Data remnants analysis of document files in Windows: Microsoft 365 as a case study

被引:1
|
作者
Joun, Jihun [1 ]
Lee, Sangjin [1 ]
Park, Jungheum [1 ]
机构
[1] Korea Univ, Sch Cybersecur, 145 Anam Ro, Seoul, South Korea
关键词
Digital forensics; Data remnants; Electronic document; File tracing; Microsoft; 365;
D O I
10.1016/j.fsidi.2023.301612
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the era of digitization, electronic evidence has become increasingly important for investigations and legal proceedings. However, traditional digital forensic technologies, such as recovery and carving, face limitations because of difficulties acquiring unallocated areas intact. Furthermore, artifacts and files previously used for tracing can be easily deleted manually or via anti-forensic tools, which hinders traceability. This paper presents a novel framework to overcome these limitations. This method facilitates a more precise and comprehensive tracing of residual files through data remnants analysis, a forensic approach that investigates traces of deleted or overwritten data. By systematically constructing a dataset based on user action, we identify and analyze all data remnants within the system, thereby revealing file traces. The results of a case study on Microsoft 365 demonstrate our proposed framework's superior efficacy and accuracy compared to existing methods. Our approach offers valuable insights into data remnants analysis and contributes to digital forensic investigations conducted on Windows systems.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Remote data monitoring and data analysis for substations - A case study in implementation
    Dolezilek, David
    McDermott, Brian
    2006 POWER SYSTEMS CONFERENCE ADVANCED METERING, PROTECTION, CONTROL, COMMUNICATION, AND DISTRIBUTED RESOURCES, 2006, : 493 - +
  • [32] Interactive and dynamic graphics for data analysis: A case study on quasar data
    Cook, D
    STATISTICAL CHALLENGES IN ASTRONOMY, 2003, : 255 - 264
  • [33] Data Mining Methods for Traffic Monitoring Data Analysis: A case study
    Gecchele, Gregorio
    Rossi, Riccardo
    Gastaldi, Massimiliano
    Caprini, Armando
    STATE OF THE ART IN THE EUROPEAN QUANTITATIVE ORIENTED TRANSPORTATION AND LOGISTICS RESEARCH, 2011: 14TH EURO WORKING GROUP ON TRANSPORTATION & 26TH MINI EURO CONFERENCE & 1ST EUROPEAN SCIENTIFIC CONFERENCE ON AIR TRANSPORT, 2011, 20 : 455 - 464
  • [34] Automation of Post-Order Costing Analysis ByUsing Visual Basic For Applications In Microsoft Excel: A Case Study
    Kalwar, Muhammad Ahmed
    Khan, Muhammad Ali
    Wassan, Asif Nawaz
    Phul, Zuhaib
    Shaikh, Shakeel Ahmed
    Marri, Hussain Bux
    WPOM-WORKING PAPERS ON OPERATIONS MANAGEMENT, 2023, 14 (02): : 101 - 136
  • [35] Application of Rigour and Credibility in Qualitative Document Analysis: Lessons Learnt from a Case Study
    Wood, Leanne M.
    Sebar, Bernadette
    Vecchio, Nerina
    QUALITATIVE REPORT, 2020, 25 (02): : 456 - 470
  • [36] GO TO THE PEOPLE: A HISTORICAL CASE STUDY & POLICY ANALYSIS OF MASSACHUSETTS AND OPEN STANDARD DOCUMENT
    Kennis, Andrew
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON STANDARDIZATION AND INNOVATION IN INFORMATION TECHNOLOGY, SIIT 2009, 2010, : 133 - 146
  • [37] Interactive data analysis in a manufacturing setting - A case study
    James, DA
    COMPUTATIONAL STATISTICS, 1999, 14 (01) : 147 - 159
  • [38] Exploratory analysis of medical mass data: A case study
    Nagel, M
    COMPUTATIONAL STATISTICS, 1996, 11 (04) : 429 - 448
  • [39] DATA MINING IN TELECOMMUNICATIONS: CASE STUDY OF CLUSTER ANALYSIS
    Bach, Mirjana Pejic
    Simicevic, Vanja
    Leskovic, Darko
    ANNALS OF DAAAM FOR 2009 & PROCEEDINGS OF THE 20TH INTERNATIONAL DAAAM SYMPOSIUM, 2009, 20 : 491 - 492
  • [40] Interactive data analysis in a manufacturing setting — A case study
    David A. James
    Computational Statistics, 1999, 14 : 147 - 159