
This article is about Digital Forensic process including acquisition, processing, and analyzing data from windows-based harddisk.
Executive Summary
The article aims to explore about digital forensic, data retrieval, and analysis from windows-based hard disks acquired from public market place. The urgent needs for this article is to notify the potential risks about data fragments that still dwells on the hard disk even when the data already erased, which this case can lead to unauthorized access to confidential data or sensitive information.
1. Methodology
There are four main process in the Digital Forensic, which are Preparation, Acquisition, Analysis, and Reporting.

Preparation
- Resource preparation: Buy hard disks from public market place with minimum size of 250 GB.
- Define Objectives: Determine the goal of forensic analysis (data recovery, evidence gathering, malware investigation).
- Gather Tools: Identify the tools we need for supporting the digital forensic process, such as FTK Imager for acquisition, Autopsy or OSForensics for analysis.
Acquisition
- Write Blockers: Use software, hardware, or boot-able USB to ensure that no data is modified when doing acquisition process.
- Create Forensic Images: Acquire the images of the hard disk that we want to use for analyzing using imaging tools like FTK Imager, and determine the format data we want to use such as E01, dd or etc.. Ensure the acquired images data has the integrity with the real images data using hash checksum (MD5, SHA256).
- Log Everything: Keep a track the chain of custody for who was handling the evidence, the time when it was collected, and the time when it was returned.
Analysis
File System Analysis
- Identify File System Type: Determine what the file system is used (NTFS, FAT32, etc).
- Recover Deleted Files: Use file recovery techniques and tools to recover deleted files and analyze their metadata (timestamps, file size).
- Check for Hidden Files: Look for hidden, system files, or camouflaged files that may contain relevant evidence.
Registry Analysis
- Extract Registry: Analyze Windows registry to gather information about user, installed software, and system configuration.
Artifact Analysis
- Investigate Temporary Files: Examine temporary files, prefetch files, and recent documents for trails of user activity.
- Review Log Files: Analyze Windows Event Logs, Security Logs, and application logs for relevant actions and events.
Memory Analysis
- Utilize Memory Dumps: If available, analyze memory dumps to extract live data about processes, network connections, and other volatile information.
Timeline Creation
- Establish a Timeline: Create and chronologically arrange events based on file metadata, log files, and registry entries to create a timeline of user activity.
Reporting
- Document Findings: Create a comprehensive report detailing methods used, findings from analysis, and the significance of discovered artifacts.
2. Preparation
For this article, the process is carried out by purchasing several hard disks from the public market place and e-commerce platforms. We need to make sure that the hard disk that we bought is a windows based operating system. To make the acquisition and analyzing process much faster, we limiting the hard disks size to 250 GB only.
The following tools of this project are:
- FTK Imager tool for acquisition process
- Autopsy version 4.21.0 (Windows) tool for analysis purposes
- USB Write Protect version 2.0.0 (Windows) for write blocker.
- Boot-able USB with Linux OS can be used as alternative write blocker
- CrystaldiskInfo application to check the status and health of the hard disks.
- Orico Docker for mounting the hard disks.
- Sandisk External SSD with capacity of 2 TB is used to save the images of each hard disk and for analysis purposes.
3. Acquisition
Before doing the acquisition process, make sure the write blocker application or the boot-able runs correctly to ensure that no modified data when in the middle of acquisiton process. After that, the imaging process is carried out using the FTK Imager tool and we choose the Raw (dd) data format. This format was chosen not only because it is easy, but it also performs bit-for-bit copy without compression, thus we can get a identical image as the real image data. The image data we get from the acquisition process is stored in the external SSD that we prepared before.
| Name | MD5 Hash | Verified | Health |
|---|---|---|---|
| DF-01 | b95259e45a6eccb464f7ce7bf401fd69 | Yes | 96% |
| DF-02 | e29e70fce358dc1cd1848864e3be3c9c | Yes | 69% |
| DF-03 | db7b17357f7d8cc0da95a40cf6da29f2 | Yes | 100% |
