit file allocation; valid data length slack; file initialization; file tunneling; CREATION ORDER RECONSTRUCTION; LINUX FAT32 ALLOCATOR;
D O I
10.1111/1556-4029.13722
中图分类号
DF [法律]; D9 [法律]; R [医药、卫生];
学科分类号
0301 ; 10 ;
摘要
This work introduces novel methods for conducting forensic analysis of file allocation traces, collectively called digital stratigraphy. These in-depth forensic analysis methods can provide insight into the origin, composition, distribution, and time frame of strata within storage media. Using case examples and empirical studies, this paper illuminates the successes, challenges, and limitations of digital stratigraphy. This study also shows how understanding file allocation methods can provide insight into concealment activities and how real-world computer usage can complicate digital stratigraphy. Furthermore, this work explains how forensic analysts have misinterpreted traces of normal file system behavior as indications of concealment activities. This work raises awareness of the value of taking the overall context into account when analyzing file system traces. This work calls for further research in this area and for forensic tools to provide necessary information for such contextual analysis, such as highlighting mass deletion, mass copying, and potential backdating.
引用
收藏
页码:1383 / 1391
页数:9
相关论文
共 19 条
[1]  
[Anonymous], 2011, Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet
[2]  
Carrier B., 2005, File System Forensic Analysis
[3]  
Casey E, 2017, P 69 ANN SCI M AM AC
[4]   An ontology-based approach for the reconstruction and analysis of digital incidents timelines [J].
Chabot, Yoan ;
Bertaux, Aurelie ;
Nicolle, Christophe ;
Kechadi, Tahar .
DIGITAL INVESTIGATION, 2015, 15 :83-100
[5]   A complete formalized knowledge representation model for advanced digital forensics timeline analysis [J].
Chabot, Yoan ;
Bertaux, Aurelie ;
Nicolle, Christophe ;
Kechadi, M-Tahar .
DIGITAL INVESTIGATION, 2014, 11 :S95-S105
[6]  
Ferguson David Glen, 2008, Journal of Digital Forensic Practice, V2, P140, DOI 10.1080/15567280802587965
[7]  
Friedberg E, 2004, AM LAWYER
[8]  
Hales G, 2016, THESIS
[9]  
Harris EdwardC., 1989, PRINCIPLES ARCHAEOLO, V2nd
[10]   Comments on the Linux FAT32 allocator and file creation order reconstruction [Digit Investig 11( 4), 224-233] [J].
Lee, Wan Yeon ;
Kwon, Hyuckmin ;
Lee, Heejo .
DIGITAL INVESTIGATION, 2015, 15 :119-123