Back and Forth—On Automatic Exposure of Origin and Dissemination of Files on Windows


연구 분야: Safety



학회: Digital Threats: Research and Practice, Volume 4, Issue 3


초록

The number of Child Sexual Abuse Material (CSAM) cases has increased dramatically in recent years. This leads to the need to automate various steps in digital forensic processing, especially for CSAM investigations. For instance, if CSAM pictures are found on a device, the investigator aim at finding traces about the origin and possible further dissemination, respectively. In this article, we address this challenge with respect to the widespread Windows operating system. We model different common scenarios of system use by CSAM offenders in the scope of file inbound and outbound transfer channels. This gives us insights about digital traces in the Windows operating system and its applications to get knowledge about origin and possible destination of a file. We review available concepts and applications to support this issue. Furthermore, we develop a recursive-based approach and provide a prototype as plugin for the open source application Autopsy. We call our prototype AutoTrack. Our evaluation against the different models of Windows system usage reveals that Autotrack is superior to existing solutions and provides support for an investigator to find digital traces about the origin and possible further dissemination of files. We publish our AutoTrack plugin and thus provide full reproducibility of our approach.


Author Profile
Samantha Klier

University of the Bundeswehr Munich RI CODE Germany

Germany
Author Profile
Jan Varenkamp

Technical University of Darmstadt Germany

Germany
Author Profile
Harald Baier

University of the Bundeswehr Munich RI CODE Germany

Germany

📄 논문 정보

발행 연도 2023년
인용수 2
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (110건)