Advertisement

Examining NTFS File System

  • Xiaodong Lin
Chapter

Abstract

The objectives of this chapter are to:

References

  1. 1.
    “New Technology File System (NTFS)”. http://www.pcguide.com/ref/hdd/file/ntfs/index.htm
  2. 2.
    Brian Carrier. “File System Forensic Analysis”. Addison-Wesley Professional, 2005Google Scholar
  3. 3.
    The Structure and Function of an Operating System. http://www.sqa.org.uk/e-learning/COS101CD/page_18.htm
  4. 4.
  5. 5.
  6. 6.
    Petra Koruga, Miroslav Bača. Analysis of B-tree data structure and its usage in computer forensics. https://bib.irb.hr/datoteka/484192.B-tree.pdf
  7. 7.
    Gyu-Sang Cho. NTFS Directory Index Analysis for Computer Forensics.Google Scholar
  8. 8.
    NTFS: Sometimes accurate file times are not in $FILE_NAME but in $STANDARD_INFORMATION. http://jnode.org/node/2861
  9. 9.
  10. 10.
  11. 11.

Copyright information

© Springer Nature Switzerland AG 2018

Authors and Affiliations

  • Xiaodong Lin
    • 1
  1. 1.Department of Physics and Computer Science, Faculty of ScienceWilfrid Laurier UniversityWaterlooCanada

Personalised recommendations