25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

6.10.2 Interpretation of Results<br />

An analyst may be presented with a scenario where doubt is cast upon whether<br />

the system was working properly at the time of the alleged incident. The<br />

manipulation of thumbnail cache artefacts was evaluated in Section 6.7. The<br />

section showed methods of verifying and corroborating the artefacts in the<br />

thumbnail cache to ascertain the likelihood they were created whilst the system<br />

was working normally. It is a non-trivial task to alter all the relationships within<br />

the system which relate to the thumbnail cache; therefore it is likely an analyst<br />

would find some information to cast doubt on the manipulated data. The<br />

experiments performed in Sections 6.4 - 6.6 were based on a system<br />

functioning normally and document the expected results of certain behaviours.<br />

By establishing relationships between the thumbnail cache and the rest of the<br />

system it is possible to analyse the information in the thumbnail cache in the<br />

context of the general system activity; therefore the behaviour an artefact<br />

represents can be established [Section 6.5].<br />

Thumbnail cache artefacts can be corroborated by forming relationships with<br />

other system artefacts [Section 6.6]. Artefacts such as a GUID within a nonstandard<br />

thumbnail cache entry can be difficult for an analyst to place into<br />

context without supplementary information. However if a relationship is formed<br />

between the thumbnail cache entry and the registry it is possible to determine<br />

the meaning of the GUID and create further relationships to provide additional<br />

information. Relationships between thumbnail cache artefacts and the original<br />

source file can also assist an analyst; the potential system behaviour identified<br />

from thumbnail cache and corroborating artefacts can be linked to a specific file.<br />

By forming relationships with other sources of information and continuing to<br />

build relationships until all the links between artefacts are identified it is possible<br />

to maximise the corroboration of thumbnail cache artefacts. The thumbnail<br />

Page<br />

154

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!