Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective

Byeongyeong Yoo, Jewan Bang, Kyung Soo Lim, Sangjin Lee

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Transaction indicates that the reservation of original data before committing works by executing a single work as an atomic unit. Transactional NTFS (TxF) is the thing that applies Transaction into on NTFS and is the first introduced in the Windows Vista. As Transactional NTFS, Transactional Registry (TxR) is that applies Transaction functions into Registry. When working on the task that Transaction is applied, the log relating to the work is recorded. Throughout the log, user can check work information. This paper introduces Transactional NTFS and Transactional Registry and analysis logs in the point view of digital forensics. Furthermore, this paper simulates the implement that analyze the Transaction log file.

Original languageEnglish
Title of host publicationProceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009
DOIs
Publication statusPublished - 2009 Dec 1
Event2009 2nd International Conference on Computer Science and Its Applications, CSA 2009 - Jeju Island, Korea, Republic of
Duration: 2009 Dec 102009 Dec 12

Other

Other2009 2nd International Conference on Computer Science and Its Applications, CSA 2009
CountryKorea, Republic of
CityJeju Island
Period09/12/1009/12/12

Fingerprint

Digital forensics

Keywords

  • Digital forensic
  • NTFS
  • Registry
  • Transaction

ASJC Scopus subject areas

  • Computational Theory and Mathematics
  • Computer Science Applications

Cite this

Yoo, B., Bang, J., Lim, K. S., & Lee, S. (2009). Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective. In Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009 [5404233] https://doi.org/10.1109/CSA.2009.5404233

Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective. / Yoo, Byeongyeong; Bang, Jewan; Lim, Kyung Soo; Lee, Sangjin.

Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009. 2009. 5404233.

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Yoo, B, Bang, J, Lim, KS & Lee, S 2009, Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective. in Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009., 5404233, 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009, Jeju Island, Korea, Republic of, 09/12/10. https://doi.org/10.1109/CSA.2009.5404233
Yoo B, Bang J, Lim KS, Lee S. Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective. In Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009. 2009. 5404233 https://doi.org/10.1109/CSA.2009.5404233
Yoo, Byeongyeong ; Bang, Jewan ; Lim, Kyung Soo ; Lee, Sangjin. / Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective. Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009. 2009.
@inproceedings{bf162224e12e4e9fa0fc4306dd3fc62e,
title = "Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective",
abstract = "Transaction indicates that the reservation of original data before committing works by executing a single work as an atomic unit. Transactional NTFS (TxF) is the thing that applies Transaction into on NTFS and is the first introduced in the Windows Vista. As Transactional NTFS, Transactional Registry (TxR) is that applies Transaction functions into Registry. When working on the task that Transaction is applied, the log relating to the work is recorded. Throughout the log, user can check work information. This paper introduces Transactional NTFS and Transactional Registry and analysis logs in the point view of digital forensics. Furthermore, this paper simulates the implement that analyze the Transaction log file.",
keywords = "Digital forensic, NTFS, Registry, Transaction",
author = "Byeongyeong Yoo and Jewan Bang and Lim, {Kyung Soo} and Sangjin Lee",
year = "2009",
month = "12",
day = "1",
doi = "10.1109/CSA.2009.5404233",
language = "English",
isbn = "9781424449460",
booktitle = "Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009",

}

TY - GEN

T1 - Analysis of window Transactional NTFS(TxF) and Transactional Registry(TxR) in the digital forensic perspective

AU - Yoo, Byeongyeong

AU - Bang, Jewan

AU - Lim, Kyung Soo

AU - Lee, Sangjin

PY - 2009/12/1

Y1 - 2009/12/1

N2 - Transaction indicates that the reservation of original data before committing works by executing a single work as an atomic unit. Transactional NTFS (TxF) is the thing that applies Transaction into on NTFS and is the first introduced in the Windows Vista. As Transactional NTFS, Transactional Registry (TxR) is that applies Transaction functions into Registry. When working on the task that Transaction is applied, the log relating to the work is recorded. Throughout the log, user can check work information. This paper introduces Transactional NTFS and Transactional Registry and analysis logs in the point view of digital forensics. Furthermore, this paper simulates the implement that analyze the Transaction log file.

AB - Transaction indicates that the reservation of original data before committing works by executing a single work as an atomic unit. Transactional NTFS (TxF) is the thing that applies Transaction into on NTFS and is the first introduced in the Windows Vista. As Transactional NTFS, Transactional Registry (TxR) is that applies Transaction functions into Registry. When working on the task that Transaction is applied, the log relating to the work is recorded. Throughout the log, user can check work information. This paper introduces Transactional NTFS and Transactional Registry and analysis logs in the point view of digital forensics. Furthermore, this paper simulates the implement that analyze the Transaction log file.

KW - Digital forensic

KW - NTFS

KW - Registry

KW - Transaction

UR - http://www.scopus.com/inward/record.url?scp=80655124306&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=80655124306&partnerID=8YFLogxK

U2 - 10.1109/CSA.2009.5404233

DO - 10.1109/CSA.2009.5404233

M3 - Conference contribution

AN - SCOPUS:80655124306

SN - 9781424449460

BT - Proceedings of the 2009 2nd International Conference on Computer Science and Its Applications, CSA 2009

ER -