论文标题

用于诊断的Windows遥测的法医分析

Forensic analysis of the Windows telemetry for diagnostics

论文作者

Han, Jaehyeok, Park, Jungheum, Chung, Hyunji, Lee, Sangjin

论文摘要

遥测是从远程设备的自动传感和收集数据。它通常用于为用户提供更好的服务。 Microsoft使用遥测来定期收集有关Windows系统的信息,并帮助改善用户体验并解决潜在问题。 Windows遥测服务功能通过在本地系统上创建RBS文件来可靠地传输和管理遥测数据,这些文件可以在数字法医调查中提供有用的信息。结合从传统的Windows取证中得出的信息,研究人员可以对来自各种文物的证据具有更大的信心。可以获取仅用于实时系统的信息,例如计算机硬件序列号,外部存储设备的连接记录以及执行过程的痕迹。此信息包含在为Windows遥测中使用的RBS文件中。在本文中,我们介绍了如何获取RBS文件遥测并分析了这些RBS文件的数据结构,这些文件结构能够确定Windows OS已收集的信息类型。我们还通过将常规工件与RBS文件进行比较,讨论了可靠性和新颖性,这在数字法医调查中可能很有用。

Telemetry is the automated sensing and collection of data from a remote device. It is often used to provide better services for users. Microsoft uses telemetry to periodically collect information about Windows systems and to help improve user experience and fix potential issues. Windows telemetry service functions by creating RBS files on the local system to reliably transfer and manage the telemetry data, and these files can provide useful information in a digital forensic investigation. Combined with the information derived from traditional Windows forensics, investigators can have greater confidence in the evidence derived from various artifacts. It is possible to acquire information that can be confirmed only for live systems, such as the computer hardware serial number, the connection records for external storage devices, and traces of executed processes. This information is included in the RBS files that are created for use in Windows telemetry. In this paper, we introduced how to acquire RBS files telemetry and analyzed the data structure of these RBS files, which are able to determine the types of information that Windows OS have been collected. We also discussed the reliability and the novelty by comparing the conventional artifacts with the RBS files, which could be useful in digital forensic investigation.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源