25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In each experiment a single variable was altered on all of the files; for example<br />

variables included: changing the file path, changing the volume the file was<br />

stored on, changing dates/times of both the system and the files. <strong>After</strong> each test<br />

the resulting thumbnail cache was extracted and compared with the original<br />

thumbnail cache; therefore any changes made to the thumbnail cache ID values<br />

could be identified. The results of this testing have shown this ID is comprised<br />

of data relating to the user file; it has been identified that the thumbnail cache ID<br />

is related to the volume, MFT data and the type of the file.<br />

This suggests that there is no straightforward way of recovering the file path<br />

from the thumbnail cache ID; however, in Section 6.6.1 the thumbnail cache ID<br />

is used to form a relationship through the Windows Desktop Search database.<br />

6.8.4 Event timeline<br />

It is possible to identify the order user created files were added to the thumbnail<br />

cache by identifying their position in the individual thumbnail cache files.<br />

Section 6.6.4 identified that it is possible for subrecords which do not contain<br />

visual thumbnails to move closer to the top of thumbnail cache files over time.<br />

Section 6.5.1 described an experiment which suggested that new subrecords<br />

containing visual thumbnails were appended to the bottom of the thumbnail<br />

cache files; they also maintained their relative positions in the thumbnail cache<br />

overtime. Therefore for user generated files the related subrecords in the file<br />

appear in the order they were created by the system. This can assist with<br />

creating an event timeline as a subrecord can only be created for an original<br />

source file which has a relationship with the operating system at the time of<br />

creation. A relationship between the original source file and the operating<br />

system is defined as the file being viewable within the operating system. In<br />

order to add extra data to the event timeline it is possible to add metadata<br />

recovered from the subrecords, windows.edb, and the user created source file.<br />

Page<br />

147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!