• DocumentCode
    3025793
  • Title

    A framework for computer forensics investigations involving Microsoft Vista

  • Author

    Hayes, Darren R. ; Qureshi, Shareq

  • Author_Institution
    Univ. of Pace, New York, NY
  • fYear
    2008
  • fDate
    2-2 May 2008
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The technical environment continues to change and impact the work of digital investigations. This research provides a framework within which computer forensics investigators can take advantage of new or different types of evidence from Microsoftpsilas Vista operating system (ldquoVistardquo). Moreover, this paper will also indicate the many challenges that investigators will encounter when faced with the Vista platform. The focus herein will be on changes associated with new security, encryption and file restoration features. These features vary according to the version of Vista and these differences will also be discussed. This research will also detail the integrity of data recovery procedures through detailed experiments used to identify how data could be manipulated by a perpetrator in Vista as compared to previous versions of Microsoftpsilas operating systems. Ultimately, this paper will indicate that enhancements in security and encryption associated with Encrypted File System (EFS) as well as BitLocker Drive Encryption are very problematic for investigators. Vista has serious implications for computer forensics investigations. Nevertheless, this research will guide the digital investigator through the labyrinth of new challenges, to effect a more thorough investigation of digital evidence.
  • Keywords
    cryptography; operating systems (computers); BitLocker Drive Encryption; Encrypted File System; computer forensics investigations; computer security; data recovery procedures; encryption; Computer security; Cryptography; Data security; File systems; Forensics; Internet; Operating systems; Postal services; Protection; Universal Serial Bus; BitLocker; Computer Forensics; Computer Security; Encryption; Operating Systems; Vista;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems, Applications and Technology Conference, 2008 IEEE Long Island
  • Conference_Location
    Farmingdale, NY
  • Print_ISBN
    978-1-4244-1731-5
  • Electronic_ISBN
    978-1-4244-1732-2
  • Type

    conf

  • DOI
    10.1109/LISAT.2008.4638951
  • Filename
    4638951