From the results of the check using the Crystal disk application, not all hard disks we have are 100% healthy, but the acquisition process can still be carried out perfectly. Since we have 3 hard disks, we can respectively named it using a code to make it easier to investigate later. When the acquisition process is finished, each images from every hard disks have MD5 hash value, we need to make sure that the MD5 hash value of the imaged data match perfectly with the original image MD5 Hash value.
4. Analysis
After finishing the imaging process, the next step is to analyze the images in external SSD using analysis tools. Using Autopsy we can conduct an investigation of user profiling, date recovery, and data leak identification. After analyzing and investigating the image of several hard disks using keyword search and file identification, we find that one of the image of the hard disks contains information related to user profile, sensitive information and confidential data.
DF-01
On this hard disk, the operating system and user account were found, but there was no other supporting sufficient data to perform user profiling account. Because of the very small amount of data in files and history on the website, we unable to determine the user behaviour.
DF-02
On this hard disk, the operating system was found and DF-02 has a user profile and some confidential data or sensitive information. Using the Autopsy tools, various pieces of information can be recovered on this hard disks, and this hard disks has sufficient data to help our investigation.
DF-03
On this hard disk, the operation system used was also found, but there was no specific user account used by the user plus there was no other supporting data sufficient to perform user profiling on the account. Also, no confidential data was found on this hard disk. But there is one thing that is quite interesting, a ZIP file was found that is suspected to be a ZIP Bomb file.
Keywords Used
The following are the keywords that used during the analysis and investigation process.
| Keywords | Files with Hits | Keywords | Files with Hits |
|---|---|---|---|
| akta (188) | 188 | gmail (486) | 486 |
| alamat (215) | 215 | hack (859) | 859 |
| biaya (146) | 146 | hang tuah (36) | 36 |
| B*****g (4997) | 4997 | instagram (16) | 16 |
| budget (200) | 200 | K*****i (104) | 104 |
| cheat (486) | 486 | kartu keluarga (4) | 4 |
| confidential (6375) | 6375 | kartu kredit (18) | 18 |
| crack (430) | 430 | kesehatan (400) | 400 |
| credit card (358) | 358 | keuangan (86) | 86 |
| daftar riwayat hidup (31) | 31 | kk (34266) | 34266 |
| data pribadi (20) | 20 | ktp (3012) | 3012 |
| dump (2198) | 2198 | lahir (129) | 129 |
| email (3532) | 3532 | L**u (5729) | 5729 |
| f1460141 (1) | 1 | l******i@gmail.com (4) | 4 |
| facebook (2031) | 2031 | mabes (80) | 80 |
| finance (193) | 193 | markas (46) | 46 |
| finansial (36) | 36 | memdump (4) | 4 |
| foursquare (19) | 19 | memory (15337) | 15337 |
| gaji (212) | 212 | messenger (1556) | 1556 |
| game (5629) | 5629 | nota (449) | 449 |
| pasien (152) | 152 | sertifikat (57) | 57 |
| payroll (30) | 30 | tni (5492) | 5492 |
| pembayaran (72) | 72 | tni al (177) | 177 |
| pembelian (46) | 46 | yahoo (2710) | 2710 |
| perjanjian (59) | 59 | peraturan (107) | 107 |
| pribadi (142) | 142 | ||
| profile (13165) | 13165 | ||
| rahasia (77) | 77 | ||
| riwayat (144) | 144 | ||
| salary (68) | 68 |
OS Information & Accounts
For the DF-01 hard disk, the previous user used Windows 10 Pro operating system with AMD64 architecture. The user is known to use the P***o A*******r user account. The author has tried to do user profiling but due to lack of supporting data, this user data could not be obtained.
| Hard disk | DF-01 |
| OS | Windows 10 Pro |
| Architecture | AMD64 |
| User Account |
|
| Primary User | P***o A*******r |
For DF-02 hard disk, the previous user used the Windows 7 Ultimate Service Pack 1 operating system with x86 architecture. The hard disk owner's name is L**u, and the name of her computer L**U-PC. We found several accounts used in this hard disk.
We analyzed the accounts and concluded that there were 2 main accounts that were most often used, namely the L**u account as many as 907 times and B*****g as many as 1198 times. The B*****g account was created on May 21, 2011, and L**u was created on October 15, 2012. Both of these accounts are Administrator accounts and were found no need to use passwords to log in. Apart from the 2 accounts mentioned above, there were 2 Administrator and Guest accounts were also found each with disabled status.
| Hard disk | DF-02 |
