Computer Theory
摘要
Perhaps the most important skill for someone working with computer forensics is to know how computers work. In order to locate digital traces of an e-mail, the examiner must know what such traces may look like. While this book is intended for someone who is fairly skilled in the computer world, there is theory that is extra important for a forensic examiner, and this computer theory is presented in this chapter. This includes an overview of encryptionEncryption as well as a presentation of how data is represented in the digital world, in binary, hexadecimal, and plain ASCII. Further, this chapter introduces theory that is often overlooked by disciplines other than computer forensics. This includes an overview of the NTFSNTFS file systemFile system and the Windows registryWindows Registry—which is one of the most valuable sources of information during an examinationExamination of a Windows computer. The chapter also describes what happens when files are deleted, both from the perspective of the file systemFile system and the actual hard driveHard Drive.