File Download
  Links for fulltext
     (May Require Subscription)
Supplementary

postgraduate thesis: Temporal analysis on HFS+ and across file systems in digital forensic investigation

TitleTemporal analysis on HFS+ and across file systems in digital forensic investigation
Authors
Advisors
Advisor(s):Chow, KP
Issue Date2013
PublisherThe University of Hong Kong (Pokfulam, Hong Kong)
Citation
Wang, M. [王萌萌]. (2013). Temporal analysis on HFS+ and across file systems in digital forensic investigation. (Thesis). University of Hong Kong, Pokfulam, Hong Kong SAR. Retrieved from http://dx.doi.org/10.5353/th_b5090012
AbstractIn computer forensics, digital evidence related to time is both important and complex. The rules of changes in time associated with digital evidence, such as files or folders, can be used to analyze certain user behaviors like data access, modification or transfer. However, the format and the rules in time information for user actions are quite different for different file systems, even for different versions of operating systems with the same file system. Some research on temporal analysis has already been done on NTFS and FAT file systems, while there are few resources that describe temporal analysis on the Hierarchical File System Plus (HFS+), the default file system in Apple computer. Moreover, removable devices like USB disks are used frequently; transferring files and folders between different devices with different file systems and operating systems happens more and more frequently, so the changes of times across different file systems are also crucial in digital forensics and investigations. In this research, the changes in time attributes of files and folders resulting from user actions on the HFS+ file system and across file systems are analyzed, and the rules of time are generated by inductive reasoning to help reconstruct crime scenes in the digital forensic investigation. Since inductive reasoning is not definitely true compared with deductive reasoning, experiments are performed to validate the rules. The usage of the rules is demonstrated by analyzing a case in details. The methods proposed here are efficient, practical and easy to put into practice in real scenarios.
DegreeMaster of Philosophy
SubjectComputer crimes - Investigation.
File organization (Computer science)
Forensic sciences.
Dept/ProgramComputer Science
Persistent Identifierhttp://hdl.handle.net/10722/192867
HKU Library Item IDb5090012

 

DC FieldValueLanguage
dc.contributor.advisorChow, KP-
dc.contributor.authorWang, Mengmeng-
dc.contributor.author王萌萌-
dc.date.accessioned2013-11-24T02:01:17Z-
dc.date.available2013-11-24T02:01:17Z-
dc.date.issued2013-
dc.identifier.citationWang, M. [王萌萌]. (2013). Temporal analysis on HFS+ and across file systems in digital forensic investigation. (Thesis). University of Hong Kong, Pokfulam, Hong Kong SAR. Retrieved from http://dx.doi.org/10.5353/th_b5090012-
dc.identifier.urihttp://hdl.handle.net/10722/192867-
dc.description.abstractIn computer forensics, digital evidence related to time is both important and complex. The rules of changes in time associated with digital evidence, such as files or folders, can be used to analyze certain user behaviors like data access, modification or transfer. However, the format and the rules in time information for user actions are quite different for different file systems, even for different versions of operating systems with the same file system. Some research on temporal analysis has already been done on NTFS and FAT file systems, while there are few resources that describe temporal analysis on the Hierarchical File System Plus (HFS+), the default file system in Apple computer. Moreover, removable devices like USB disks are used frequently; transferring files and folders between different devices with different file systems and operating systems happens more and more frequently, so the changes of times across different file systems are also crucial in digital forensics and investigations. In this research, the changes in time attributes of files and folders resulting from user actions on the HFS+ file system and across file systems are analyzed, and the rules of time are generated by inductive reasoning to help reconstruct crime scenes in the digital forensic investigation. Since inductive reasoning is not definitely true compared with deductive reasoning, experiments are performed to validate the rules. The usage of the rules is demonstrated by analyzing a case in details. The methods proposed here are efficient, practical and easy to put into practice in real scenarios.-
dc.languageeng-
dc.publisherThe University of Hong Kong (Pokfulam, Hong Kong)-
dc.relation.ispartofHKU Theses Online (HKUTO)-
dc.rightsThe author retains all proprietary rights, (such as patent rights) and the right to use in future works.-
dc.rightsThis work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.-
dc.source.urihttp://hub.hku.hk/bib/B50900122-
dc.subject.lcshComputer crimes - Investigation.-
dc.subject.lcshFile organization (Computer science)-
dc.subject.lcshForensic sciences.-
dc.titleTemporal analysis on HFS+ and across file systems in digital forensic investigation-
dc.typePG_Thesis-
dc.identifier.hkulb5090012-
dc.description.thesisnameMaster of Philosophy-
dc.description.thesislevelMaster-
dc.description.thesisdisciplineComputer Science-
dc.description.naturepublished_or_final_version-
dc.identifier.doi10.5353/th_b5090012-
dc.date.hkucongregation2013-
dc.identifier.mmsid991035827159703414-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats