ADS Analytics on NTFS Date-time Stamps for Event Reconstruction

碩士 === 中央警察大學 === 資訊管理研究所 === 107 === Alternate Data Stream (ADS) can be stored into existing files without affecting their functionality, size, or display. Executables in ADS can be executed from the command line. It is common for attackers to hide malware in cover media (files or folders) by ADS c...

Full description

Bibliographic Details
Main Authors: CHEN, YUAN-PEI, 陳元培
Other Authors: Kao, Da-Yu
Format: Others
Language:en_US
Published: 2018
Online Access:http://ndltd.ncl.edu.tw/handle/m2hamv