25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

which have a relationship with the thumbnail cache record; therefore if<br />

tampering had occurred an analyst would identify conflicting artefacts.<br />

6.7.3 Original source file<br />

In Section 6.5 it was shown that the modification of the contents of a user file<br />

within the virtual machine would result in the corresponding record in the<br />

thumbnail cache being updated the next time it was viewed in thumbnail view. A<br />

further experiment was performed where the last modified date of 6 files were<br />

altered; the times were moved backwards by 24 hours so that the modification<br />

time of each file appeared a day earlier. The files were then viewed in Windows<br />

Explorer thumbnail view; there was a noticeable delay in displaying the visual<br />

thumbnails whilst they were regenerated. If the last modification date in the<br />

original source file is altered to a time before that stored in Windows.edb, then<br />

the thumbnail subrecord is regenerated next time it is called.<br />

It is possible to modify the contents of a file within a hexadecimal editor,<br />

therefore ensuring the files metadata remains accurate. This was identified by<br />

editing a JPEG image using WinHex version 15 running from a portable storage<br />

device attached to the virtual machine; the image was replaced by one of the<br />

same size but with noticeable visual differences. The results showed that this<br />

form of modification does not lead to the records within the thumbnail cache<br />

being updated; as the checks performed on the data show the subrecord is<br />

accurate.<br />

6.8 Forming a relationship between the thumbnail subrecords<br />

and the source files<br />

The previous section discussed ways in which the information in the thumbnail<br />

cache could potentially be manipulated; the section highlighted the importance<br />

of relationships to provide corroborating information and make unidentifiable<br />

tampering of data harder. This section discusses the artefacts that can assist in<br />

Page<br />

143

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!