USN Journal-based Research of Check Marks and Forensics on NTFS File System

HUANG Jia-shun,ZHAO Xin-yu,LUO Shun,QIU Wei-dong
DOI: https://doi.org/10.3969/j.issn.1009-8054.2013.02.032
2013-01-01
Abstract:The computer system check marks and forensics is the process,by certain techniques and methods,to collect all kinds of information in the target computer as clues and evidence. The analysis and interpretation of USN journal on NTFS file system could be used in computer crime investigation and forensic,and the research on computer crime investigation technologies is helpful to acquisition of crime clues and evidence in USN journal. Meanwhile some examples and explanations are also given in this paper.
What problem does this paper attempt to address?