| OS | Windows 7 Ultimate Service Pack 1 |
| Architecture | x86 |
| User Account |
|
| Primary User |
|
For DF-03 hard disk, no specific user account was found from the previous user and the lacks of other supporting data meant that the we did not get user profiling from the previous user.
| Hard disk | DF-03 |
| OS | Windows 10 Home |
| Architecture | AMD64 |
| User Account |
|
| Primary User | Administrator |
User Profile & Data Leak
User profile is information about the previous users which can contain data such as:
- Full name.
- Residential address.
- Place of work.
Meanwhile, data leaks are sensitive information that is meant to be kept private and is protected from unauthorized access, disclosure, or use that is successfully found during the analysis and investigation process such as:
- Personal Identifiable Information (PII).
- Protected Health Information.
- Financial Information.
In conducting the analysis, We found a user profile on DF-02 hard disk that matched one of the user accounts and computer names obtained previously, namely L**u. Then we conducted further investigation and found data related to L**u including college registration, driver's license number, residential address, email, social media and other supporting data.
| File | Location | MD5 Hash | Notes |
|---|---|---|---|
| 711056088.pdf | /img_DF-02.001/vol_vol6/$CarvedFiles/13/f0024165.pdf | 39fac4c23bd37d5faf79ae99bed24404 | Registration form contain PII and license number |
| ijasah 22.pdf | /img_DF-02.001/vol_vol2/Windows.old/Users/B*****g/Documents/ijasah 22.pdf | 81555d8cad171914263f4d80d58eb0ab | Ijazah K*****i |
| ijasah 33.pdf | /img_DF-02.001/vol_vol2/Windows.old/Users/B*****g/Documents/ijasah 33.pdf | a1729adfc93f696e79976c30311f7a1a | Ijazah K*****i |
| places.sqlite | /img_DF-02.001/vol_vol2/## aswSnx private storage/sfzone/image/Users/B*****g/AppData/Roaming/Mozilla/Firefox/Profiles/apbmfcu0.default/places.sqlite | e875dc678a4b65d22ddcf96e77c59630 | K*****i Facebook Profile (1) |
| History | /img_DF-02.001/vol_vol2/Windows.old/Users/B*****g/AppData/Local/Google/Chrome/User Data/Default/History | d3785af792ca3595a68e45acc9193c4e | K*****i Facebook Profile (2) |
| f0313845.docx | /img_DF-02.001/vol_vol6/$CarvedFiles/10/f0313845.docx | fbf537a355db1a56327e4e815880de6d | K*****i Curriculum Vitae |
| f0069113.jpg | /img_DF-02.001/vol_vol6/$CarvedFiles/26/f0069113.jpg | bce5aeb5b9436125ef0696763e9768cb | K*****i's photo with her husband |
| f0293033.jpg | /img_DF-02.001/vol_vol6/$CarvedFiles/23/f0293033.jpg | 6c4c23e3bf43d8b72a08633945125b7b | K*****i's photo with TNI uniform. |
| f0598525.jpg | /img_DF-02.001/vol_vol6/$CarvedFiles/11/f0598525.jpg | 329da7afb743b2c031d7baf922ff4320 | K*****i's photo with T*I uniform. |
| f0986341.jpg | /img_DF-02.001/vol_vol6/$CarvedFiles/20/f0986341.jpg | a757997fa9975083fd93207d83e0fb9a | K*****i's photo with her childrens. |
From several sample data that shown above, we found that L**u's real name is K*****i and was born in B*****i on February 2, 19**. K*****i graduated from the H******h Dental Academy in Jakarta in 20**. It seems that K*****i tried to continue her education to a bachelor's program at the University of I******a majoring in Public Health. K*****i used her email l**uK*****i@gmail.com for the registration. Based on cross-references from data in documents and her social media, K*****i has 3 work history which we can't shown due to privacy. And what we got from the analysis was that K*****i has a permanent address in the B****i area, but also has a temporary residence in the Jakarta. She is married, and have kids.
For the summary above, what we found in the hard disk contains Data Leak from previous user, that contains Driving License Number, educational certificate, and Curriculum vitae. All of those data leaks are confidential data and sensitive information that can be used as malicious activity. And for the DF-01 and DF-03 hard disks, we did not find any user profile and confidential data leaks.
User Behaviour & Other Information
For DF-02 hard disk, the author conducted a behavioral analysis of previous users starting from the analysis of programs installed on the OS. Many games were found installed in the OS, it seems that K*****i's children installed and played the games. Pirated games were also found in it. Previous users also installed common programs such as Microsoft Office, Nitro PDF, Yahoo! Messenger and Google Chrome.
| Software | Location | MD5 Hash | Notes |
|---|---|---|---|
| Big Kahuna Reef | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Games |
| Poker Superstars | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Games |
