{"title":"Event Observation of Date-time Stamps for ADS Reconstruction","authors":"Da-Yu Kao, Yuan Chen, En-Cih Chang","doi":"10.23919/ICACT.2019.8701988","DOIUrl":null,"url":null,"abstract":"Alternate Data Streams (ADS) is a method of information hiding that is only possible on NTFS file systems. Criminals are using it to hide data because the ADS can hide any size and type of data in NTFS file system. ADS is invisible to users. However, ADS operation updates the temporal attribute of cover medium, which could be a trace for ADS evaluating. Cover medium indicates to the file/folder which is used for ADS operation (creating, modifying and overwriting). In general file/folder operation, if we create (archive/copy) a file into folder, it updates certain timestamps attributes of folder and file itself. Same result takes place when modifying/overwriting the file within folder. Based on this concept, we took a file within folder as a cover medium and applied some operations (create, modify and overwrite) on it to observe the timestamps variation on both folder and cover medium.","PeriodicalId":226261,"journal":{"name":"2019 21st International Conference on Advanced Communication Technology (ICACT)","volume":"130 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 21st International Conference on Advanced Communication Technology (ICACT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/ICACT.2019.8701988","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Alternate Data Streams (ADS) is a method of information hiding that is only possible on NTFS file systems. Criminals are using it to hide data because the ADS can hide any size and type of data in NTFS file system. ADS is invisible to users. However, ADS operation updates the temporal attribute of cover medium, which could be a trace for ADS evaluating. Cover medium indicates to the file/folder which is used for ADS operation (creating, modifying and overwriting). In general file/folder operation, if we create (archive/copy) a file into folder, it updates certain timestamps attributes of folder and file itself. Same result takes place when modifying/overwriting the file within folder. Based on this concept, we took a file within folder as a cover medium and applied some operations (create, modify and overwrite) on it to observe the timestamps variation on both folder and cover medium.