25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

only information which does not conflict with existing information in the event<br />

timeline should be added:<br />

1. If a subrecord exists whose name corresponds to an MD5 hash of the<br />

source files current URI, it should be extracted and added to the event<br />

timeline. Section 5.9.3 describes the relationships which can be formed<br />

between the thumbnail cache and user files based on MD5 hashes.<br />

2. Any thumbnail records, with a hash value for the IDAT chunks that<br />

matches the hash value for the original source files thumbnail created<br />

should be extracted. Section 5.9.2 describes the limitations of matching<br />

visual data from the thumbnail cache with user created files.<br />

3. Any records which contain a URI which ends with the same file name<br />

may then be extracted; the same file name may suggest a previous path<br />

of the file or that the file has been copied.<br />

4. Any subrecords which have the same metadata information within them<br />

as the metadata contained within a generated subrecord of the original<br />

source file can then be added. Section 5.9.1discusses the limitations of<br />

forming relationships between thumbnail cache artefacts and user files<br />

based on metadata.<br />

5. Any subrecords of the same file type may then be extracted for hand<br />

analysis by an analyst.<br />

The ability to construct an event timeline based on a single subrecord can assist<br />

in establishing the user’s behaviour; establishing how the file was manipulated<br />

by the user can show their intention and assist with proving or disproving the<br />

mens rea aspect of the investigation [Chapter 4].<br />

Page 95

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!