A Consistency Study of the Windows Registry - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

A Consistency Study of the Windows Registry

Résumé

This paper proposes a novel method for checking the consistency of forensic registry artifacts by gathering event information from the artifacts and analyzing the event sequences based on the associated timestamps. The method helps detect the use of counter-forensic techniques without focusing on one particular counter-forensic tool at a time. Several consistency checking models are presented to verify events derived from registry artifacts. Examples of these models are used to demonstrate how evidence of alteration may be detected.
Fichier principal
Vignette du fichier
ZhuJG10.pdf (1.39 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01060611 , version 1 (27-11-2017)

Licence

Paternité

Identifiants

Citer

Yuandong Zhu, Joshua James, Pavel Gladyshev. A Consistency Study of the Windows Registry. 6th IFIP WG 11.9 International Conference on Digital Forensics (DF), Jan 2010, Hong Kong, China. pp.77-90, ⟨10.1007/978-3-642-15506-2_6⟩. ⟨hal-01060611⟩
93 Consultations
135 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More