25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Thumbnail caches contain metadata, such as the original files modification time,<br />

location and name [Hurlbut, 2005]. This information is useful to corroborate<br />

other metadata sources related to the file; this is particularly useful when only<br />

fragments of the original file are available. The metadata and associated visual<br />

thumbnail are not always removed from the cache when the original file is<br />

deleted or moved. This can provide the analyst with information about the event<br />

timeline for a file and can also be useful when producing evidence from deleted<br />

files.<br />

2.5 Conclusion<br />

This chapter has analysed research related to this thesis; this began with an<br />

overview of the field of Forensic Computing. The methodologies and tools used<br />

in this field were examined along with current opportunities for research. It was<br />

identified that artefacts in new operating systems such as the changes to the<br />

thumbnail cache were of interest to analysts and therefore understanding their<br />

structure and behaviour is an area for current research.<br />

It was also noted that anti forensic techniques may be employed to remove<br />

sources of potential information, therefore an area of current research would be<br />

to identify and analyse any potentially useful fragments remaining on the<br />

storage media. This Chapter examined data and information, focusing on how<br />

information is stored and the forensic implications of metadata. It is important to<br />

understand both the structure of the thumbnail cache and the storage media to<br />

ensure an artefact is analysed in its original context.<br />

<strong>Final</strong>ly operating system thumbnail caches were discussed, it was highlighted<br />

that whilst the general purpose of a thumbnail cache is defined each operating<br />

system implements the construct in its own way. As well as the difference in<br />

Page 38

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!