首页    期刊浏览 2024年12月05日 星期四
登录注册

文章基本信息

  • 标题:Forensic Analysis of the Windows 7 Registry
  • 本地全文:下载
  • 作者:Khawla Abdulla Alghafli ; Andrew Jones ; Thomas Anthony Martin
  • 期刊名称:Journal of Digital Forensics, Security and Law
  • 印刷版ISSN:1558-7215
  • 电子版ISSN:1558-7223
  • 出版年度:2010
  • 卷号:4
  • 期号:1708
  • 页码:5-30
  • 语种:English
  • 出版社:Association of Digital Forensics, Security and Law
  • 摘要:The recovery of digital evidence of crimes from storage media is an increasingly time consuming process as the capacity of the storage media is in a state of constant growth. It is also a difficult and complex task for the forensic investigator to analyse all of the locations in the storage media. These two factors, when combined, may result in a delay in bringing a case to court. The concept of this paper is to start the initial forensic analysis of the storage media in locations that are most likely to contain digital evidence, the Windows Registry. Consequently, the forensic analysis process and the recovery of digital evidence may take less time than would otherwise be required. In this paper, the Registry structure of Windows 7 is discussed together with several elements of information within the Registry of Windows 7 that may be valuable to a forensic investigator. These elements were categorized into five groups which are system, application, networks, attached devices and the history lists. We have discussed the values of identified elements to a forensic investigator. Also, a tool was implemented to perform the function of extracting these elements and presents them in usable form to a forensics investigator.
国家哲学社会科学文献中心版权所有