{"title":"Research of Recycle Bin Forensic Analysis Platform Based on XML Techniques","authors":"Gao Qinquan, Wu Shunxiang","doi":"10.1109/WCSE.2009.111","DOIUrl":null,"url":null,"abstract":"Windows Recycle Bin is an important component of the operating system and the algorithm is very important and worth exploring. Recycle Bin preserves deleted files and directories signs. So, it’s an important part to exam the control files of the Recycle Bin in computer forensic. In this paper, by parsing the structure of INFO2, we completely analyze the recovery model and algorithms of the Recycle Bin. And based on the use of XML structure, the parsing data are packaged in XML. By this way, a practical evidence analysis Platform is designed, which can work out and restore the information of deleted files into the form of a friendly user interface. This application will be an important information-gaining tool to conduct forensic analysis of a suspect’s computer system.","PeriodicalId":331155,"journal":{"name":"2009 WRI World Congress on Software Engineering","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-05-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 WRI World Congress on Software Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WCSE.2009.111","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
Windows Recycle Bin is an important component of the operating system and the algorithm is very important and worth exploring. Recycle Bin preserves deleted files and directories signs. So, it’s an important part to exam the control files of the Recycle Bin in computer forensic. In this paper, by parsing the structure of INFO2, we completely analyze the recovery model and algorithms of the Recycle Bin. And based on the use of XML structure, the parsing data are packaged in XML. By this way, a practical evidence analysis Platform is designed, which can work out and restore the information of deleted files into the form of a friendly user interface. This application will be an important information-gaining tool to conduct forensic analysis of a suspect’s computer system.