applied sciences Article Extraction of Creation-Time for Recovered Files on Windows FAT32 File System Wan Yeon Lee 1, Kyong Hoon Kim 2 and Heejo Lee 3,* 1 Department of Computer Science, Dongduk Women’s University, Seoul 02748, Korea;
[email protected] or
[email protected] 2 Department of Informatics, Gyeongsang National University, Jinju 52828, Korea;
[email protected] 3 Department of Computer Science and Engineering, Korea University, Seoul 02841, Korea * Correspondence:
[email protected]; Tel.: +82-2-3290-3208 Received: 16 November 2019; Accepted: 11 December 2019; Published: 15 December 2019 Abstract: In this article, we propose a creation order reconstruction method of deleted files for the FAT32 file system with Windows operating systems. Creation order of files is established using a correlation between storage locations of the files and their directory entry locations. This method can be utilized to derive the creation-time bound of files recovered without the creation-time information. In this article, we first examine the file allocation behavior of Windows FAT32 file system. Next, based on the examined behavior, we propose a novel method that finds the creation order of deleted files after being recovered without the creation-time information. Due to complex behaviors of Windows FAT32 file system, the method may find multiple creation orders although the actual creation order is unique. In experiments with a commercial device, we confirm that the actual creation order of each recovered file belongs to one of the creation orders found by the method. Keywords: creation-time; FAT32 file system; file allocation behavior; order reconstruction; recovered file 1.