{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T15:43:32Z","timestamp":1783784612727,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":27,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Deutsche Forschungsgemeinschaft (DFG, German Research Foundation) as part of the Research and Training Group 2475 \u201cCybercrime and Forensic Computing\u201d","award":["393541319\/GRK2475\/2-2024"],"award-info":[{"award-number":["393541319\/GRK2475\/2-2024"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4]]},"DOI":"10.1145\/3712716.3712727","type":"proceedings-article","created":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T07:10:13Z","timestamp":1743145813000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Understanding Strategies and Challenges of Timestamp Tampering for Improved Digital Forensic Event Reconstruction"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3690-8574","authenticated-orcid":false,"given":"C\u00e9line","family":"Vanini","sequence":"first","affiliation":[{"name":"School of Criminal Justice, University of Lausanne, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1862-2900","authenticated-orcid":false,"given":"Jan","family":"Gruber","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Friedrich-Alexander-Universit\u00e4t Erlangen-N\u00fcrnberg (FAU), Erlangen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1088-8302","authenticated-orcid":false,"given":"Christopher","family":"Hargreaves","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Oxford, Oxford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7158-0219","authenticated-orcid":false,"given":"Zinaida","family":"Benenson","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Friedrich-Alexander-Universit\u00e4t Erlangen-N\u00fcrnberg (FAU), Erlangen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8279-8401","authenticated-orcid":false,"given":"Felix","family":"Freiling","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Friedrich-Alexander-Universit\u00e4t Erlangen-N\u00fcrnberg (FAU), Erlangen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5261-4600","authenticated-orcid":false,"given":"Frank","family":"Breitinger","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, University of Augsburg, Augsburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","unstructured":"Michael\u00a0A. Caloyannides. 2003. Digital \"evidence\" and reasonable doubt. IEEE Security & Privacy 1 6 (2003) 89\u201391. 10.1109\/MSECP.2003.1266366","DOI":"10.1109\/MSECP.2003.1266366"},{"key":"e_1_3_3_2_3_2","unstructured":"Brian\u00a0D. Carrier. 2003. Defining Digital Forensic Examination and Analysis Tool Using Abstraction Layers. International Journal of Digital Evidence 1 4 (2003) 1\u201312. http:\/\/www.utica.edu\/academic\/institutes\/ecii\/publications\/articles\/A04C3F91-AFBB-FC13-4A2E0F13203BA980.pdf"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","unstructured":"Eoghan Casey. 2020. Standardization of forming and expressing preliminary evaluative opinions on digital evidence. Forensic Science International: Digital Investigation 32 (March 2020) 200888. 10.1016\/j.fsidi.2019.200888","DOI":"10.1016\/j.fsidi.2019.200888"},{"key":"e_1_3_3_2_5_2","unstructured":"William\u00a0J. Chisum and Brent\u00a0E Turvey. 2000. Evidence dynamics: Locard\u2019s exchange principle & crime reconstruction. Journal of Behavioral Profiling 1 1 (2000) 1\u201315."},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","unstructured":"Kevin Conlan Ibrahim Baggili and Frank Breitinger. 2016. Anti-forensics: Furthering digital forensic science through a new extended granular taxonomy. Digital Investigation 18 (Aug. 2016) S66\u2013S75. 10.1016\/j.diin.2016.04.006","DOI":"10.1016\/j.diin.2016.04.006"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"publisher","unstructured":"Lisa\u00a0M. Dreier C\u00e9line Vanini Christopher\u00a0J. Hargreaves Frank Breitinger and Felix Freiling. 2024. Beyond timestamps: Integrating implicit timing information into digital forensic timelines. Forensic Science International: Digital Investigation 49 (2024) 301755. 10.1016\/j.fsidi.2024.301755","DOI":"10.1016\/j.fsidi.2024.301755"},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","unstructured":"Felix Freiling and Leonhard H\u00f6sch. 2018. Controlled experiments in digital evidence tampering. Digital Investigation 24 (March 2018) S83\u2013S92. 10.1016\/j.diin.2018.01.011","DOI":"10.1016\/j.diin.2018.01.011"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3465481.3470016"},{"key":"e_1_3_3_2_10_2","first-page":"77","volume-title":"2nd International Conference on i-Warfare and Security","volume":"20087","author":"Garfinkel Simson","year":"2007","unstructured":"Simson Garfinkel. 2007. Anti-forensics: Techniques, detection and countermeasures. In 2nd International Conference on i-Warfare and Security , Vol.\u00a020087. 77\u201384."},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","unstructured":"Ryan Harris. 2006. Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem. Digital Investigation 3 Supplement (2006) 44\u201349. 10.1016\/j.diin.2006.06.005","DOI":"10.1016\/j.diin.2006.06.005"},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00581-8"},{"key":"e_1_3_3_2_13_2","unstructured":"Farhad Manjoo. 