25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

analysing the file type it is possible to concentrate on typical user behaviour<br />

instead of the bias towards the known information; this could be followed up<br />

with a set of experiments attempting to alter the known variables. A comparison<br />

of the results from the initial user experiments and those achieved from the<br />

second set of experimentation provide a wider insight into the file and potential<br />

sources of further investigation.<br />

This research has highlighted the importance of contextual analysis of digital<br />

artefacts by showing the difference small variations in file structures and<br />

differing methods of storing data relating to the same user interaction can have<br />

on the artefacts found on a system. This research has provided documentation<br />

on the structure and behaviour of thumbnail caches for digital analysts which<br />

was not previously documented in a peer reviewed publication. Whilst the<br />

research could have gone further into a study of the thumbs.db cache as this<br />

research has shown it is still implemented in Windows 7 the complex OLE2<br />

structure was felt to be too time consuming to attempt file fragment identification<br />

on this type on top of the thumbnail caches already under investigation.<br />

11.4 Thumbnail Cache File Fragment Identification<br />

A significant contribution of this research was the comparative study of file<br />

fragment identification techniques which led to the creation of a hybrid<br />

technique which improved the identification of thumbnail cache file fragments. It<br />

was necessary to adapt existing techniques to identify single file fragments. If a<br />

single method had been created for the identification the criteria for maximising<br />

the data may not have been met; by using the strengths of individual methods it<br />

was possible to maximise the identification of fragments in each classification.<br />

Whilst several common file fragment identification techniques were compared<br />

time and resource constraints did not permit the evaluation of every available<br />

Page<br />

282

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!