E.I. Dukhan – Ph.D.(Eng.), Associate Professor,
Ural Federal University named after the first President of Russia B.N.Yeltsin (Ekaterinburg)
N.S. Knyazeva – Post-graduate Student,
Ural Federal University named after the first President of Russia B.N.Yeltsin (Ekaterinburg)
Restoring a sequence of user actions or system events by examining file system metadata is a poorly studied task that many experts are solving. The main file system metadata includes timestamps. File timestamps can be stored in various areas of the file system. Each and every file has timestamps within the file record of the MFT (Master File Table). Some files contain timestamps within their structure. Such timestamps are updated by a certain application software assigned to this very file format. Huge amounts of timestamps are stored in special system files required for the operation of the operating system. Timestamps of the MFT are of our main interest, as this element is the basic structure of the NTFS data file system, crucial for the operation of the file system. Review of the published papers indicate high interest in the analysis of timestamps; however, most authors consider only 3 or 4 timestamps contained in attributes of the MFT. Their observations are limited to a small number of file operations, while the objects under study are represented by the similar files, which prevents the authors from making accurate conclusions when examining the mechanisms of timestamp modification. Thus, it is necessary to develop a methodology for studying the nature of changes in timestamps when performing file operations, since incorrectly performed experiments can lead to incorrect conclusions. In this paper develop a methodology for studying changes in the timestamps of file objects. A methodology has been developed for studying changes in the timestamps of file objects, which describes the steps for preparing file objects, conducting experiments, and recording results. FTA (File Time Analyzer) command let was developed to monitor the creation and update of the file timestamps in NTFS. This software detects and displays twelve timestamps from the MFT for each file object. The observation results obtained allow concluding that there are regularities in the file timestamp changes during operations with them. Many file operations have a unique influence on the nature of timestamp changes. The observation data obtained are generalized in table of change in timestamps for the NTFS and Windows XP, 7, 8 10.
