Automatic collection and analysis of digital evidence from windows-based systems within the scope of digital forensics
2025
0 görüntülenme
0 i̇ndirme
Danışman: Prof. Dr. İbrahim Özçelik
Özet (EN)
With advancing technology, information technologies and digital devices play a significant role in our daily lives. Cybercriminals and attackers also exploit information technologies and digital devices for malicious activities. Due to the increasing use of computers for criminal purposes, digital forensics has become a crucial part of criminal investigations. The work involved in digital forensics can be summarized as the initial response at the crime scene, the collection of electronic evidence, the examination and analysis of evidence collected at the crime scene or in the laboratory, and reporting to the relevant authorities. In order to combat cybercrimes and crimes committed using information technologies more effectively, digital evidence (data and information transmitted or stored via electronic or magnetic media) is needed in addition to physical evidence in the process of identifying the facts of the crime and bringing criminals to justice. Data acquired from information technologies has become crucial in investigations and trial processes. Therefore, in order for legal processes to proceed without interruption, collected digital data must be analyzed accurately within the required timeframe and presented to the relevant authorities. Digital evidence refers to data recorded on electronic or magnetic devices that contributes to the investigation of a crime. To examine seized digital material, it is generally necessary to create a forensic copy (an image) of the digital material and analyze this copy. This is done to prevent damage to the original digital material and to maintain the integrity of the evidence. In the process of collecting digital evidence, examining the operating system in particular can provide access to evidentiary data. The operating system provides access to various structured data, including all searches, file operations, system logs, running applications, internet access history, email files, and more. Therefore, operating system-based digital forensics offers significant opportunities for the collection of digital evidence. In Windows-based systems, digital evidence is generally divided into four main categories: Registry, File System, User and System, and Memory. Registry evidence resides in a hierarchical database containing valuable information such as user activity, system configurations, and software traces. These records are loaded into memory during system startup, and changes are written to disk both at regular intervals during operation and when the system shuts down properly. These records allow digital forensics experts to retrospectively examine past user activity, program execution history, and changes made to the system. File system evidence encompasses digital traces originating from the NTFS (New Technology File System) architecture used in the Windows operating system. NTFS records timestamps such as creation, modification, and access times for files and folders, as well as file permissions and alternate data streams. Furthermore, thanks to the Master File Table (MFT), even metadata from deleted files can remain in the system for some time. This structure is a significant source of evidence for identifying and creating a timeline of user actions on files. User and system evidence is collected from audit logs generated by the operating system and applications. This evidence includes information such as when users logged into the system, which programs they ran, how often they used those programs, and which resources they accessed. Application, security, and system logs, especially Windows Event Logs, play a critical role in detecting unauthorized access, errors, and suspicious activity. These records allow for a chronological analysis of events. Memory evidence consists of temporary data structures located in RAM while the system is running. Extremely sensitive information such as running processes, network connections, open files, passwords, and encryption keys can reside in memory. Acquisition of this type of evidence requires taking a memory image from the live system; otherwise, this data is lost when the system is shut down. However, files like pagefile.sys and hiberfil.sys, which consist of memory data written to disk, contain important memory remnants that can be examined even in static forensics. Memory records allow for the analysis of software and user activity. Digital forensics tools can collect various types of digital evidence from live or offline systems. Tools operating on offline systems typically collect digital evidence via disk images or RAM images. The collection, organization, correlation, interpretation, and analysis of digital evidence are performed by digital forensics experts and can be timeconsuming and costly. Some digital forensics tools focus on disks, while others focus on RAM. Open-source or free tools, in particular, often prioritize the collection of digital evidence while neglecting automated analysis. In addition to collecting digital evidence from both disk and RAM images, it is crucial to convert the collected digital evidence into an understandable format for digital forensics experts and to perform automated inferences based on that evidence. In this study, in addition to collecting digital evidence from disk and RAM images of Windows-based systems and recovering deleted files, the following objectives have been achieved. A timeline is created for digital evidence collected from disk and RAM images. By correlating digital evidence collected from disk images with digital evidence collected from RAM images taken before the system was last shut down, detailed information such as the process ID, process name, start time, initiator username, parent process ID, parent process name, network connections, and file paths of malicious processes identified in the RAM image is obtained. Digital evidence collected from disk and RAM images is analyzed in two stages. In the first stage, rule-based analysis identifies matters such as running malicious powershell commands, pass the hash attacks, installing malicious services, running psexec, deleting Windows event logs, connecting to the local area network via RDP from an external network, disabling Windows event log monitoring, suspicious scheduled tasks, suspicious failed logins, suspicious file writing, persistence indicators, system date and time setting information, changing the system date and time, malicious process information, suspicious process, suspicious network connection, suspicious DLL. In the second stage, AI-assisted analysis identifies unusual activities from data such as the frequency, length, and structure of registry key changes, the timing of successful and unsuccessful login and logout operations, usernames, and the timing, frequency, and usernames of file deletions. The analysis results are correlated with attacker behaviors within the MITRE ATT&CK framework. A software called "CAMGÖZ" has been developed to perform all these operations. In conclusion, in this study, digital evidence/artifacts in Windows-based systems, which are widely used in today's computing environments, and the forensic process have been examined from a technical perspective. A literature research on the subject was conducted, and forensic tools were analyzed. Collection of digital evidence from disk and RAM images with Windows-based systems, extraction of a timeline, recovery of deleted files, correlation collected digital evidence, detection of malicious/suspicious activities with rule-based analysis and anomalies with artificial intelligence-assisted analysis have been automatically performed. In this context, a software called "CAMGÖZ" was developed. Thus, the digital forensic analysis has been made more effective, efficient, fast, and easy to perform. It is evaluated that the software in question will be useful in the field of forensic computer and cyber security.
Yazar
Dr. Şahin Özdemir
Bu Yayına Nasıl Atıf Yapılır
Şahin Özdemir (Master Thesis). Automatic collection and analysis of digital evidence from windows-based systems within the scope of digital forensics, 2025, Sakarya University.
Anahtar Kelimeler
Lisans
Tüm Hakları Saklıdır
Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.
Sakarya University tezlerinden daha fazlası
- Computational investigation of battery materials using density functional theory(2023)
- Haci Ahmed b. Seyyid al-Bigavî and Tarjama al-Awārif al-maārif (sections of 22-43)(2024)
- Synthesis of carbazol substituted 3,4-dihydropyrimidine-2(1h)-thione deri̇vati̇ves(2024)
- Classification of recyclable wastes with deep learning models: A comparison on the effect of dataset size(2024)
- Hermeneutical analysis of sacrifice, sacred violence and scapegoat motifs in Turkish Mythology(2024)
- Novel thio-chalcone substituted metallophthalocyanines: synthesis, characterization and redox behaviour(2018)