首页    期刊浏览 2024年11月27日 星期三
登录注册

文章基本信息

  • 标题:Investigation of Artefacts Left by BitTorrent Client in Windows 8 Registry
  • 本地全文:下载
  • 作者:Algimantas Venčkauskas ; Robertas Damaševičius ; Nerijus Jusas
  • 期刊名称:Information Security and Computer Fraud
  • 印刷版ISSN:2376-9602
  • 电子版ISSN:2376-9629
  • 出版年度:2015
  • 卷号:3
  • 期号:2
  • 页码:25-31
  • DOI:10.12691/iscf-3-2-1
  • 出版社:Science and Education Publishing
  • 摘要:BitTorrent client application is a popular tool to download large files from Internet, but this application is quite frequently used for illegal purposes that are one of the types of cybercrimes. If order to fight against this type of cybercrime we carried out the research, during which we investigated the evidences left by BitTorrent client application in registry under Windows 8 operating system. The experiment was carried out in three steps: installation, download, and uninstallation. The snapshots of registry were taken and compared prior and after each step. Changes in Windows registry were collected and joined into tables. The experiment revealed that BitTorrent client application creates Windows registry artefacts that can contain information which might be used as evidence during an investigation. The evidence remains in the registry even after the removal of the application, although it can really prove the fact of usage of the application only. The investigation of file system can reveal the purpose and the contents of the BitTorrent client session.
  • 关键词:BitTorrent protocol; forensics investigation; forensic evidence; registry
国家哲学社会科学文献中心版权所有