期刊名称:International Journal of Advanced Research in Computer Engineering & Technology (IJARCET)
印刷版ISSN:2278-1323
出版年度:2015
卷号:4
期号:4
页码:1146-1151
出版社:Shri Pannalal Research Institute of Technolgy
摘要:Computer forensics (also known as cyber forensics) is a branch of forensic science that employs various analysis techniques to verify the facts and obtain the evidence related to computer crimes. The aim of computer forensics is to prevent computer related crimes by acquiring, analyzing and presenting the facts related to the crime. Computer forensics has been an extremely useful in solving various crimes related to cyber world. The main focus of research in this paper is time analysis of files used in windows system. The creation time, last written time, last accessed time and MFT modification time of a file are an important factor that indicates the events that have affected a computer system. The form of the time information varies with the file system and the information changes the features, depending on the user's actions such as copy, transfer or rename of files.
关键词:time analysis; MAC times; File ; system; NTFS; Digital Investigation