Data remnants analysis of document files in Windows: Microsoft 365 as a case study

被引:1
|
作者
Joun, Jihun [1 ]
Lee, Sangjin [1 ]
Park, Jungheum [1 ]
机构
[1] Korea Univ, Sch Cybersecur, 145 Anam Ro, Seoul, South Korea
关键词
Digital forensics; Data remnants; Electronic document; File tracing; Microsoft; 365;
D O I
10.1016/j.fsidi.2023.301612
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the era of digitization, electronic evidence has become increasingly important for investigations and legal proceedings. However, traditional digital forensic technologies, such as recovery and carving, face limitations because of difficulties acquiring unallocated areas intact. Furthermore, artifacts and files previously used for tracing can be easily deleted manually or via anti-forensic tools, which hinders traceability. This paper presents a novel framework to overcome these limitations. This method facilitates a more precise and comprehensive tracing of residual files through data remnants analysis, a forensic approach that investigates traces of deleted or overwritten data. By systematically constructing a dataset based on user action, we identify and analyze all data remnants within the system, thereby revealing file traces. The results of a case study on Microsoft 365 demonstrate our proposed framework's superior efficacy and accuracy compared to existing methods. Our approach offers valuable insights into data remnants analysis and contributes to digital forensic investigations conducted on Windows systems.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Book review: data analysis with microsoft excel 5.0 for windows
    Berk, K.
    Carey, P.
    Technometrics, 1997, 39 (02):
  • [2] Statistical Approach For Cloud Security: Microsoft Office 365 audit logs case study
    Letourneau, Louis-Simon
    El Jabri, Chaymae
    Frappier, Marc
    Tardif, Pierre-Martin
    Lepine, Guy
    Boisvert, Guillaume
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN-W 2021), 2021, : 15 - 18
  • [3] Semantic Representation of Cloud Services: a Case Study for Microsoft Windows Azure
    Di Martino, Beniamino
    Cretella, Giuseppina
    Esposito, Antonio
    Sperandeo, Raffaele Giulio
    2014 INTERNATIONAL CONFERENCE ON INTELLIGENT NETWORKING AND COLLABORATIVE SYSTEMS (INCOS), 2014, : 647 - 652
  • [4] Scientific Data Analysis Toolkit: A Versatile Add-in to Microsoft Excel for Windows
    Halper, Arthur M.
    Frye, Ephen L.
    Marzzacco, Harles J.
    JOURNAL OF CHEMICAL EDUCATION, 2018, 95 (06) : 1063 - 1068
  • [5] Crash data collection: A windows case study
    Ganapathi, A
    Patterson, D
    2005 INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2005, : 280 - 285
  • [6] COMPARATIVE ANALYSIS OF NEUTRON DATA FILES AS A SENSITIVITY STUDY
    SEGEV, M
    YIFTAH, S
    GUR, Y
    GITTER, L
    NUCLEAR SCIENCE AND ENGINEERING, 1974, 55 (01) : 103 - 104
  • [7] Obtaining subject data from log files using deep log analysis: case study OhioLINK
    Huntington, Paul
    Nicholas, David
    Jamali, Hamid R.
    Watkinson, Anthony
    JOURNAL OF INFORMATION SCIENCE, 2006, 32 (04) : 299 - 308
  • [8] Improving Quality of Data Exchange Files. An Industrial Case Study
    Fleck, Guenter
    Moser, Michael
    Pichler, Josef
    PRODUCT-FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROFES 2019, 2019, 11915 : 161 - 175
  • [9] Microsoft Open Government Data Initiative (OGDI), Eye on Earth Case Study
    Jiricek, Zdenek
    Di Massimo, Francesa
    ENVIRONMENTAL SOFTWARE SYSTEMS: FRAMEWORKS OF EENVIRONMENT, 2011, 359 : 26 - +
  • [10] Digital forensic analysis of encrypted database files in instant messaging applications on Windows operating systems: Case study with KakaoTalk, NateOn and QQ messenger
    Choi, Jusop
    Yu, Jaegwan
    Hyun, Sangwon
    Kim, Hyoungshick
    DIGITAL INVESTIGATION, 2019, 28 : S50 - S59