DocumentCode
3025793
Title
A framework for computer forensics investigations involving Microsoft Vista
Author
Hayes, Darren R. ; Qureshi, Shareq
Author_Institution
Univ. of Pace, New York, NY
fYear
2008
fDate
2-2 May 2008
Firstpage
1
Lastpage
8
Abstract
The technical environment continues to change and impact the work of digital investigations. This research provides a framework within which computer forensics investigators can take advantage of new or different types of evidence from Microsoftpsilas Vista operating system (ldquoVistardquo). Moreover, this paper will also indicate the many challenges that investigators will encounter when faced with the Vista platform. The focus herein will be on changes associated with new security, encryption and file restoration features. These features vary according to the version of Vista and these differences will also be discussed. This research will also detail the integrity of data recovery procedures through detailed experiments used to identify how data could be manipulated by a perpetrator in Vista as compared to previous versions of Microsoftpsilas operating systems. Ultimately, this paper will indicate that enhancements in security and encryption associated with Encrypted File System (EFS) as well as BitLocker Drive Encryption are very problematic for investigators. Vista has serious implications for computer forensics investigations. Nevertheless, this research will guide the digital investigator through the labyrinth of new challenges, to effect a more thorough investigation of digital evidence.
Keywords
cryptography; operating systems (computers); BitLocker Drive Encryption; Encrypted File System; computer forensics investigations; computer security; data recovery procedures; encryption; Computer security; Cryptography; Data security; File systems; Forensics; Internet; Operating systems; Postal services; Protection; Universal Serial Bus; BitLocker; Computer Forensics; Computer Security; Encryption; Operating Systems; Vista;
fLanguage
English
Publisher
ieee
Conference_Titel
Systems, Applications and Technology Conference, 2008 IEEE Long Island
Conference_Location
Farmingdale, NY
Print_ISBN
978-1-4244-1731-5
Electronic_ISBN
978-1-4244-1732-2
Type
conf
DOI
10.1109/LISAT.2008.4638951
Filename
4638951
Link To Document