Understanding strategies and challenges of timestamp tampering for improved digital forensic event reconstruction

  • Timestamps play a pivotal role in digital forensic event reconstruction, but due to their non-essential nature, tampering or manipulation of timestamps is possible by users in multiple ways, even on running systems. This has a significant effect on the reliability of the results from applying a timeline analysis as part of an investigation. We investigate the problem of users tampering with timestamps on a running (“live”) system. While prior work has shown that digital evidence tampering is hard, we focus on the question of why this is so. By performing a qualitative user study with advanced university students, we derive factors that influence the reliability of successful tampering, such as the individual knowledge about temporal traces, and technical restrictions to change them. These insights help to assess the reliability of timestamps from individual artifacts that are used for event reconstruction and subsequently reduce the risk of misinterpretations.

Download full text files

Export metadata

Statistics

Number of document requests

Additional Services

Share in Twitter Search Google Scholar
Metadaten
Author:Céline Vanini, Jan Gruber, Christopher Hargreaves, Zinaida Benenson, Felix Freiling, Frank BreitingerORCiDGND
URN:urn:nbn:de:bvb:384-opus4-1213455
Frontdoor URLhttps://opus.bibliothek.uni-augsburg.de/opus4/121345
ISBN:979-8-4007-1076-6OPAC
Parent Title (English):DFDS '25: Proceedings of the Digital Forensics Doctoral Symposium, Brno, Czech Republic, 1 April 2025
Publisher:Association for Computing Machinery (ACM)
Place of publication:New York, NY
Type:Conference Proceeding
Language:English
Year of first Publication:2025
Publishing Institution:Universität Augsburg
Release Date:2025/04/09
First Page:10
DOI:https://doi.org/10.1145/3712716.3712727
Institutes:Fakultät für Angewandte Informatik
Fakultät für Angewandte Informatik / Institut für Informatik
Fakultät für Angewandte Informatik / Institut für Informatik / Lehrstuhl für Cybersicherheit
Dewey Decimal Classification:0 Informatik, Informationswissenschaft, allgemeine Werke / 00 Informatik, Wissen, Systeme / 004 Datenverarbeitung; Informatik
Licence (German):CC-BY 4.0: Creative Commons: Namensnennung