Forensic Analysis of Windows Thumbcache Files

Quick D, Tassone C and Choo K-K R 2014. Forensic Analysis of Windows Thumbcache files. In 20th Americas Conference on Information Systems (AMCIS 2014), 7-10 August 2014, Association for Information Systems (Forthcoming)

13 Pages Posted: 2 May 2014

See all articles by Darren Quick

Darren Quick

Government of South Australia

Christopher Tassone

University of South Australia

Kim-Kwang Raymond Choo

The University of Texas at San Antonio

Date Written: April 26, 2014

Abstract

A range of court cases and forensic investigations have involved thumbnail pictures contained within operating system files, such as thumbcache and thumbs.db. In many of these cases, the thumbnail image has been the evidence presented to a court. Further analysis may locate additional information relating to thumbnail pictures, such as being able to link a thumbnail to a picture file on storage media, or locating information relating to the original file used to create the thumbnail, such as the full path and original file name. Using real-world law enforcement and test data, we demonstrate the application of our proposed operational methodology to conduct analysis of thumbcache files. We also propose a reporting and visualisation methodology to present the evidence to investigators, legal counsel, and court, which then forms the basis of our software prototype. Insider threat cases which involve pictures of intellectual property can potentially benefit from our proposed method.

Keywords: Digital Forensic Analysis, Thumbcache, Microsoft Windows, Computer Forensics

JEL Classification: C88, C89, K42, K49

Suggested Citation

Quick, Darren and Tassone, Christopher and Choo, Kim-Kwang Raymond, Forensic Analysis of Windows Thumbcache Files (April 26, 2014). Quick D, Tassone C and Choo K-K R 2014. Forensic Analysis of Windows Thumbcache files. In 20th Americas Conference on Information Systems (AMCIS 2014), 7-10 August 2014, Association for Information Systems (Forthcoming). Available at SSRN: https://ssrn.com/abstract=2429795

Darren Quick

Government of South Australia ( email )

Adelaide SA 5000
Australia

Christopher Tassone

University of South Australia ( email )

37-44 North Terrace, City West Campus
Adelaide, South Australia 5001
Australia

Kim-Kwang Raymond Choo (Contact Author)

The University of Texas at San Antonio ( email )

San Antonio, TX 78249
United States
+12104587867 (Phone)

HOME PAGE: http://https://sites.google.com/site/raymondchooau/

Register to save articles to
your library

Register

Paper statistics

Downloads
691
Abstract Views
2,470
rank
35,844
PlumX Metrics