Structure and application of IconCache.db files for digital forensics

Chan Youn Lee, Sangjin Lee

Research output: Contribution to journalArticle

3 Citations (Scopus)

Abstract

Anti-forensics has developed to prevent digital forensic investigations, thus forensic investigations to prevent anti-forensic behaviors have been studied in various area. In the area of user activity analysis, "IconCache.db" files contain icon cache information related to applications, which can yield meaningful information for digital forensic investigations such as the traces of deleted files. A previous study investigated the general artifacts found in the IconCache.db file. In the present study, further features and structures of the IconCache.db file are described. We also propose methods for analyzing anti-forensic behaviors (e.g., time information related to the deletion of files). Finally, we introduce an analytical tool that was developed based on the file structure of IconCache.db. The tool parses out strings from the IconCache.db to assist an analyst. Therefore, an analyst can more easily analyze the IconCache.db file using the tool.

Original languageEnglish
Pages (from-to)102-110
Number of pages9
JournalDigital Investigation
Volume11
Issue number2
DOIs
Publication statusPublished - 2014 Jan 1

Fingerprint

Artifacts
artifact
cyhalothrin
Digital forensics
time

ASJC Scopus subject areas

  • Law
  • Computer Science Applications
  • Medical Laboratory Technology

Cite this

Structure and application of IconCache.db files for digital forensics. / Lee, Chan Youn; Lee, Sangjin.

In: Digital Investigation, Vol. 11, No. 2, 01.01.2014, p. 102-110.

Research output: Contribution to journalArticle

@article{8a29987306e448e7a83112b6841d66b9,
title = "Structure and application of IconCache.db files for digital forensics",
abstract = "Anti-forensics has developed to prevent digital forensic investigations, thus forensic investigations to prevent anti-forensic behaviors have been studied in various area. In the area of user activity analysis, {"}IconCache.db{"} files contain icon cache information related to applications, which can yield meaningful information for digital forensic investigations such as the traces of deleted files. A previous study investigated the general artifacts found in the IconCache.db file. In the present study, further features and structures of the IconCache.db file are described. We also propose methods for analyzing anti-forensic behaviors (e.g., time information related to the deletion of files). Finally, we introduce an analytical tool that was developed based on the file structure of IconCache.db. The tool parses out strings from the IconCache.db to assist an analyst. Therefore, an analyst can more easily analyze the IconCache.db file using the tool.",
keywords = "Anti-forensics, Digital forensics, Icon, IconCache.db, User behavior",
author = "Lee, {Chan Youn} and Sangjin Lee",
year = "2014",
month = "1",
day = "1",
doi = "10.1016/j.diin.2014.05.017",
language = "English",
volume = "11",
pages = "102--110",
journal = "Digital Investigation",
issn = "1742-2876",
publisher = "Elsevier Limited",
number = "2",

}

TY - JOUR

T1 - Structure and application of IconCache.db files for digital forensics

AU - Lee, Chan Youn

AU - Lee, Sangjin

PY - 2014/1/1

Y1 - 2014/1/1

N2 - Anti-forensics has developed to prevent digital forensic investigations, thus forensic investigations to prevent anti-forensic behaviors have been studied in various area. In the area of user activity analysis, "IconCache.db" files contain icon cache information related to applications, which can yield meaningful information for digital forensic investigations such as the traces of deleted files. A previous study investigated the general artifacts found in the IconCache.db file. In the present study, further features and structures of the IconCache.db file are described. We also propose methods for analyzing anti-forensic behaviors (e.g., time information related to the deletion of files). Finally, we introduce an analytical tool that was developed based on the file structure of IconCache.db. The tool parses out strings from the IconCache.db to assist an analyst. Therefore, an analyst can more easily analyze the IconCache.db file using the tool.

AB - Anti-forensics has developed to prevent digital forensic investigations, thus forensic investigations to prevent anti-forensic behaviors have been studied in various area. In the area of user activity analysis, "IconCache.db" files contain icon cache information related to applications, which can yield meaningful information for digital forensic investigations such as the traces of deleted files. A previous study investigated the general artifacts found in the IconCache.db file. In the present study, further features and structures of the IconCache.db file are described. We also propose methods for analyzing anti-forensic behaviors (e.g., time information related to the deletion of files). Finally, we introduce an analytical tool that was developed based on the file structure of IconCache.db. The tool parses out strings from the IconCache.db to assist an analyst. Therefore, an analyst can more easily analyze the IconCache.db file using the tool.

KW - Anti-forensics

KW - Digital forensics

KW - Icon

KW - IconCache.db

KW - User behavior

UR - http://www.scopus.com/inward/record.url?scp=84903272686&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=84903272686&partnerID=8YFLogxK

U2 - 10.1016/j.diin.2014.05.017

DO - 10.1016/j.diin.2014.05.017

M3 - Article

AN - SCOPUS:84903272686

VL - 11

SP - 102

EP - 110

JO - Digital Investigation

JF - Digital Investigation

SN - 1742-2876

IS - 2

ER -