Time anchoring artifacts for digital forensic event reconstruction

Ref. 2600

Datensatzübersicht

Datensatz-Titel

Time anchoring artifacts for digital forensic event reconstruction

Kanonischer DOI

Ermöglicht das Zitieren des gesamten Datensatzes, unabhängig von Versionen.

https://doi.org/10.48657/7jwv-rf37

DOI

Ermöglicht das Zitieren einer spezifischen Datensatzversion.

https://doi.org/10.48657/55mc-5440

Sprache der Datensatzbeschreibung

Englisch

Datensatz URL

-

Verfügbarkeit der Daten

-

Datensatzbeschreibung

This dataset is an ensemble of artifacts extracted from four Windows disk images, analyzed and discussed in the following paper (publication in progress): C. Vanini, C. J. Hargreaves, H. van Beek, F. Breitinger, ``Was the Clock Correct? Exploring Timestamp Interpretation Through Time Anchors for Digital Forensic Event Reconstruction". Forensic Science International: Digital Investigation, 2024. This paper deals with timestamp interpretation and addresses the problem of incorrect clocks. When this system time is skewed due to tampering, natural clock drift, or system malfunctions, recorded timestamps will not reflect the actual times the (real-world) events occurred. These disk images were created as part of two multi-part controlled experiments that illustrate the application of concepts defined in the paper. For this work, only the following artifacts were extracted and are included in this dataset: the Google Chrome History database, Google Chrome cache files, and several Windows Event Logs. These artifacts contain what we refer to as `time anchors' or `time anomalies' and can be used to assess the correctness of system clocks.

Bemerkungen zur Dokumentation

The structure and details of the artifacts uploaded in this repository can be found in the README.txt file.

Versionsnummer

1.0

Enddatum des Embargos

-

Publikationsdatum

01.05.2024

Hinweise zur Version

Version 1.0

Bibliografische Zitierung

Vanini, C., Hargreaves, C. J., Breitinger, F., & van Beek, H. (2024). Time anchoring artifacts for digital forensic event reconstruction (Version 1.0.0) [Data set]. UNIL data service. https://doi.org/10.48657/55mc-5440

MD5-Hash des DIP

e2cdcbbf7853bb6888773bbc08ab5905

Inhalt des Datensatzes

swissubase_2600_1_0.zip
metadata.yaml