Work place: Engineering Science Laboratory, National School for Applied Sciences, Ibn Tofail University, Kenitra, Morocco
E-mail: khalid.chougdali@uit.ac.ma
Website:
Research Interests: Information Security
Biography
Dr. CHOUGDALI Khalid is an associate professor in computer science at the National School for Applied Science, Ibn Tofail University, Kenitra Morocco. Its main research areas are information security, digital forensics and data analysis.
By ALJI Mohamed CHOUGDALI Khalid
DOI: https://doi.org/10.5815/ijcnis.2021.04.06, Pub. Date: 8 Aug. 2021
When a computer gets involved in a crime, it is the mission of the digital forensic experts to extract the left binary artifacts on that device. Among those artifacts, there may be some volume shadow copy files left on the Windows operating system. Those files are snapshots of the volume recorded by the system in case of a needed restore to a specific past date. Before this study, we did not know if the valuable forensic information hold within those snapshot files can be exploited to locate suspicious timestamps in an NTFS formatted partition. This study provides the reader with an inter-snapshot time analysis for detecting file system timestamp manipulation. In other words, we will leverage the presence of the time information within multiples volume shadow copies to detect any suspicious tampering of the file system timestamps. A detection algorithm of the suspicious timestamps is contributed. Its main role is to assist the digital investigator to spot the manipulation if it has occurred. In addition, a virtual environment has been set up to validate the use of the proposed algorithm for the detection.
[...] Read more.Subscribe to receive issue release notifications and newsletters from MECS Press journals