dc.creator |
Morris, Sarah |
|
dc.creator |
Chivers, Howard |
|
dc.date |
2018-10-19T10:24:18Z |
|
dc.date |
2018-10-19T10:24:18Z |
|
dc.date |
2011-06-28 |
|
dc.date.accessioned |
2022-05-25T16:39:04Z |
|
dc.date.available |
2022-05-25T16:39:04Z |
|
dc.identifier |
Sarah Morris and Howard Chivers. An analysis of the structure and behaviour of the Windows 7 operating system thumbnail cache. Proceedings from 1st International Conference on Cybercrime, Security and Digital Forensics, 27-28 June 2011, University of Strathclyde, Glasgow, Scotland, UK. |
|
dc.identifier |
9780947649784 |
|
dc.identifier |
http://dspace.lib.cranfield.ac.uk/handle/1826/13547 |
|
dc.identifier.uri |
http://localhost:8080/xmlui/handle/CUHPOERS/182403 |
|
dc.description |
Operating systems such as Windows 7 implement a thumbnail cache structure to store visual thumbnails and associated metadata. There is no standard implementation of a thumbnail cache or its functions, which has led developers to implement their own structures and behaviour. The artefacts present within a thumbnail cache are of interest to a forensic analyst as they can provide information on files within the system which may be of use to the investigation. This research investigates the structure and behaviour of the thumbnail cache implemented in Windows 7 and shows that as well as storing information relating to visual thumbnails the cache also stores the names of networked computers, GUIDs relating to system artefacts and allocated drive letter information. It also shows that due to the behaviour of the cache, information such as records relating to files which are no longer on the system may be available, proving interesting forensic evidence. |
|
dc.language |
en |
|
dc.publisher |
University of Strathclyde, Glasgow |
|
dc.subject |
thumbnail cache |
|
dc.subject |
windows 7 |
|
dc.subject |
forensic computing |
|
dc.title |
An analysis of the structure and behaviour of the Windows 7 operating system thumbnail cache |
|
dc.type |
Conference paper |
|