25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

information about hiding your actions. This growth of understanding makes it<br />

more likely that a user wishing to hide information relating to their activities may<br />

seek to remove sources of potential artefacts such as the thumbnail cache. If<br />

the thumbnail cache is deleted it can still be found in unallocated space;<br />

potentially fragments of the thumbnail cache may exist in unallocated space for<br />

a significant time after deletion. Whilst the evidential value of fragments of data<br />

recovered from unallocated space may be less than a complete file the<br />

fragments have the potential to provide information that is not available in the<br />

live file set and which may provide vital information to prove or disprove a<br />

hypothesis.<br />

This research has shown that the ability to understand a file format can improve<br />

the ability to construct methods for the identification and reassembly of file<br />

fragments. This was highlighted by the creation of proof of concept software<br />

which implemented a hybrid identification approach which was refined using<br />

structural and syntactical knowledge about the file identified during this<br />

research. Further support for the importance of understanding a file type came<br />

from the use of this information in producing specific reassembly methods; each<br />

method relied upon unique file characteristics to reassemble the files as<br />

accurately as possible.<br />

This research has shown the structure and behaviour of common operating<br />

system thumbnail caches and highlighted the importance of contextual analysis<br />

of an artefact in order to fully understand the user and system behaviour it<br />

represents. The methodologies produced for the identification and reassembly<br />

of thumbnail cache file types showed that there are some forms of information<br />

which may only be retrieved from unallocated space. Whilst a complete<br />

thumbnail cache in a live file set gives an analyst the opportunity to develop<br />

relationships and construct a detailed contextual analysis of the systems<br />

behaviour deleted thumbnail cache artefacts may also assist in an analysis. For<br />

example thumbnail caches in unallocated space may belong to previous<br />

Page<br />

294

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!