+ All Categories
Home > Documents > Identification and Collection

Identification and Collection

Date post: 07-Jan-2016
Category:
Upload: jerod
View: 28 times
Download: 0 times
Share this document with a friend
Description:
Identification and Collection. INFM 718X/LBSC 708X Douglas W. Oard. “Data” Mapping. Organizational Application-al Logical Physical Geographic. Levels of Analysis. How Disks Work. Extracted From Shelly Cashman Vermatt’s Discovering Computers 2004. Windows “NTFS” File Metadata. - PowerPoint PPT Presentation
Popular Tags:
14
Identification and Collection INFM 718X/LBSC 708X Douglas W. Oard
Transcript
Page 1: Identification and Collection

Identification and Collection

INFM 718X/LBSC 708XDouglas W. Oard

Page 2: Identification and Collection

“Data” Mapping

• Organizational

• Application-al

• Logical

• Physical

• Geographic

Page 3: Identification and Collection

Levels of Analysis

Page 4: Identification and Collection

How Disks Work

Extracted From Shelly Cashman Vermatt’s Discovering Computers 2004

Page 5: Identification and Collection

Windows “NTFS” File Metadata• Time file created (or copied)– Most recent one; optionally “journaled”

• Time file content changed (or made changeable)– Most recent one; optionally “journaled”

• Time file renamed (or moved)– Most recent one

• Time file metadata created or changed– Most recent one

• Time file accessed (content or metadata)– Most recent one; optionally disabled

Page 6: Identification and Collection

Microsoft Word Metadata

• Author• Title• Dates (may not agree with NTFS!)– Created– Modified– Accessed– Printed– Each tracked change

Page 7: Identification and Collection

EXIF Image Metadata

• Time• Location• Camera manufacturer and model• Camera orientation• Exposure information (shutter speed, f stop)• Thumbnail versions– Altering the image may not change the thumbnail!

Page 8: Identification and Collection
Page 9: Identification and Collection

Email Metadata

• Message metadata– Times

• Sent• Resent• Received

– Route– In-reply-to– Attachment file type

• System metadata– Folder

Page 10: Identification and Collection

File Types

• Extensions– MyDocument.xls

• MIME type

• Magic bytes

• Supervised machine learning

Page 11: Identification and Collection
Page 12: Identification and Collection

Capture

• Imaging– Tape copy– Disk image

• Active file capture– Hardware write block– Software write blocking

• File system copy

Page 13: Identification and Collection

Culling

• Custodian

• De-NISTing– Based on NIST list of known program hashes

• Date range

Page 14: Identification and Collection

Preservation

• Future accessibility– Replication– Service copies

• Authenticity– Documented traceable process– Separately stored hashes


Recommended