Timeline Analysis Bibliography
From Forensics Wiki
Papers
- Generating computer forensic supertimelines under Linux - A comprehensive guide for Windows-based disk images, by R. Carbone, C. Bean, August 2012
- J. Olsson, M. Boldt, "Computer forensic timeline visualization tool", ScienceDirect Digital Investigation, Volume 6, September 2009
- Jewan Bang, BY Yoo, JS Kim, SJ Lee, "Analysis of Time Information for Digital Investigation", NCM 2009, 5th International Joint Conference on INC, IMS, IDC, August 2009
- S. Willassen, "A Model Based Approach to Timestamp Evidence Interpretation", International Journal of Digital Crime and Forensics, 1:2, 2009
- Olsson, Jens Digital Evidence with an Emphasis on Time, Master's Thesis, Blekinge Institute of Technology, September 2008.
- R. Koen, M. Olivier, "The Use of File Timestamps in Digital Forensics", ISSA 2008, Johannesburg, South Africa, July 2008
- S. Willassen, "Methods for Enhancement of Timestamp Evidence in Digital Investigations", PhD Dissertation, Norwegian University of Science and Technology, 2008
- S. Willassen, "Finding Evidence of Antedating in Digital Investigations", ARES 2008, Barcelona, Spain, March 2008
- S. Willassen, "Hypothesis Based Investigation of Digital Timestamp", 4th IFIP WG 11.9 Workskop on Digital Evidence, Kyoto, Japan, January 2008
- S. Willassen, "Timestamp Evidence Correlation by model based clock hypothesis testing", E-Forensics 2008, Adelaide, Australia, January 2008
- F. Buchholz, "An Improved Clock Model for Translating Timestamps", JMU-INFOSEC-TR-2007-001, James Madison University
- F. Buchholz, B. Tjaden, "A brief study of time", Digital Investigation 2007:4S
- K. Chow, F. Law, M. Kwan, P. Lai, "The Rules of Time on NTFS File System", 2nd International Workshop on Systematic Approaches to Digital Forensic Engineering, Seattle, Washington, April 2007
- B. Schatz, G. Mohay, A. Clark, "A correlation method for establishing provenance of timestamps in digital evidence", Digital Investigation 2006:3S
- P. Gladyshev, A. Patel, "Formalizing Event Time Bouding in Digital Investigation", International Journal of Digital Evidence, vol 4:2, 2005
- C. Boyd, P. Forster, "Time and Date issues in forensic computing - a case study", Digital Investigation 2004:1
- M.W. Stevens, "Unification of relative time frames for digital forensics", Digital Investigation 2004:1
- "Dynamic Time & Date Stamp Analysis", M .C. Weil, International Journal of Digital Evidence, vol 1:2, 2002
- ThemeRiver: In Search of Trends, Patterns, and Relationships, Susan Havre, Beth Hetzler, and Lucy Nowell, Battelle Pacific Northwest Division, Richland, Washington, 1999
- Timeline Visualization of Research Fronts, Steven A. Morris2, G. Yen, Zheng Wu, Benyam Asnake , School of Electrical and Computer Engineering, Oklahoma State University, Stillwater, Oklahoma. 2003
- Visualizing gaps in time-based lists, Moritz Stefaner, November 6, 2000
Tools
- Zeitline — Forensic timeline editor
- http://projects.cerias.purdue.edu/forensics/timeline.php
- http://sourceforge.net/projects/zeitline/
- log2timeline - An artifact timeline creation and analysis framework
- http://log2timeline.net
- https://blogs.sans.org/computer-forensics/2009/08/13/artifact-timeline-creation-and-analysis-tool-release-log2timeline/
- https://blogs.sans.org/computer-forensics/2009/08/14/artifact-timeline-creation-and-analysis-part-2/
- PTK has a timeline analysis tool.
- Aftertime - Java based application for creating timelines
- http://www.holmes.nl/NFIlabs/Aftertime/index.html
ns.org/computer-forensics/2009/08/13/artifact-timeline-creation-and-analysis-tool-release-log2timeline/
- https://blogs.sans.org/computer-forensics/2009/08/14/artifact-timeline-creation-and-analysis-part-2/
- PTK has a timeline analysis tool.
- Aftertime - Java based application for creating timelines
- http://www.holm
- TimeFlow - Visual timelines for investigation - source freely available
https://github.com/FlowingMedia/TimeFlow/wiki/