Michael Galhuber

dblp:299/5766 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2024
0009-0002-2529-7405ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2024 Timestamp-based Application Fingerprinting in NTFS
abstract
The NTFS file system contains crucial (meta-)information that plays a significant role in forensic analysis. Among these details are the eight file timestamps, which serve as the foundation for constructing a reliable timeline. However, beyond their temporal significance, these timestamps also harbor valuable clues. Specifically, the patterns of file handling by user programs are reflected in these timestamps. By analyzing these “fingerprint” patterns, it becomes possible to identify the applications responsible for creating and editing files. This discovery facilitates event reconstruction in digital forensics investigations.
Michael Galhuber, Robert Luh
ARES1
2021 Time for Truth: Forensic Analysis of NTFS Timestamps
abstract
Timeline forgery a widely employed technique in computer anti-forensics. Numerous freely available and easy-to-use tampering tools make it difficult for forensic scientists to collect legally valid evidence and reconstruct a credible timeline. At the same time, the large number of possible file operations performed by a genuine user can result in a wide variety of timestamp patterns that pose a challenge when reconstructing a chain of events, especially since application-specific discrepancies are often disregarded.
Michael Galhuber, Robert Luh
ARES1