2020
DOI: 10.1016/j.fsidi.2020.301005
|View full text |Cite
|
Sign up to set email alerts
|

Generic Metadata Time Carving

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2022
2022
2022
2022

Publication Types

Select...
2

Relationship

0
2

Authors

Journals

citations
Cited by 2 publications
(3 citation statements)
references
References 8 publications
0
3
0
Order By: Relevance
“…Nordvik [20] performed a study to recover metadata using the characteristics of timestamps included in the metadata of each file system. The recovery method looked for corresponding patterns using a feature in which the timestamp of the same value was continuously stored, and then carving of the metadata including the pattern was performed.…”
Section: Recovery Of Timestampmentioning
confidence: 99%
“…Nordvik [20] performed a study to recover metadata using the characteristics of timestamps included in the metadata of each file system. The recovery method looked for corresponding patterns using a feature in which the timestamp of the same value was continuously stored, and then carving of the metadata including the pattern was performed.…”
Section: Recovery Of Timestampmentioning
confidence: 99%
“…Regarding the situation that little effort was put forth toward the recovery of binary executable files, Hand et al (2012), for the first time, provided a solution that leverages the combination of both road map information defined in executable file headers and explicit control flow paths within the binary code. Nordvik et al (2020) argued that existing CRF methods do not consider how to recover file-related metadata, which, such as timestamps, have greater value for complete forensics. For this reason, they proposed a generic timestamp metadata carving method for the first time.…”
Section: Research On File Recoverymentioning
confidence: 99%
“…Different from MFR, CFR does not rely on metadata. It leverages syntactic signatures (e.g., file header-footer pairs) (Tang et al, 2016), semantic structures (e.g., explicit control flow paths within a binary executable) (Hand et al, 2012), heuristic technologies (Garfinkel & McCarrin, 2015;Gladyshev & James, 2017;Pal et al, 2008), timestamps (Nordvik et al, 2020;Portera et al, 2021) or deep learning technologies (Heo et al, 2019;Mohammad & Alqahtani, 2019) to restore files. Unlike MFR, which can precisely recover a file under the "direct guidance" of metadata, CFR "indirectly infers" which data blocks belong to the file to be recovered.…”
Section: Introductionmentioning
confidence: 99%