| Mah Jong Medley | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Games |
| Counter-Strike 1.6 v.Counter-Strike 1.6 No Steam | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Games |
| Mozilla Firefox | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Browser |
| Microsoft Office Enterprise 2007 | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Office |
| Microsoft Outlook 2007 | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Email Software |
| Adobe Flash Player 11 | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Flash Player |
| Yahoo! Messenger | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Chatting Apps |
| Internet Download Manager | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Downloader Apps |
| K-Lite Codec Pack | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Media Player |
| Nitro PDF Professional | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | PDF Reader |
| Google Chrome | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Browser |
| Mozilla Firefox | /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE | f940198b8253f541f2e2fad8cc7fcba4 | Browser |
| Crack.lnk | F:\Pes 2011 v1 02\Crack | db3eb46c900832a034a5c69d73f39ff7 | Pirate Games |
When analyzing office files and PDF formats, many readings and presentation materials were found on health, especially in the military environment, considering K*****i's background in health and the military.
| File | Location | MD5 Hash | Notes |
|---|---|---|---|
| f0613373_DATA_LAPORAN_I*****S.ppt | /img_DF-02.001/vol_vol6/$CarvedFiles/17/f0613373_DATA_LAPORAN_I*****S.ppt | 10478310a82d602764a30f26ccdd1e58 | Work place information data |
| f0085701_INFORMASI_DASAR_PMS_HIV_AIDS.ppt | /img_DF-02.001/vol_vol6/$CarvedFiles/17/f0085701_INFORMASI_DASAR_PMS_HIV_AIDS.ppt | cd9363b387e60fa41bf4e6a942c63019 | Basic information about HIV AIDS |
| f0901621_PERATURAN_PER_UU_YG_BERKAITAN_DENGAN_TUGAS2_***.ppt | /img_DF-02.001/vol_vol6/$CarvedFiles/12/f0901621_PERATURAN_PER_UU_YG_BERKAITAN_DENGAN_TUGAS2_***I.ppt | 1f4022a71fe4a5bc35270f538b397b8b | Regulations relating to work duties |
The author also found a third-party antivirus installed in the OS using ESET NOD32. Seeing that this third-party antivirus is installed, it can be concluded that the user are concerned about their device security.
| Software | Location | MD5 Hash | Notes |
|---|---|---|---|
| ESET NOD32 Antivirus v.3.0.672.0 | /img_DF-02.001/vol_vol2/Windows/System32/config/software | d199431bdffafcd70b3a648a0c777715 | Antivirus |
From the results of the search on web history, the author found that Facebook is one of the most frequently accessed websites by K****i, From the results of the search on web history, the author found that Facebook was one of the most frequently accessed websites by K*****i, then Twitter became the next website that was frequently accessed.
We also found that there were 2 chromium profiles, namely First User which was used by the L**u account and Default Profile which was used by the B*****g account. For the DF-01 and DF-03 hard disks, we did not find any user behavior instructions or other supporting information because the lacks of data.
5. Conclusion
Based on the results of the digital forensics investigation that has been carried out, we can draw conclusions:
- For the user profile, we found the main user account used in the OS from DF-02 hard disk, namely L**u, whose real name is K*****i. The woman who was born in B******i on February 2, 19**, her 3 work of history. Her current addreses, her family, and the evidence of her and her family photos.
- For confidential data leaks, we found a educational certificate, curriculum vitae and driver's license number from K*****i from DF-02 hard disk. The certificate found was a certitiface when she took education at the H******h Academy in Jakarta. Then the resume includes the date of birth, position, rank history and position history. And finally on the registration form, the author found the driver's license number used as the ID to register.
- For user behavior, we found that users install a lot of game applications and several commonly installed programs such as Microsoft Office and Google Chrome on the OS, some were found to use pirated game applications from DF-02 hard disk. The author also found that the user was using ESET NOD32 antivirus. Also found were many files of materials and presentations related to health and military, according to the user's background.
Appendix
1. Hard disks bought from the market place
DF-01
- Brand: Hitachi
- Size: 250 GB
- P/N: 0A73352

