Time anchoring artifacts for digital forensic event reconstruction

Ref. 2600

Dataset Overview

Dataset title

Time anchoring artifacts for digital forensic event reconstruction

Canonical DOI

Used to cite the entire dataset, regardless of version updates.

https://doi.org/10.48657/7jwv-rf37

DOI

Used to cite a specific dataset version.

https://doi.org/10.48657/55mc-5440

Dataset description language

English

Data URL

-

Data Availability

-

Dataset Description

This dataset is an ensemble of artifacts extracted from four Windows disk images, analyzed and discussed in the following paper (publication in progress): C. Vanini, C. J. Hargreaves, H. van Beek, F. Breitinger, ``Was the Clock Correct? Exploring Timestamp Interpretation Through Time Anchors for Digital Forensic Event Reconstruction". Forensic Science International: Digital Investigation, 2024. This paper deals with timestamp interpretation and addresses the problem of incorrect clocks. When this system time is skewed due to tampering, natural clock drift, or system malfunctions, recorded timestamps will not reflect the actual times the (real-world) events occurred. These disk images were created as part of two multi-part controlled experiments that illustrate the application of concepts defined in the paper. For this work, only the following artifacts were extracted and are included in this dataset: the Google Chrome History database, Google Chrome cache files, and several Windows Event Logs. These artifacts contain what we refer to as `time anchors' or `time anomalies' and can be used to assess the correctness of system clocks.

Remarks about the documentation

The structure and details of the artifacts uploaded in this repository can be found in the README.txt file.

Version number

1.0

Embargo end date

-

Publication date

01.05.2024

Version notes

Version 1.0

Bibliographical citation

Vanini, C., Hargreaves, C. J., Breitinger, F., & van Beek, H. (2024). Time anchoring artifacts for digital forensic event reconstruction (Version 1.0.0) [Data set]. UNIL data service. https://doi.org/10.48657/55mc-5440

DIP MD5 hash

e2cdcbbf7853bb6888773bbc08ab5905

Dataset contents

swissubase_2600_1_0.zip
metadata.yaml