Gyu-Sang Cho

Learn More
Patterns of file time change $LogFile NTFS a b s t r a c t In this paper, we present a computer forensic method for detecting timestamp forgeries in the Windows NTFS file system. It is difficult to know precisely that the timestamps have been changed by only examining the timestamps of the file itself. If we can find the past timestamps before any changes(More)
  • 1