25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

throughout this research. Within this research it has been decided that the focus<br />

will be on artefacts most likely to assist in an investigation; the methodologies<br />

created can then be generalised to other less frequently observed artefacts.<br />

3.4 Tools<br />

Throughout this research the most commonly used tool will be a virtual<br />

machine, specifically VMWare Workstation version 7 [2011]; the virtual<br />

machines will originally be created as part of the structural and behavioural<br />

studies and will then be used as file fragments for the identification and<br />

reassembly research. The use of a virtual machine will enable a clean baseline<br />

of each operating system to be created which can be specifically manipulated<br />

for each individual experiment. The results of each experiment can then be<br />

compared with the original baseline virtual machine to identify the differences.<br />

The use of flat virtual hard disks means the hard disk was equivalent to a<br />

standard uncompressed hard drive image and can therefore be examined using<br />

tools and methodologies that would be used during a typical analysis.<br />

Procmon [Microsoft, 2012b] will be used during the experiments in Windows<br />

systems to log the processes being called; the logs will be stored in CSV format<br />

and the results will be examined in Procmon and Excel to identify potentially<br />

interesting processes. Procmon results may provide significant insight into the<br />

processes being called when thumbnails were being created and displayed.<br />

A hexadecimal editor called Winhex [Fleishmamn, 2008] will be the primary tool<br />

used in the examination of the virtual hard disks; the Winhex software allows<br />

the file system of the disks to be viewed, which will assist in locating and<br />

reading artefacts in the live file set. Functionality, such as templates and basic<br />

scripting, will be used to assist in ascertaining the structure of the thumbnail<br />

cache and related files; once the templates are created they will be applied to<br />

Page 44

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!