Event Observation of Date-time Stamps for ADS Reconstruction

Da-Yu Kao, Yuan Chen, En-Cih Chang
{"title":"Event Observation of Date-time Stamps for ADS Reconstruction","authors":"Da-Yu Kao, Yuan Chen, En-Cih Chang","doi":"10.23919/ICACT.2019.8701988","DOIUrl":null,"url":null,"abstract":"Alternate Data Streams (ADS) is a method of information hiding that is only possible on NTFS file systems. Criminals are using it to hide data because the ADS can hide any size and type of data in NTFS file system. ADS is invisible to users. However, ADS operation updates the temporal attribute of cover medium, which could be a trace for ADS evaluating. Cover medium indicates to the file/folder which is used for ADS operation (creating, modifying and overwriting). In general file/folder operation, if we create (archive/copy) a file into folder, it updates certain timestamps attributes of folder and file itself. Same result takes place when modifying/overwriting the file within folder. Based on this concept, we took a file within folder as a cover medium and applied some operations (create, modify and overwrite) on it to observe the timestamps variation on both folder and cover medium.","PeriodicalId":226261,"journal":{"name":"2019 21st International Conference on Advanced Communication Technology (ICACT)","volume":"130 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 21st International Conference on Advanced Communication Technology (ICACT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/ICACT.2019.8701988","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Alternate Data Streams (ADS) is a method of information hiding that is only possible on NTFS file systems. Criminals are using it to hide data because the ADS can hide any size and type of data in NTFS file system. ADS is invisible to users. However, ADS operation updates the temporal attribute of cover medium, which could be a trace for ADS evaluating. Cover medium indicates to the file/folder which is used for ADS operation (creating, modifying and overwriting). In general file/folder operation, if we create (archive/copy) a file into folder, it updates certain timestamps attributes of folder and file itself. Same result takes place when modifying/overwriting the file within folder. Based on this concept, we took a file within folder as a cover medium and applied some operations (create, modify and overwrite) on it to observe the timestamps variation on both folder and cover medium.
ADS重建中日期-时间戳的事件观测
备用数据流(ADS)是一种仅在NTFS文件系统上可行的信息隐藏方法。犯罪分子利用它来隐藏数据,因为ADS可以在NTFS文件系统中隐藏任何大小和类型的数据。ADS对用户是不可见的。然而,ADS操作更新了覆盖介质的时间属性,这可能是ADS评估的一个痕迹。覆盖介质指用于ADS操作(创建、修改和覆盖)的文件/文件夹。在一般的文件/文件夹操作中,如果我们创建(存档/复制)一个文件到文件夹中,它会更新文件夹和文件本身的某些时间戳属性。当修改/覆盖文件夹中的文件时也会发生相同的结果。基于这个概念,我们将文件夹中的一个文件作为覆盖介质,对其进行一些操作(创建、修改和覆盖),观察文件夹和覆盖介质上时间戳的变化。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信