25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The type of a file can be identified through the flags stored in the thumbnail<br />

cache; each type of file has a specific sub-set of flags; these flags are found in<br />

the main record for each file located in the thumbcache_idx.db file [Morris,<br />

2011]. The flags can be used to identify the type of file which relates to the<br />

record, as the file type may not be obvious from a visual inspection [Section<br />

6.4.2].<br />

6.8.3 Thumbnail cache ID<br />

Each record contains a unique thumbnail cache ID which is made up of sixteen<br />

hexadecimal characters. In order to ascertain the information which was used in<br />

the formula for creating the thumbcache ID a series of tests were conducted.<br />

The tests were conducted to investigate the possibility of a simple relationship<br />

that allowed a file path of MFT ID to be determined from the thumbnail cache<br />

ID. Each test was performed in a clone of the baseline virtual machine with a<br />

set of 20 user created files stored in the current user’s “My Documents”<br />

directory; the images were viewed using Windows Explorer in order to create a<br />

baseline thumbnail cache. The files selected were: 2 BMP, 2 DOC, 2 DOCX, 2<br />

GIF, 5 JPEG, 3 PDF, 2 PPT, and 2 XLS.<br />

Figure 6-13: Restore points for the directory Explorer<br />

Page<br />

146

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!