DF-02
- Brand: Hitachi
- Size: 250 GB
- P/N: 0A74422

DF-03
- Brand: Hitachi
- Size: 250 GB
- P/N: 0A70432

2. Acquisition
FTK Imager DF-01
Created By Exterro® FTK® Imager 4.7.3.81Case Information:Acquired using: ADI4.7.3.81Case Number: DF-01Evidence Number: 01Unique description: DF-01Examiner: DFIRNotes:Information for F:\DF-01\DF-01:Physical Evidentiary Item (Source) Information:[Device Info]Source Type: Physical[Drive Geometry]Cylinders: 30.401Tracks per Cylinder: 255Sectors per Track: 63Bytes per Sector: 512Sector Count: 488.397.168[Physical Drive Information]Drive Model: HITACHI HTS725025A9A361 SCSI Disk DeviceDrive Serial Number: 8F9038EE1A62Drive Interface Type: SCSIRemovable drive: FalseSource data size: 238475 MBSector count: 488397168ATTENTION:The following sector(s) on the source drive could not be read:287027738The contents of these sectors were replaced with zeros in the image.[Computed Hashes]MD5 checksum: 8d608d993a1b6b7c9588860e1b096184SHA1 checksum: c6bf819984808887d40f507992a8e8c105604d0bSegment list:F:\DF-01\DF-01.001COMPUTED HASH : 8d608d993a1b6b7c9588860e1b096184COMPUTED HASH : c6bf819984808887d40f507992a8e8c105604d0bImage Verification Results:MD5 checksum: 8d608d993a1b6b7c9588860e1b096184 : verifiedSHA1 checksum: c6bf819984808887d40f507992a8e8c105604d0b : verified
FTK Imager DF-02
Created By Exterro® FTK® Imager 4.7.3.81Case Information:Acquired using: ADI4.7.3.81Case Number: 2Evidence Number: DF-02Unique description: HITACHI 250 GB-0A74422Examiner: DFIRPhysical Evidentiary Item (Source) Information:[Device Info]Source Type: Physical[Drive Geometry]Cylinders: 30.401Tracks per Cylinder: 255Sectors per Track: 63Bytes per Sector: 512Sector Count: 488.397.168[Physical Drive Information]Drive Model: Hitachi HTS545025B9A300 SCSI Disk DeviceDrive Serial Number: 8F9038EE1A62Drive Interface Type: SCSIRemovable drive: FalseSource data size: 238475 MBSector count: 488397168[Computed Hashes]MD5 checksum: e29e70fce358dc1cd1848864e3be3c9cSHA1 checksum: 183dd19f8f0330ec8e15dabdba2da2d61b4fa079Segment list:D:\DF-02\DF-02.001COMPUTED HASH : e29e70fce358dc1cd1848864e3be3c9cCOMPUTED HASH : 183dd19f8f0330ec8e15dabdba2da2d61b4fa079Image Verification Results:MD5 checksum: e29e70fce358dc1cd1848864e3be3c9c : verifiedSHA1 checksum: 183dd19f8f0330ec8e15dabdba2da2d61b4fa079 : verified
FTK Imager DF-03
Created By Exterro® FTK® Imager 4.7.3.81Case Information:Acquired using: ADI4.7.3.81Case Number: DF-03Evidence Number: 03Unique description: DF-03Examiner: DFIRNotes:Information for E:\DF-03\DF-03:Physical Evidentiary Item (Source) Information:[Device Info]Source Type: Physical[Drive Geometry]Cylinders: 30.401Tracks per Cylinder: 255Sectors per Track: 63Bytes per Sector: 512Sector Count: 488.397.168[Physical Drive Information]Drive Model: Hitachi HTS545025B9A300 SCSI Disk DeviceDrive Serial Number: 8F9038EE1A62Drive Interface Type: SCSIRemovable drive: FalseSource data size: 238475 MBSector count: 488397168[Computed Hashes]MD5 checksum: ab3965104e82b4c44d60c8afeabb8ebcSHA1 checksum: 912e8b113c5d36ed5705772f6d2d90489cab5e5eSegment list:E:\DF-03\DF-03.001COMPUTED HASH : ab3965104e82b4c44d60c8afeabb8ebcCOMPUTED HASH : 912e8b113c5d36ed5705772f6d2d90489cab5e5eImage Verification Results:MD5 checksum: ab3965104e82b4c44d60c8afeabb8ebc : verifiedSHA1 checksum: 912e8b113c5d36ed5705772f6d2d90489cab5e5e : verified
3. Analysis Process



