【24h】

Time Bounding Event Reasoning in Computer Forensic

机译:计算机取证中的时限事件推理

获取原文
获取原文并翻译 | 示例

摘要

Timestamps are widely used in computing and offer an easy way to determine the time of events in digital investigations.Unfortunately,the ability of users to change clock settings,the difficult to recover the multi-level overwriting data in a disk,etc.can not provide the efficient timestamp for event reasoning.In this paper,we present techniques to use lay technique to deal with the time of a file on local machine,even its data block of a file had been re-written many times or deleted long ago,and adopt the time offset mechanism to deal with the deviation time of the file at time t.Use a logging mechanism to record the time of modifications to each disk block and its deviation time at time t to calculate the real time of a file for reasoning the order of the events and obtaining a timeline of activities on a file.
机译:时间戳在计算中被广泛使用,并提供了一种确定数字调查中事件时间的简便方法。不幸的是,用户更改时钟设置的能力,难以恢复磁盘中的多级覆盖数据等都无法实现。为事件推理提供了有效的时间戳。在本文中,我们提出了使用居中技术来处理本地计算机上文件时间的技术,即使其文件数据块已被多次重写或很早就删除了,并采用时间偏移机制处理文件在时间t的偏离时间。使用日志记录机制记录每个磁盘块的修改时间及其在时间t的偏离时间,以计算文件的实时推理时间事件的顺序并获得文件上活动的时间表。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号