Conceptual

Tamper-Resistance Factors for Live-System Timestamp Forensics

Through a qualitative user study -- ten advanced students tasked with forging timestamps on a running virtual machine, followed by questionnaires and semi-structured interviews -- this work explains why tampering with digital evidence on a live system is hard rather than merely showing that it is. Participants converged on a multi-step strategy for handling second-order traces (the traces left by the act of tampering itself), and the study derives the factors that govern whether tampering succeeds undetected: the tamperer's knowledge of which temporal artifacts exist, the technical restrictions on altering them, and the propagation of second-order traces. These factors let an investigator reason about how far a given timestamp can be trusted during event reconstruction.