期刊文献+

Windows 8回收站取证分析 被引量:4

Recycle Bin Forensic for Windows 8
下载PDF
导出
摘要 在计算机取证过程中,对于删除文件的分析常常提供有价值的信息。知道在哪里找到被删除文件并且能够理解文件被删除过程中产生的元数据,这是一个合格的计算机取证人员必备的素质。本文对Window 8系统的回收站与传统的Windows XP系统的回收站的相似点和不同点进行了对比分析,并详细说明了Windows 8系统回收站的工作细节,以期为计算机取证人员提供帮助。 Analysis of deleted files often provides useful information for the forensic computer examiner. Knowing where to find the deleted files, and how to interpret the metadata associated with the file's deletion, make up the cornerstone of a successful forensic computer examination. In this paper, the author compares and contrasts the similarities and differences of the Recycle Bin of the Windows 8 between the Recycle Bin of the Windows XP Operating System. In this investigation, the author points-out the details of each implementation that are of interest for the forensic computer examiner.
作者 宋冰
机构地区 河南警察学院
出处 《信息安全与技术》 2012年第12期50-52,共3页
关键词 计算机取证 WINDOWS 8 回收站 SID computer forensics Windows 8 recycle bin SID
  • 相关文献

参考文献3

  • 1Microsoft Help and Support. "How the Recycle Bin Stores Files"[OL].http://support.microsoft.com/kb/136517,2009.
  • 2Machor,Mitchell. The Forensic Analysis of the Microsoft Windows Vista Recycle Bin[OL].http://www.forensicfocus.com/downloads/forensic-analysis-vista-recycle-bin.pdf,.
  • 3孙奕.Widows 7环境下电子取证特点分析[J].信息网络安全,2010(11):43-45. 被引量:8

共引文献7

同被引文献13

  • 1Wikipedia.Features new to Windows 8[EB/OL].http://en.wikipedi a.org/wiki/Features new to Windows_8,2012.
  • 2Windows 8 Forensics[EB/OL].http://computerforensics.champlain. edu/blog/windows-8-forensics,2012.
  • 3Amanda C.F.Thomson.Windows 8 Forensic Guide[EB/OL].http: //prop ellerheadforensics.files.wordpress.com/2012~05~thomson_ windows-8-forensic-guide2.pdf,2012.
  • 4Windows 8 FileHistory[EB/OL].http://randomthoughtsofforensics. blog spot.hk/search/label/Windows%208,2012.
  • 5Windows 8 typedURLsTime [EB/OL].http://dfstream.blogspot. hk/2012/05/windows-8-typedurlstime.html,2012.
  • 6What is INFO2 File Hidden in Recycled or Recycler Folder? [EB/OL].https://www.raymond.cc/blog/what-is-info2-file-hid- den-in -recycled -or-recycler-folder/.
  • 7McAfee Software royalty-Free License[EB/OL].http://www.mcafee. com/us/downloads/free-tools/termsofuse . aspx ? url--Download thistoolnow#.
  • 8孙奕.Widows 7环境下电子取证特点分析[J].信息网络安全,2010(11):43-45. 被引量:8
  • 9王宁,刘志军,李佟鸿,麦永浩.Windows 7系统注册表的取证分析[J].警察技术,2013(3):39-41. 被引量:10
  • 10向涛,苟木理.Windows 8下基于镜像文件的内存取证研究[J].计算机工程与应用,2013,49(19):63-67. 被引量:3

引证文献4

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部