• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

数字地层学:法医学中文件系统痕迹的语境分析。

Digital Stratigraphy: Contextual Analysis of File System Traces in Forensic Science.

作者信息

Casey Eoghan

机构信息

Ecole des Sciences Criminelles (ESC), Université de Lausanne, Batochime, CH-1015, Lausanne-Dorigny, Switzerland.

出版信息

J Forensic Sci. 2018 Sep;63(5):1383-1391. doi: 10.1111/1556-4029.13722. Epub 2017 Dec 28.

DOI:10.1111/1556-4029.13722
PMID:29284066
Abstract

This work introduces novel methods for conducting forensic analysis of file allocation traces, collectively called digital stratigraphy. These in-depth forensic analysis methods can provide insight into the origin, composition, distribution, and time frame of strata within storage media. Using case examples and empirical studies, this paper illuminates the successes, challenges, and limitations of digital stratigraphy. This study also shows how understanding file allocation methods can provide insight into concealment activities and how real-world computer usage can complicate digital stratigraphy. Furthermore, this work explains how forensic analysts have misinterpreted traces of normal file system behavior as indications of concealment activities. This work raises awareness of the value of taking the overall context into account when analyzing file system traces. This work calls for further research in this area and for forensic tools to provide necessary information for such contextual analysis, such as highlighting mass deletion, mass copying, and potential backdating.

摘要

这项工作介绍了对文件分配踪迹进行法医分析的新方法,统称为数字地层学。这些深入的法医分析方法可以深入了解存储介质中层的起源、组成、分布和时间框架。通过案例和实证研究,本文阐明了数字地层学的成功之处、挑战和局限性。这项研究还展示了理解文件分配方法如何能深入了解隐藏活动,以及现实世界中的计算机使用情况如何使数字地层学变得复杂。此外,这项工作解释了法医分析师如何将正常文件系统行为的踪迹误判为隐藏活动的迹象。这项工作提高了人们在分析文件系统踪迹时考虑整体背景的价值的意识。这项工作呼吁在该领域进行进一步研究,并要求法医工具提供此类背景分析所需的信息,例如突出显示大规模删除、大规模复制和潜在的回溯。

相似文献

1
Digital Stratigraphy: Contextual Analysis of File System Traces in Forensic Science.数字地层学:法医学中文件系统痕迹的语境分析。
J Forensic Sci. 2018 Sep;63(5):1383-1391. doi: 10.1111/1556-4029.13722. Epub 2017 Dec 28.
2
A case study on anonymised sharing platforms and digital traces left by their usage.匿名共享平台及其使用所留下的数字痕迹案例研究。
Sci Justice. 2021 Jan;61(1):97-106. doi: 10.1016/j.scijus.2020.09.002. Epub 2020 Sep 9.
3
A reference database of Windows artifacts for file-wiping tool execution analysis.
J Forensic Sci. 2023 May;68(3):856-870. doi: 10.1111/1556-4029.15240. Epub 2023 Apr 5.
4
The prevalence of encoded digital trace evidence in the nonfile space of computer media(,) (.).计算机介质非文件空间中编码数字痕迹证据的流行情况(,) (.)
J Forensic Sci. 2014 Sep;59(5):1386-93. doi: 10.1111/1556-4029.12528. Epub 2014 Jul 23.
5
Media analyses based on Microsoft NTFS file ownership.
Forensic Sci Int. 2006 Oct 16;162(1-3):44-8. doi: 10.1016/j.forsciint.2006.06.014. Epub 2006 Jul 28.
6
Can computer forensic tools be trusted in digital investigations?在数字调查中,计算机取证工具值得信赖吗?
Sci Justice. 2021 Mar;61(2):198-203. doi: 10.1016/j.scijus.2020.10.002. Epub 2020 Oct 28.
7
Forensic Investigation of Cooperative Storage Cloud Service: Symform as a Case Study.合作存储云服务的法医调查:以Symform为例进行研究
J Forensic Sci. 2017 May;62(3):641-654. doi: 10.1111/1556-4029.13271. Epub 2016 Nov 25.
8
When finding nothing may be evidence of something: Anti-forensics and digital tool marks.当一无所获可能成为某种证据时:反取证与数字工具痕迹
Sci Justice. 2019 Sep;59(5):565-572. doi: 10.1016/j.scijus.2019.06.004. Epub 2019 Jun 3.
9
Forensic analysis of anti-forensic file-wiping tools on Windows.Windows 上反取证文件擦除工具的法医分析。
J Forensic Sci. 2022 Mar;67(2):562-587. doi: 10.1111/1556-4029.14907. Epub 2021 Oct 7.
10
Taxonomy of Challenges for Digital Forensics.数字取证挑战的分类法。
J Forensic Sci. 2015 Jul;60(4):885-93. doi: 10.1111/1556-4029.12809. Epub 2015 Jul 14.

引用本文的文献

1
Interpol review of digital evidence for 2019-2022.国际刑警组织对2019年至2022年数字证据的审查。
Forensic Sci Int Synerg. 2023 Jan 31;6:100313. doi: 10.1016/j.fsisyn.2022.100313. eCollection 2023.