Logo des Repositoriums
 

Post-mortem path correlation based on the NT Object Manager in Windows 1x systems

dc.contributor.authorHelfer, Dominic
dc.contributor.authorRothe, Felix
dc.contributor.authorBodach, Ronny
dc.contributor.editorKlein, Maike
dc.contributor.editorKrupka, Daniel
dc.contributor.editorWinter, Cornelia
dc.contributor.editorWohlgemuth, Volker
dc.date.accessioned2023-11-29T14:50:32Z
dc.date.available2023-11-29T14:50:32Z
dc.date.issued2023
dc.description.abstractThe specifications of file and directory paths in forensic artifacts of Windows 1x systems are not uniform. A correlation of paths is needed to prove the hypothesis that two paths in different artifacts describe the same file. During runtime of Windows, this correlation is managed inside the NT Object Manager [Al22]. The available information of the NT Object Manager is lost when Windows is shut down, so an analyst with the appropriate knowledge and experience must perform the correlation of paths manually. A mapping of the NT Object Manager is required to develop forensic tools that allow an automated correlation of paths. The mapping was used to develop a reconstruction approach based on an empirical study of differently configured Windows 1x systems. This allows for post-mortem path correlation using non-volatile data.en
dc.identifier.doi10.18420/inf2023_70
dc.identifier.isbn978-3-88579-731-9
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/43193
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofINFORMATIK 2023 - Designing Futures: Zukünfte gestalten
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-337
dc.subjectDigital Forensics
dc.subjectPath Correlation
dc.subjectWindows Artifacts
dc.subjectNT-Object Manager
dc.titlePost-mortem path correlation based on the NT Object Manager in Windows 1x systemsen
dc.typeText/Conference Paper
gi.citation.endPage606
gi.citation.publisherPlaceBonn
gi.citation.startPage597
gi.conference.date26.-29. September 2023
gi.conference.locationBerlin
gi.conference.sessiontitleCybersecurity & Privatsphäre - 3. International Workshop on Digital Forensics / IWDF3

Dateien

Originalbündel
1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
03_02_03_Helfer.pdf
Größe:
534.26 KB
Format:
Adobe Portable Document Format