참고문헌
- S. Willassen, "Hypothesis-Based Investigation of Digital Timestamps," in Advances in Digital Forensics IV, Boston, MA: Springer US, 2008, pp. 75-86. DOI: https://doi.org/10.1007/978-0-387-84927-0_7
- S. Y. Willassen, "Timestamp evidence correlation by model based clock hypothesis testing," in Proceedings of the 1st International ICST Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia, 2008. DOI: https://doi.org/10.4108/e-forensics.2008.2637
- B. D. Carrier "A hypothesis-based approach to digital forensic investigations," 2006.
- P. Gladyshev and A. Patel, "Finite state machine approach to digital event reconstruction," Digit. Investig., vol. 1, no. 2, pp. 130-149, Jun. 2004. DOI: https://doi.org/10.7236/JIIBC.2016.16.3.21
- R. Koen and M. S. Olivier, "The Use of File Timestamps in Digital Forensics.," 2008.
- B. Yoo, "Analysis of File Time Change by File Manipulation of Linux System," J. Inst. Internet Broadcast. Commun., vol. 16, no. 3, pp. 21-28, Jun. 2016. DOI: https://doi.org/10.7236/JIIBC.2016.16.3.21
- J. I. James and P. Gladyshev, "Modeling Timestamp Update Patterns for Automated Event Reconstruction," in Proceedings of the 11th International Conference on the Systematic Approaches to Digital Forensics Engineering, 2016, pp. 79-94.
- J. I. James and P. Gladyshev, "Automated inference of past action instances in digital investigations," Int. J. Inf. Secur., vol. 14, no. 3, pp. 249-261, 2015. DOI: https://doi.org/10.1007/s10207-014-0249-6
- H. Min and J. Heo, "An Estimation Model of Missing Data for Smart Phone Sensing," J. Inst. Webcasting, Internet Telecommun., vol. 13, no. 3, pp. 33-38, Jun. 2013. DOI: https://doi.org/10.7236/JIIBC.2013.13.3.33
- M. W. Stevens, "Unification of relative time frames for digital forensics," Digit. Investig., vol. 1, no. 3, pp. 225-239, Sep. 2004. DOI: https://doi.org/10.1016/j.diin.2004.07.003
- M. Kang, S. Park, S. Kim, and K. Kim, "Detection of Complex Event Patterns over Interval-based Events," J. Inst. Internet, Broadcast. Commun., vol. 12, no. 4, pp. 201-209, 2012. DOI: https://doi.org/10.7236/JIWIT.2012.12.4.201
- D. Farmer and W. Venema, Forensic discovery, vol. 6. Addison-Wesley Upper Saddle River, 2005.
- J. I. James, P. Gladyshev, and Y. Zhu, "Signature Based Detection of User Events for Post-mortem Forensic Analysis," in Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST, vol. 53, 2011, pp. 96-109. DOI: https://doi.org/10.1007/978-3-642-19513-6_8