Analysis of changes in file time attributes with file manipulation

Jewan Bang, Byeongyeong Yoo, Sangjin Lee

Research output: Contribution to journalArticle

7 Citations (Scopus)

Abstract

Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.

Original languageEnglish
Pages (from-to)135-144
Number of pages10
JournalDigital Investigation
Volume7
Issue number3-4
DOIs
Publication statusPublished - 2011 Apr 1

Fingerprint

Windows operating system
Data transfer
manipulation
data exchange
new technology
Digital forensics
time
Technology

Keywords

  • Digital forensics
  • Filesystem
  • NTFS
  • Timestamp
  • Windows

ASJC Scopus subject areas

  • Law
  • Computer Science Applications
  • Medical Laboratory Technology

Cite this

Analysis of changes in file time attributes with file manipulation. / Bang, Jewan; Yoo, Byeongyeong; Lee, Sangjin.

In: Digital Investigation, Vol. 7, No. 3-4, 01.04.2011, p. 135-144.

Research output: Contribution to journalArticle

Bang, Jewan ; Yoo, Byeongyeong ; Lee, Sangjin. / Analysis of changes in file time attributes with file manipulation. In: Digital Investigation. 2011 ; Vol. 7, No. 3-4. pp. 135-144.
@article{9136387b65164c4b816c062a035826f7,
title = "Analysis of changes in file time attributes with file manipulation",
abstract = "Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.",
keywords = "Digital forensics, Filesystem, NTFS, Timestamp, Windows",
author = "Jewan Bang and Byeongyeong Yoo and Sangjin Lee",
year = "2011",
month = "4",
day = "1",
doi = "10.1016/j.diin.2010.12.001",
language = "English",
volume = "7",
pages = "135--144",
journal = "Digital Investigation",
issn = "1742-2876",
publisher = "Elsevier Limited",
number = "3-4",

}

TY - JOUR

T1 - Analysis of changes in file time attributes with file manipulation

AU - Bang, Jewan

AU - Yoo, Byeongyeong

AU - Lee, Sangjin

PY - 2011/4/1

Y1 - 2011/4/1

N2 - Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.

AB - Time information is an important factor in digital forensic investigations. The time information of files obtained under the New Technology File System (NTFS) for Windows is determined by the creation, modification, access, and master file table (MFT) entry modification times and can be changed by user manipulations such as copy, move, and change. The characteristics of changes in time attributes can be used to analyze certain user behaviors related to data transfer and modification. This study analyzes the change in time attributes of files or folders resulting from user manipulations under different Windows operating systems and deduces user behaviors through a procedure based on the analysis results.

KW - Digital forensics

KW - Filesystem

KW - NTFS

KW - Timestamp

KW - Windows

UR - http://www.scopus.com/inward/record.url?scp=79953853321&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=79953853321&partnerID=8YFLogxK

U2 - 10.1016/j.diin.2010.12.001

DO - 10.1016/j.diin.2010.12.001

M3 - Article

AN - SCOPUS:79953853321

VL - 7

SP - 135

EP - 144

JO - Digital Investigation

JF - Digital Investigation

SN - 1742-2876

IS - 3-4

ER -