ALJI Mohamed

Work place: Engineering Science Laboratory, National School for Applied Sciences, Ibn Tofail University, Kenitra, Morocco

E-mail: mohamed.alji@uit.ac.ma

Website:

Research Interests:

Biography

Eng. ALJI Mohamed is a PhD student at the Engineering Science Laboratory, National School for Applied Sciences, Ibn Tofail University, Kenitra, Morocco and a computer science engineer from the ENSEIRB-MATMECA engineering school, Bordeaux, France.

Author Articles
Detection of Suspicious Timestamps in NTFS using Volume Shadow Copies

By ALJI Mohamed CHOUGDALI Khalid

DOI: https://doi.org/10.5815/ijcnis.2021.04.06, Pub. Date: 8 Aug. 2021

When a computer gets involved in a crime, it is the mission of the digital forensic experts to extract the left binary artifacts on that device. Among those artifacts, there may be some volume shadow copy files left on the Windows operating system. Those files are snapshots of the volume recorded by the system in case of a needed restore to a specific past date. Before this study, we did not know if the valuable forensic information hold within those snapshot files can be exploited to locate suspicious timestamps in an NTFS formatted partition. This study provides the reader with an inter-snapshot time analysis for detecting file system timestamp manipulation. In other words, we will leverage the presence of the time information within multiples volume shadow copies to detect any suspicious tampering of the file system timestamps. A detection algorithm of the suspicious timestamps is contributed. Its main role is to assist the digital investigator to spot the manipulation if it has occurred. In addition, a virtual environment has been set up to validate the use of the proposed algorithm for the detection.

[...] Read more.
Other Articles