A Consistency Study of the Windows Registry - Advances in Digital Forensics VI
Conference Papers Year : 2010

A Consistency Study of the Windows Registry

Abstract

This paper proposes a novel method for checking the consistency of forensic registry artifacts by gathering event information from the artifacts and analyzing the event sequences based on the associated timestamps. The method helps detect the use of counter-forensic techniques without focusing on one particular counter-forensic tool at a time. Several consistency checking models are presented to verify events derived from registry artifacts. Examples of these models are used to demonstrate how evidence of alteration may be detected.
Fichier principal
Vignette du fichier
ZhuJG10.pdf (1.39 Mo) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01060611 , version 1 (27-11-2017)

Licence

Identifiers

Cite

Yuandong Zhu, Joshua James, Pavel Gladyshev. A Consistency Study of the Windows Registry. 6th IFIP WG 11.9 International Conference on Digital Forensics (DF), Jan 2010, Hong Kong, China. pp.77-90, ⟨10.1007/978-3-642-15506-2_6⟩. ⟨hal-01060611⟩
106 View
155 Download

Altmetric

Share

More