2001. Unix Tick Tocks to a Billion. Wired (2001). https:\/\/www.wired.com\/2001\/09\/unix-tick-tocks-to-a-billion\/"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","unstructured":"Andrew Marrington Ibrahim Baggili George Mohay and Andrew Clark. 2011. CAT Detect (Computer Activity Timeline Detection): A tool for detecting inconsistency in computer activity timelines. Digital Investigation 8 (2011) S52\u2013S61. 10.1016\/j.diin.2011.05.007The Proceedings of the Eleventh Annual DFRWS Conference.","DOI":"10.1016\/j.diin.2011.05.007"},{"key":"e_1_3_3_2_15_2","unstructured":"Joachim Metz. 2024. Welcome to the Plaso documentation. https:\/\/plaso.readthedocs.io\/en\/latest\/"},{"key":"e_1_3_3_2_16_2","unstructured":"MITRE ATT&CK. 2020. MITRE ATT&CK v15.1 Indicator Removal: Timestomp. https:\/\/attack.mitre.org\/versions\/v15\/techniques\/T1070\/006\/"},{"key":"e_1_3_3_2_17_2","unstructured":"Christian Moch. 2015. Automatisierte Erstellung von \u00dcbungsaufgaben in der digitalen Forensik. Ph.\u00a0D. Dissertation. University of Erlangen-Nuremberg. https:\/\/d-nb.info\/1068781181"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","unstructured":"Alji Mohamed and Chougdali Khalid. 2019. Detection of Timestamps Tampering in NTFS using Machine Learning. Procedia Computer Science 160 (Jan. 2019) 778\u2013784. 10.1016\/j.procs.2019.11.011","DOI":"10.1016\/j.procs.2019.11.011"},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","unstructured":"Christopher Neale. 2023. Fool me once: A systematic review of techniques to authenticate digital artefacts. Forensic Science International: Digital Investigation 45 (June 2023) 301516. 10.1016\/j.fsidi.2023.301516","DOI":"10.1016\/j.fsidi.2023.301516"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","unstructured":"David Palmbach and Frank Breitinger. 2020. Artifacts for Detecting Timestamp Manipulation in NTFS on Windows and Their Reliability. Forensic Science International: Digital Investigation 32 (April 2020) 300920. 10.1016\/j.fsidi.2020.300920","DOI":"10.1016\/j.fsidi.2020.300920"},{"key":"e_1_3_3_2_21_2","volume-title":"The coding manual for qualitative researchers","author":"Salda\u00f1a Johnny","year":"2021","unstructured":"Johnny Salda\u00f1a. 2021. The coding manual for qualitative researchers. SAGE Publications."},{"key":"e_1_3_3_2_22_2","unstructured":"Chris\u00a0W. Sanchirico. 2004. Evidence Tampering. Duke Law Journal 53 4 (2004) 1215\u20131336."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","unstructured":"Janine Schneider Julian Wolf and Felix Freiling. 2020. Tampering with Digital Evidence is Hard: The Case of Main Memory Images. Forensic Science International: Digital Investigation 32 (2020) 300924. 10.1016\/j.fsidi.2020.300924","DOI":"10.1016\/j.fsidi.2020.300924"},{"key":"e_1_3_3_2_24_2","volume-title":"MITRE ATT&CK: Design and philosophy","author":"Strom Blake\u00a0E","year":"2020","unstructured":"Blake\u00a0E Strom, Andy Applebaum, Doug\u00a0P Miller, Kathryn\u00a0C Nickels, Adam\u00a0G Pennington, and Cody\u00a0B Thomas. 2020. MITRE ATT&CK: Design and philosophy. Technical Report MP180360R1. The MITRE Corporation."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","unstructured":"C\u00e9line Vanini Jan Gruber Christopher J. Hargreaves Zinaida Benenson Felix Freiling and Frank Breitinger. 2024. Guidelines and Questionnaires for a User Study on Live Timestamp Tampering in Digital Forensic Event Reconstruction. 10.48657\/ydrk-qa98(Version 1.0).","DOI":"10.48657\/ydrk-qa98"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","unstructured":"C\u00e9line Vanini Jan Gruber Christopher Hargreaves Zinaida Benenson Felix Freiling and Frank Breitinger. 2024. Strategies and Challenges of Timestamp Tampering for Improved Digital Forensic Event Reconstruction (extended version). 10.48550\/arXiv.2501.00175 arxiv:https:\/\/arXiv.org\/abs\/2501.00175\u00a0[cs.CR]","DOI":"10.48550\/arXiv.2501.00175"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","unstructured":"C\u00e9line Vanini Chris Hargreaves and Frank Breitinger. 2024. Evaluating tamper resistance of digital forensic artifacts during event reconstruction. 10.48550\/arXiv.2412.12814 arxiv:https:\/\/arXiv.org\/abs\/2412.12814\u00a0[cs.CR]","DOI":"10.48550\/arXiv.2412.12814"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2008.149"}],"event":{"name":"DFDS 2025: Digital Forensics Doctoral Symposium","location":"Brno Czech Republic","acronym":"DFDS 2025"},"container-title":["Proceedings of the Digital Forensics Doctoral Symposium"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3712716.3712727","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3712716.3712727","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:09Z","timestamp":1750295889000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3712716.3712727"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4]]},"references-count":27,"alternative-id":["10.1145\/3712716.3712727","10.1145\/3712716"],"URL":"https:\/\/doi.org\/10.1145\/3712716.3712727","relation":{},"subject":[],"published":{"date-parts":[[2025,4]]},"assertion":[{"value":"2025-04-01","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}