• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

适用于Windows 10的USB存储设备取证

USB Storage Device Forensics for Windows 10.

作者信息

Arshad Ayesha, Iqbal Waseem, Abbas Haider

机构信息

National University of Sciences and Technology (NUST), Islamabad, 44000, Pakistan.

Florida Institute of Technology (FIT), Melbourne, FL, 32901, USA.

出版信息

J Forensic Sci. 2018 May;63(3):856-867. doi: 10.1111/1556-4029.13596. Epub 2017 Jul 18.

DOI:10.1111/1556-4029.13596
PMID:28718907
Abstract

Significantly increased use of USB devices due to their user-friendliness and large storage capacities poses various threats for many users/companies in terms of data theft that becomes easier due to their efficient mobility. Investigations for such data theft activities would require gathering critical digital information capable of recovering digital forensics artifacts like date, time, and device information. This research gathers three sets of registry and logs data: first, before insertion; second, during insertion; and the third, after removal of a USB device. These sets are analyzed to gather evidentiary information from Registry and Windows Event log that helps in tracking a USB device. This research furthers the prior research on earlier versions of Microsoft Windows and compares it with latest Windows 10 system. Comparison of Windows 8 and Windows 10 does not show much difference except for new subkey under USB Key in registry. However, comparison of Windows 7 with latest version indicates significant variances.

摘要

由于USB设备用户友好且存储容量大,其使用量显著增加,这给许多用户/公司带来了各种威胁,因为其高效的移动性使得数据盗窃变得更加容易。对此类数据盗窃活动的调查需要收集关键的数字信息,以便能够恢复数字取证工件,如日期、时间和设备信息。本研究收集了三组注册表和日志数据:第一组是在插入USB设备之前;第二组是在插入过程中;第三组是在移除USB设备之后。对这些数据集进行分析,以从注册表和Windows事件日志中收集有助于追踪USB设备的证据信息。本研究进一步推进了对早期版本Microsoft Windows的先前研究,并将其与最新的Windows 10系统进行了比较。Windows 8和Windows 10的比较除了注册表中USB密钥下的新子键外,没有显示出太大差异。然而,Windows 7与最新版本的比较显示出显著差异。

相似文献

1
USB Storage Device Forensics for Windows 10.适用于Windows 10的USB存储设备取证
J Forensic Sci. 2018 May;63(3):856-867. doi: 10.1111/1556-4029.13596. Epub 2017 Jul 18.
2
A Forensic Exploration of the Microsoft Windows 10 Timeline.对微软Windows 10时间线的法证探索
J Forensic Sci. 2019 Mar;64(2):577-586. doi: 10.1111/1556-4029.13875. Epub 2018 Jul 26.
3
Forensic Investigation of Cooperative Storage Cloud Service: Symform as a Case Study.合作存储云服务的法医调查:以Symform为例进行研究
J Forensic Sci. 2017 May;62(3):641-654. doi: 10.1111/1556-4029.13271. Epub 2016 Nov 25.
4
We are meeting on Microsoft Teams: Forensic analysis in Windows, Android, and iOS operating systems.我们正在微软团队上开会:关于Windows、安卓和iOS操作系统中的法医分析。
J Forensic Sci. 2023 Mar;68(2):434-460. doi: 10.1111/1556-4029.15208. Epub 2023 Feb 3.
5
Large-scale digital forensic investigation for Windows registry on Apache Spark.基于 Apache Spark 的 Windows 注册表大规模数字取证调查。
PLoS One. 2022 Dec 7;17(12):e0267411. doi: 10.1371/journal.pone.0267411. eCollection 2022.
6
An Evidence-Based Forensic Taxonomy of Windows Phone Communication Apps.基于证据的Windows Phone通信应用法医分类法。
J Forensic Sci. 2018 May;63(3):868-881. doi: 10.1111/1556-4029.13624. Epub 2017 Aug 17.
7
Microsoft Teams desktop application forensic investigations utilizing IndexedDB storage.利用 IndexedDB 存储进行 Microsoft Teams 桌面应用程序取证调查。
J Forensic Sci. 2022 Jul;67(4):1513-1533. doi: 10.1111/1556-4029.15014. Epub 2022 Feb 18.
8
A holistic digital forensic analysis of Discord - Storage, memory, and network perspectives.从存储、内存和网络角度对Discord进行全面的数字取证分析。
J Forensic Sci. 2024 Jul;69(4):1320-1333. doi: 10.1111/1556-4029.15548. Epub 2024 May 28.
9
Dataset of Windows operating system forensics artefacts.Windows操作系统取证工件数据集。
Data Brief. 2024 Jun 28;55:110693. doi: 10.1016/j.dib.2024.110693. eCollection 2024 Aug.
10
Windows 7 Antiforensics: A Review and a Novel Approach.Windows 7反取证技术:综述与一种新方法。
J Forensic Sci. 2017 Jul;62(4):1054-1070. doi: 10.1111/1556-4029.13393. Epub 2017 Feb 2.