作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (23): 281-283. doi: 10.3969/j.issn.1000-3428.2007.23.098

• 开发研究与设计技术 • 上一篇    下一篇

NTFS系统存储介质上文件操作痕迹分析

黄步根   

  1. (江苏警官学院公安科技系,南京 210012)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-12-05 发布日期:2007-12-05

Analysis of Traces on Storage Media by File Operation for NTFS File System

HUANG Bu-gen   

  1. (Department of Forensic Science, Jiangsu Police Institute, Nanjing 210012)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-12-05 Published:2007-12-05

摘要: 计算机用户通过文件系统存取数据,文件和文件夹的操作(如增加、删除、修改)会在存储介质上留下痕迹,这些痕迹与文件系统有关。NTFS文件系统以簇为单位分配和回收外存空间,通过主文件表来进行管理。文章从计算机取证角度探讨NTFS文件系统下访问文件(夹)的方法,研究NTFS文件系统下文件和文件夹的操作痕迹,并与FAT文件系统中的痕迹进行比较。

关键词: 数据恢复, 计算机取证, 痕迹, NTFS, FAT

Abstract: Computer users access data by file system. File and folder operation(such as creation, deletion, and edition) may leave some traces on storage media. These traces are related to file system. NTFS file system allocates and revokes the storage by cluster. It manages by MFT. This paper, from the point of computer forensics, analyzes the method of accessing file for NTFS file system and the traces of the file or folder operating, and compares it with traces of FAT.

Key words: data recovery, computer forensic, trace, NTFS, FAT

中图分类号: