Computer Forensics Research and Implementation Based on NTFS File System

WANG Lina,YANG Mo,WANG Hui,GUO Panfeng
DOI: https://doi.org/10.3321/j.issn:1671-8836.2006.05.002
2006-01-01
Abstract:In order to solve data recovery problems in computer forensics,this paper proposes a new algorithm based on NTFS.By analyzing the structure of NFTS,this algorithm classifies data into three varieties and handles them differently.Organized-impossible data is recovered and taken forensics by the distributing of the words.Organized-possible data is recovered and taken forensics by the references records of NTFS.Result shows that this algorithm could rebuild deleted data and make foundation for forensics.
What problem does this paper attempt to address?