25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

6 The structure and behaviour of the Windows 7<br />

Operating System Thumbnail Cache<br />

6.1 Introduction<br />

The release of Windows Vista prompted speculation from Forensic analysts<br />

about the impact of the new Operating system on investigations [Hargreaves,<br />

2008]. One interesting change was the move away from the directory specific<br />

thumbs.db, to each user having a single centralised thumbnail cache. The<br />

release of Windows 7 in 2009 prompted further speculation from analysts;<br />

additional changes were introduced to the structure and behaviour of system<br />

components such as Windows Desktop Search [Chivers, 2011].The centralised<br />

thumbnail cache format introduced in Windows Vista had also been adapted in<br />

the new operating system.<br />

Microsoft operating systems are installed on a significant proportion of user<br />

machines and it is therefore unsurprising that currently a significant proportion<br />

of forensic analysis involves their operating systems. Due to the likelihood of<br />

encountering a Windows based operating system there is significant interest in<br />

finding and understanding relevant artefacts within the forensic community.<br />

This Chapter identifies the structure and behaviour of the Windows 7 operating<br />

system thumbnail caches; it begins with the methodology employed within this<br />

chapter [Section 6.2]. This is followed by the identification of relevant artefacts<br />

in a baseline installation of Windows 7 [Section 6.3]. Section 6.4 identifies the<br />

structure of the thumbnail cache components. In Section 6.5 the behaviour of<br />

the thumbnail cache is identified through experimentation, this is followed by a<br />

review of artefacts related to the thumbnail cache which are present on the<br />

operating system [Section 6.6]. Section 6.7 looks at the effect of tampering<br />

with data contained within the thumbnail cache; Section 6.8 looks at forming a<br />

Page<br />

105

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!