Repository logo
 
Publication

Analysis of Timestamp Manipulation Detection Tools

datacite.subject.fosEngenharia e Tecnologia::Outras Engenharias e Tecnologiaspt_PT
dc.contributor.advisorNegrão, Miguel Cerdeira Marreiros
dc.contributor.advisorDomingues, Patrício Rodrigues
dc.contributor.advisorFrade, Miguel Monteiro de Sousa
dc.contributor.authorSantos, Luís Paulo Monteiro dos
dc.date.accessioned2024-12-11T16:02:31Z
dc.date.available2024-12-11T16:02:31Z
dc.date.issued2024-11-19
dc.description.abstractDetecting timestamp manipulation on NTFS file systems has historically been challenging, with early tools producing unreliable results in real-world scenarios. Previous methods, as highlighted by Oh et al., often suffered from limitations such as generating false positives by misidentifying normal file system events as manipulation or being unable to detect intentional alterations in timestamps.Tools like NTFS Log Tracker v1.71 and TimestampAnalyser struggled to reliably identify such manipulations. However, recent advancements, such as the release of NTFS Log Tracker v1.9 in May 2024, have demonstrated improved accuracy. The updated tool, as detailed in “Forensic Detection of Timestamp Manipulation for Digital Forensic Investigation,” integrates multiple forensic detection algorithms by leveraging the $MFT, $LogFile, and $UsnJrnl, along with additional system artifacts like Windows Prefetch and LNK files. These enhancements aim to more effectively detect timestamp manipulation in digital forensic investigations. This project explores these advancements and provides updated information about the file operations effects on NTFS timestamps.pt_PT
dc.identifier.tid203754344pt_PT
dc.identifier.urihttp://hdl.handle.net/10400.8/10299
dc.language.isoengpt_PT
dc.subjectInformática forensept_PT
dc.subjectSistema de ficheiros NTFSpt_PT
dc.subjectEmpresapt_PT
dc.subjectAnálise digital forensept_PT
dc.titleAnalysis of Timestamp Manipulation Detection Toolspt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameMestrado em Cibersegurança e Informática Forensept_PT

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
relatorio_assinado.pdf
Size:
2.66 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.32 KB
Format:
Item-specific license agreed upon to submission
Description: