25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The structures were reverse engineered based upon previous experiments in<br />

Windows Vista and the experiments documented above. The two experimental<br />

sets permitted the structure of the thumbnail cache to be reverse engineered;<br />

this provided the information documented in the following sub-sections. An<br />

analysis of the data collected was performed using a hex editor, and by<br />

comparing the different thumbnail caches based upon the actions that were<br />

taken it was possible to deduce the associated structure. Partial thumbnail<br />

cache structures have been presented on some websites [Noxa, 2008;<br />

Parsonage, 2012]. In contrast with prior works the present research adopts a<br />

systematic methodology including experiment planning and quantitative<br />

analysis of efficiency and effectiveness of the existing approaches to thumbnail<br />

fragment detection and reassembly. Any structural and syntactical information<br />

identified during this research will be added to the thumbnail cache extraction<br />

program to enable artefacts to be automatically extracted from Windows 7<br />

thumbnail caches.<br />

This section begins with an overview of the thumbnail cache directory structure;<br />

this is followed by an overview of the structures contained within the six files<br />

used in the thumbnail cache.<br />

6.4.2 The thumbnail cache directory structure<br />

In section 6.3the operating system thumbnail cache implemented in Windows 7<br />

was found to reside in a user’s home directory. Windows 7 has a centralised<br />

thumbnail cache for each user rather than the directory specific cache system<br />

used in Windows XP. This directory was shown to contain six thumbnail cache<br />

files: an index and five further files. The index holds records, which provide<br />

pointers to the location of subrecords in the remaining files; the structure of the<br />

thumbnail cache is shown in Figure 6.2.<br />

Page<br />

113

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!