NUST Institutional Repository

Provision of validated toolset of freeware computer forensics tools (CFTS)

Show simple item record

dc.contributor.author Zareen, Muhammad Sharjeel
dc.contributor.author Supervised By : Dr. Baber Aslam.
dc.date.accessioned 2020-10-26T06:45:25Z
dc.date.available 2020-10-26T06:45:25Z
dc.date.issued 2014-08
dc.identifier.other TIS-173
dc.identifier.other MSIS-11
dc.identifier.uri http://10.250.8.41:8080/xmlui/handle/123456789/4879
dc.description.abstract The issue of validation of computer forensics tools (CFTs) plays a critical role in computer forensics. The National Institute of Standards and Technology (NIST) of USA is among the leading organizations dealing with defining the standards for various functionalities of computer forensics and accordingly validating computer forensics tools (CFTs). Standardization procedure at NIST comprises defining tool specifications, test assertions, test methodology and test cases. NIST has not defined standards for all the functionalities of CFTs. Hence, functionalities of various CFTs cannot be validated. This research thesis defines the standards for one of the important undefined functionality i.e. Secure Wipe functionality for NTFS specific to Windows 7. These standards are defined basing on results of thorough research on file creation and file deletion processes and their artifacts in MFT records, hard disk and $LogFile. In addition, comprehensive research on $LogFile of NTFS has been done in this thesis. Research on MFT records and linking their changes to $LogFile and defining flow of activities of file creation and deletion processes are other important researched areas of this thesis. Two tools having the capability of secure wipe, have also been validated basing on the standards defined in this research thesis. en_US
dc.language.iso en en_US
dc.publisher MCS en_US
dc.title Provision of validated toolset of freeware computer forensics tools (CFTS) en_US
dc.type Thesis en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account