IRMA-International.org: Creator of Knowledge
Information Resources Management Association
Advancing the Concepts & Practices of Information Resources Management in Modern Organizations

A Model Based Approach to Timestamp Evidence Interpretation

A Model Based Approach to Timestamp Evidence Interpretation
View Sample PDF
Author(s): Svein Yngvar Willassen (Norwegian University of Science and Technology, Norway)
Copyright: 2009
Volume: 1
Issue: 2
Pages: 12
Source title: International Journal of Digital Crime and Forensics (IJDCF)
Editor(s)-in-Chief: Feng Liu (Chinese Academy of Sciences, China)
DOI: 10.4018/jdcf.2009040101

Purchase

View A Model Based Approach to Timestamp Evidence Interpretation on the publisher's website for pricing and purchasing information.

Abstract

Timestamps play an important role in digital investigations, since they are necessary for the correlation of evidence from different sources. Use of timestamps as evidence can be questionable due to the reference to a clock with unknown adjustment. This work addresses this problem by taking a hypothesis based approach to timestamp investigation. Historical clock settings can be formulated as a clock hypothesis. This hypothesis can be tested for consistency with timestamp evidence by constructing a model of actions affecting timestamps in the investigated system. Acceptance of a clock hypothesis with timestamp evidence can justify the hypothesis, and thereby establish when events occurred in civil time. The results can be used to correlate timestamp evidence from different sources, including identifying correct originators during network trace.

Related Content

Shakir A. Mehdiyev, Tahmasib Kh. Fataliyev. © 2024. 17 pages.
Fuhai Jia, Yanru Jia, Jing Li, Zhenghui Liu. © 2024. 13 pages.
Dawei Zhang. © 2024. 16 pages.
Yuwen Zhu, Lei Yu. © 2023. 16 pages.
Vijay Kumar, Sahil Sharma, Chandan Kumar, Aditya Kumar Sahu. © 2023. 14 pages.
Wenjun Yao, Ying Jiang, Yang Yang. © 2023. 20 pages.
Dawei Zhang. © 2023. 14 pages.
Body Bottom