首页> 外文会议>International Conference on Availability, Reliability and Security >Digital Forensic Artifacts of the Cortana Device Search Cache on Windows 10 Desktop
【24h】

Digital Forensic Artifacts of the Cortana Device Search Cache on Windows 10 Desktop

机译:Windows 10桌面版Cortana设备搜索缓存的数字取证工件

获取原文

摘要

Microsoft Windows 10 Desktop edition has brought some new features and updated other ones that are of special interest to digital forensics analysis. The search box available on the taskbar, next to the Windows start button is one of these novelties. Although the primary usage of this search box is to act as an interface to the intelligent personal digital assistant Cortana, in this paper, we study the digital forensic artifacts of the search box on machines when Cortana is explicitly disabled. Specifically, we locate, characterize and analyze the content and dynamics of the JSON-based files that are periodically generated by the Cortana device search cache system. Forensically important data from these JSON files include the number of times each installed application has been run, the date of the last execution and the content of the custom jump list of the applications. Since these data are collected per user and saved in a resilient text format, they can help in digital forensics, mostly in assisting the validation of other sources of information.
机译:Microsoft Windows 10桌面版带来了一些新功能,并更新了数字取证分析特别感兴趣的其他功能。 Windows的“开始”按钮旁边的任务栏上提供的搜索框就是其中之一。尽管此搜索框的主要用途是充当智能个人数字助理Cortana的接口,但在本文中,我们研究了明确禁用Cortana时机器上搜索框的数字取证伪像。具体来说,我们查找,表征和分析由Cortana设备搜索缓存系统定期生成的基于JSON的文件的内容和动态。来自这些JSON文件的具有法律意义的重要数据包括运行每个已安装应用程序的次数,最后一次执行的日期以及应用程序的自定义跳转列表的内容。由于这些数据是按用户收集的,并以有弹性的文本格式保存,因此它们可以帮助进行数字取证,主要是协助其他信息来源的验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号