The Experts below are selected from a list of 471 Experts worldwide ranked by ideXlab platform
Martin S Olivier - One of the best experts on this subject based on the ideXlab platform.
-
South-Africa
2015Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of informa-tion may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to de-termine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed
-
the use of File Timestamps in digital forensics
Information Security for South Africa, 2008Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of information may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to determine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed.
-
ISSA - The Use of File Timestamps in Digital Forensics.
2008Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of information may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to determine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed.
Renico Koen - One of the best experts on this subject based on the ideXlab platform.
-
South-Africa
2015Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of informa-tion may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to de-termine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed
-
the use of File Timestamps in digital forensics
Information Security for South Africa, 2008Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of information may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to determine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed.
-
ISSA - The Use of File Timestamps in Digital Forensics.
2008Co-Authors: Renico Koen, Martin S OlivierAbstract:Digital evidence is not well perceived by the human senses. Crucial pieces of digital evidence may simply be missed by investigators as the forensic significance of seemingly unimportant pieces of collected data may not be fully understood. This paper will discuss how abstract pieces of information may be extracted from seemingly insignificant evidence sources such a File Timestamps by making use of correlating evidence sources. The use of File Timestamps as a substitute for missing or corrupt log Files as well as the information deficiency problem surrounding the use of Timestamps will be discussed in detail. A prototype was developed to help investigators to determine the course of event as they occurred according to File Timestamps. The prototype results that were obtained as well as prototype flaws will also be addressed.
Edgar R. Weippl - One of the best experts on this subject based on the ideXlab platform.
-
Time is on my side: Steganography in Filesystem metadata
Digital Investigation, 2016Co-Authors: Sebastian Neuner, Artemios G. Voyiatzis, Martin Schmiedecker, Stefan Brunthaler, Stefan Katzenbeisser, Edgar R. WeipplAbstract:Abstract We propose and explore the applicability of File Timestamps as a steganographic channel. We identify an information gap between storage and usage of Timestamps in modern operating systems that use high-precision timers. Building on this, we describe a layered design of a steganographic system that offers stealthiness, robustness, and wide applicability. The proposed design is evaluated through theoretical, evidence-based, and experimental analysis for the case of NTFS using datasets comprising millions of Files. We report a proof-of-concept implementation and confirm that the embedded information is indistinguishable from that of a normal Filesystem use. Finally, we discuss the digital forensics analysis implications of this new information-hiding technique.
R Weippledgar - One of the best experts on this subject based on the ideXlab platform.
-
Time is on my side
2016Co-Authors: Neunersebastian, G Voyiatzisartemios, Schmiedeckermartin, Brunthalerstefan, Katzenbeisserstefan, R WeippledgarAbstract:We propose and explore the applicability of File Timestamps as a steganographic channel. We identify an information gap between storage and usage of Timestamps in modern operating systems that use ...
Karrothu Aravind - One of the best experts on this subject based on the ideXlab platform.
-
digital forensic evidence collection of cloud storage data for investigation
International Conference on Recent Trends in Information Technology, 2016Co-Authors: Sathishkumar Easwaramoorthy, Sankar Thamburasa, Guru Samy, Bharath S Bhushan, Karrothu AravindAbstract:In recent days Cloud services such as storage is more familiar to business and Individuals. This storage services are found as a problem to examiners and researchers in the field of forensics. There are many kind of storage services available in cloud and every service face a diverse issues in illegitimate action. The evidence identification, preservation, and collection are hard when dissimilar services are utilized by offenders. Lack of knowledge regarding location of evidence data can also affect investigation and it take more time to meet every cloud storage providers to decide where the evidence is saved within their infrastructure. In this study two popular public cloud service providers (Microsoft One Drive and Amazon cloud drive) are used to perform forensics evidence collection procedure through browser and service providers software on a Windows 7 computer. By identifying the evidence data on a client device, provide a clear idea about type of evidences are exist in machine for forensics practitioners. Possible evidence determined throughout this study include File Timestamps, File hashes, client software log Files, memory captures, link Files and other evidences are also obtainable to different cloud service providers.