Visible to the public Timestamp Hiccups: Detecting Manipulated Filesystem Timestamps on NTFS

TitleTimestamp Hiccups: Detecting Manipulated Filesystem Timestamps on NTFS
Publication TypeConference Paper
Year of Publication2017
AuthorsNeuner, Sebastian, Voyiatzis, Artemios G., Schmiedecker, Martin, Weippl, Edgar R.
Conference NameProceedings of the 12th International Conference on Availability, Reliability and Security
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-5257-4
Keywordscomposability, digital forensics, filesystem, information leakage, Information security, Metrics, NTFS, privacy, pubcrawl, steganography, steganography detection
Abstract

Redundant capacity in filesystem timestamps is recently proposed in the literature as an effective means for information hiding and data leakage. Here, we evaluate the steganographic capabilities of such channels and propose techniques to aid digital forensics investigation towards identifying and detecting manipulated filesystem timestamps. Our findings indicate that different storage media and interfaces exhibit different timestamp creation patterns. Such differences can be utilized to characterize file source media and increase the analysis capabilities of the incident response process.

URLhttps://dl.acm.org/citation.cfm?doid=3098954.3098994
DOI10.1145/3098954.3098994
Citation Keyneuner_timestamp_2017