25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

cache artefacts can be corroborated by forming relationships with other system<br />

artefacts and the original source file [Sections 6.6, 6.8]; this shows that multiple<br />

sources of corroboration for thumbnail cache evidence can be identified and in<br />

turn those sources can be corroborated.<br />

In Windows 7 there is a centralised thumbnail cache for each user which<br />

contains six binary files; therefore in order to maximise the data recovered<br />

from the live thumbnail cache it is necessary to extract the six binary files and<br />

examine them. Windows 7 also uses the thumbs.db format, which are directory<br />

specific thumbnail cache files. In a live file system these can be identified by<br />

searching for the filename thumbs.db; they can then be extracted and analysed.<br />

The carving of data relating to the Windows 7 centralised thumbnail cache from<br />

unallocated space is discussed in Chapters 7-9.<br />

The thumbnail cache structure and syntax identified in Section 6.4 permit the<br />

automation of extracting data from the file formats; they also permit the<br />

identification and reassembly of file fragments from unallocated space.<br />

6.11 Conclusion<br />

This chapter has examined the structure and behaviour of the operating system<br />

thumbnail cache implemented within Windows 7. Within Windows Vista, the<br />

thumbnail cache implementation changed significantly from Windows XP by<br />

using a centralised thumbnail cache for each user, this implementation was<br />

continued in Windows 7 with slight differences in the structure of records and<br />

subrecords. The thumbnail cache contains visual thumbnail records alongside<br />

GUID information, active drive letters and network places. Records are added to<br />

the cache, with a new subrecord being added to the bottom of the thumbcache<br />

files. Some records are deleted periodically, however this is application specific.<br />

The subrecords contain checksums to assist in authenticating the data;<br />

Page<br />

155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!