Dissertation > Excellent graduate degree dissertation topics show
A Study on the Windows Log Forensic and Recovery Technology
Author: WangPeng
Tutor: ZhengNing;LouYongJian
School: Hangzhou University of Electronic Science and Technology
Course: Applied Computer Technology
Keywords: Computer forensics Event log File carving Content character EVT files EVTX files Binary XML stream
CLC: TP316.7
Type: Master's thesis
Year: 2009
Downloads: 202
Quote: 1
Read: Download Dissertation
Abstract
|
Nowadays, computer crimes and computer intrusions are common incidents along with the development of information technology. Computer forensic technology, the key technology to combat computer-related crimes, has emerged. Forensic examiners are paying more attention to the protection and recovery of digital proofs during forensic process. File carving, a special data recovery technique and predominant topic of computer forensic research, can recover files from unstructured original disk image without depending on file system. Forensic analysts can recover data from unallocated disc space or corrupted file system, memory or swap space, ensuring the carved files are original or intact.we introduces the procedure of computer forensic, especially event log forensic and its research status, discussing the difficulties that examiners need more effective file carving techniques to cope with the scenarios such as deleted or corrupted files, formatted or uninstalled file system, etc. File carving technique developed quickly in recent years, many novel methods were applied. This paper significantly researches these file carving methods and discusses each method’s merit and limitation, it also learns the internal structures and content characters of many file types. The latest research results in event log file carving are discussed, and localization and challenge of existing event log file carving are summarizedBase on in-depth study of content features and internal structure of the log file, combing with the use of information statistics, data structure, semantic knowledge, we apply theory of content characters into the event log file carving technique. This file carving method can recover the EVT files from unstructured original disk image, including header/trailer/offset of trailer validation, file wrapping and internal structure validation, entropy difference validation, file fragment reassembly validation and semantic validation. Without any manual intervention, the carving method can effectively reassemble the fragments of the EVT file, especially out-of-order fragments. This method and other carving tools are tested over three real windows disc images, experimental result shows that this method is better than others.Based on the preceding experiences, theories, experiments on Windows NT event log files, this paper presents in-depth study of a brand-new log file format—EVTX file format under Windows vista system. The presented evtx file carving method which is based on content character includes some validation steps: header/chunk num/chunk check validation, chunk-based fragment search and reassembly validation, single record extraction and format transformation. This carving method can carve automatically the contiguous Evtx file and the fragmented Evtx file in the original disc image, no matter in-order or disorder.
|
Related Dissertations
- A Study on the Application of Artificial Intelligence in Direct Torque Control,TN919.81
- Research and Application of cluster technology - based job management system,TP315
- Based on the Windows platform log extraction and analysis,TP311.13
- The Design of Computer Forensics Model Based on Windows Log,D918.2
- The Key Technology Research on Computer Intrusion Forensics,TP393.08
- Research on Asymmetric SSL Tunnel and Other Key Technologies of SSL-based VPN,TP393.1
- Windows-based computer forensics research journal,TP309
- Computer -based the indirect virtual machine simulation runtime environment to reproduce,TP391.9
- Research on the Identification Technique of Cracked File Type Information in Windows,TP391.1
- Computer forensics technology research,TP399
- Data Mining in computer forensics analysis applied research and system design,TP311.13
- Application and Research of Computer Forensics Technology,TP399-C2
- An Inference with Uncertainty-Based Security Auditing System in DRM,TP393.08
- Deng Xiaoping’s Concept of Just Rules,A849.1
- The Analysis System of Computer Network Forensics,TP399-C2
- The Research of Dynamic Network Intrusion Forensics Based on Multi-Agent,TP393.08
- E-mail Event Traces Searching and Clue Synthesis,TP393.098
- UNIX system-based computer forensics Architecture,TP399
- A Research on Evidence-Collecting Technique of Network Crime on the Basis of NIDS,TP393.08
- Computer forensics system data encryption and data analysis research and implementation,TP309.7
- On the computer forensics and Norms,D918.2
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer software > Operating system > Windows operating system
© 2012 www.DissertationTopic.Net Mobile
|