Building Knowledge Bases for Timestamp Changes Detection Mechanisms in MFT Windows OS
Title | Building Knowledge Bases for Timestamp Changes Detection Mechanisms in MFT Windows OS |
Publication Type | Conference Paper |
Year of Publication | 2020 |
Authors | Knyazeva, N., Khorkov, D., Vostretsova, E. |
Conference Name | 2020 Ural Symposium on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT) |
Keywords | \$FILE\_NAME, \$STANDARDİNFORMATION, composability, computer forensic science, digital forensics, feature extraction, file operations, file organisation, file timestamp change detection, forensic analysis, İNDEX\_ALLOCATION, İNDEX\_ROOT, Information security, knowledge based systems, knowledge bases, master file table, Metrics, MFT, MFT Windows Os, Microsoft Windows (operating systems), operating system, pubcrawl, resilience, Resiliency, security, timestamps, Windows operating system, Windows Operating System Security |
Abstract | File timestamps do not receive much attention from information security specialists and computer forensic scientists. It is believed that timestamps are extremely easy to fake, and the system time of a computer can be changed. However, operating system for synchronizing processes and working with file objects needs accurate time readings. The authors estimate that several million timestamps can be stored on the logical partition of a hard disk with the NTFS. The MFT stores four timestamps for each file object in \$STANDARDINFORMATION and \$FILE\_NAME attributes. Furthermore, each directory in the INDEX\_ROOT or INDEX\_ALLOCATION attributes contains four more timestamps for each file within it. File timestamps are set and changed as a result of file operations. At the same time, some file operations differently affect changes in timestamps. This article presents the results of the tool-based observation over the creation and update of timestamps in the MFT resulting from the basic file operations. Analysis of the results is of interest with regard to computer forensic science. |
DOI | 10.1109/USBEREIT48449.2020.9117712 |
Citation Key | knyazeva_building_2020 |
- information security
- Windows Operating System Security
- timestamps
- Resiliency
- resilience
- pubcrawl
- operating system
- Microsoft Windows (operating systems)
- MFT Windows Os
- MFT
- Metrics
- master file table
- knowledge bases
- knowledge based systems
- Windows operating system
- İNDEX\_ROOT
- İNDEX\_ALLOCATION
- forensic analysis
- file timestamp change detection
- file organisation
- file operations
- feature extraction
- Digital Forensics
- computer forensic science
- composability
- \$STANDARDİNFORMATION
- \$FILE\_NAME
- security