@article{ART003029500},
author={Song JongHwa and Hyun-Seob Lee},
title={A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS},
journal={Journal of Internet of Things and Convergence},
issn={2466-0078},
year={2023},
volume={9},
number={6},
pages={23-28},
doi={10.20465/KIOTS.2023.9.6.023}
TY - JOUR
AU - Song JongHwa
AU - Hyun-Seob Lee
TI - A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS
JO - Journal of Internet of Things and Convergence
PY - 2023
VL - 9
IS - 6
PB - The Korea Internet of Things Society
SP - 23
EP - 28
SN - 2466-0078
AB - Windows operating system generates various logs with timestamps. Timestamp tampering is an act of anti-forensics in which a suspect manipulates the timestamps of data related to a crime to conceal traces, making it difficult for analysts to reconstruct the situation of the incident. This can delay investigations or lead to the failure of obtaining crucial digital evidence. Therefore, various techniques have been developed to detect timestamp tampering. However, there is a limitation in detection if a suspect is aware of timestamp patterns and manipulates timestamps skillfully or alters system artifacts used in timestamp tampering detection. In this paper, a method is designed to detect changes in timestamps, even if a suspect alters the timestamp of a file on a storage device, it is challenging to do so with precision beyond millisecond order. In the proposed detection method, the first step involves verifying the timestamp of a file suspected of tampering to determine its write time. Subsequently, the confirmed time is compared with the file size recorded within that time, taking into consideration the performance of the storage device. Finally, the total capacity of files written at a specific time is calculated, and this is compared with the maximum input and output performance of the storage device to detect any potential file tampering.
KW - Timestamp;Manipulation Detection;Storage;NTFS;Anti-forensics
DO - 10.20465/KIOTS.2023.9.6.023
ER -
Song JongHwa and Hyun-Seob Lee. (2023). A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS. Journal of Internet of Things and Convergence, 9(6), 23-28.
Song JongHwa and Hyun-Seob Lee. 2023, "A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS", Journal of Internet of Things and Convergence, vol.9, no.6 pp.23-28. Available from: doi:10.20465/KIOTS.2023.9.6.023
Song JongHwa, Hyun-Seob Lee "A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS" Journal of Internet of Things and Convergence 9.6 pp.23-28 (2023) : 23.
Song JongHwa, Hyun-Seob Lee. A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS. 2023; 9(6), 23-28. Available from: doi:10.20465/KIOTS.2023.9.6.023
Song JongHwa and Hyun-Seob Lee. "A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS" Journal of Internet of Things and Convergence 9, no.6 (2023) : 23-28.doi: 10.20465/KIOTS.2023.9.6.023
Song JongHwa; Hyun-Seob Lee. A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS. Journal of Internet of Things and Convergence, 9(6), 23-28. doi: 10.20465/KIOTS.2023.9.6.023
Song JongHwa; Hyun-Seob Lee. A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS. Journal of Internet of Things and Convergence. 2023; 9(6) 23-28. doi: 10.20465/KIOTS.2023.9.6.023
Song JongHwa, Hyun-Seob Lee. A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS. 2023; 9(6), 23-28. Available from: doi:10.20465/KIOTS.2023.9.6.023
Song JongHwa and Hyun-Seob Lee. "A Design of Timestamp Manipulation Detection Method using Storage Performance in NTFS" Journal of Internet of Things and Convergence 9, no.6 (2023) : 23-28.doi: 10.20465/KIOTS.2023.9.6.023