25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

available for office documents; therefore users may still create files using the<br />

original OLE2 structure. It is likely that any identification of thumbs.db fragments<br />

will have similarities with those from office documents making them a likely<br />

source of false positives, however it may be possible to generalise the methods<br />

used for identification to include these structures.<br />

Vista introduced a new thumbnail cache format, which centralised the holding of<br />

thumbnails for each user. This centralised cache consists of six files; each<br />

object has a record in the index file which has references for up to four different<br />

sized thumbnails of the object, each stored in a file for their size range, the<br />

purpose of the sixth file is not yet known. The four image files hold thumbnails<br />

which are up to 32 x 32, 96 x 96, 256 x 256 and 1024 x 1024 pixels in size. The<br />

introduction of larger thumbnails provides the opportunity for a more detailed<br />

image, which can show readable text, enhancing their forensic value. To show a<br />

relationship between the original object and an entry in the thumbnail cache it is<br />

necessary to establish the path where the object resided when the entry was<br />

created or modified. The path information is not stored in the cache itself, but<br />

the windows.edb file [Douglas, 2009], whilst the remainder of the metadata is<br />

located in the cache. Windows 7 uses the same centralised six file thumbnail<br />

cache format as Windows Vista, but as yet it is unclear if the structure, its<br />

interaction with the rest of the operating system, and the resulting forensic<br />

artefacts, will be the same.<br />

Ubuntu 10.10 uses Nautilus for file management, thumbnails are stored as<br />

images in a centralised folder, and thumbnails can be stored for a variety of<br />

image formats and PDF files [Ubuntu, 2010]. Open Office [2012] created a<br />

script which allows thumbnails for open office documents to be created and<br />

stored, increasing the variety of images found in the thumbnail cache. A unique<br />

feature of Nautilus’ thumbnail implementation is the creation of audio<br />

thumbnails; putting your mouse on an audio file will result in the file playing,<br />

allowing the user to browse in a similar way to image formats. Further<br />

Page 35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!