Didier Stevens complains about the feigned accuracy of timestamps in forensic reports and tool outputs. Timestamps are indicated up to the dot, though the accuracy of the data source is worse. Stevens cites the electronic purse as an example. Another example, that should be well-known among computer forensic practitioners, is the FAT file system that provides timestamps with a resolution of only 2 seconds. Therefore Stevens suggests to use the scientific error notation in reports, e.g. 11:37:30 ± 675s.
Accuracy of Timestamps
By Andreas Schuster on October 7, 2008 4:00 PM
Categories:
Tags:
Search
Deutsch
Recent Entries
Tag Cloud
Categories
Imprint
This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de
Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de
Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