4. OS Information
OS Information DF-01
File: /img_DF-01.001
MD5: -
Tools: Autopsy
Short Description: OS Information from DF-01
Artifacts: A1

OS Information DF-02
File: /img_DF-02.001
MD5: e29e70fce358dc1cd1848864e3be3c9c
Tools: Autopsy
Short Description: OS Information from DF-02
Artifacts: A2

OS Information DF-03
File: /img_DF-03.001
MD5: -
Tools: Autopsy
Short Description: OS Information from DF-03
Artifacts: A3

5. OS Accounts
OS Account DF-01


OS Account DF-02


OS Account DF-03

6. Sample list of installed games
Installed Games in DF-02 account

7. Antivirus installed
Antivirus in DF-02
File: /img_DF-02.001/vol_vol2/Windows/System32/config/RegBack/SOFTWARE
MD5: f940198b8253f541f2e2fad8cc7fcba4
Tools: Autopsy
Short Description: Sample list of installed antivirus.
Artifacts: A18

8. ZIP Bomb
ZIP Bomb in DF-03
File: /img_DF-03.001/vol_vol6/Windows/bootstat.dat
MD5: 926d009a45277629a81311ba551e6815
Tools: Autopsy
Short Description: ZIP Bomb file.
Artifacts: A21

References
- [1]Amoruso, E., Zou, C. and Leinecker, R. (2023) 'User Profiling Attack Using Windows Registry Data', 2023 IEEE 14th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), pp. 171–181. https:
/ / doi.org/ 10.1109/ UEMCON59035.2023.10315968 - [2]Carvey, H.A. (2009) Windows forensic analysis DVD toolkit 2E. 2nd ed. Burlington, Mass: Syngress Pub.
- [3]Dong, X. et al. (2020) 'Profiling users via their reviews: an extended systematic mapping study', Software and Systems Modeling, 20, pp. 49–69. https:
/ / doi.org/ 10.1007/ s10270- 020- 00790- w - [4]Kwon, H., Lee, S. and Jeong, D. (2021) 'User profiling via application usage pattern on digital devices for digital forensics', Expert Syst. Appl., 168, p. 114488. https:
/ / doi.org/ 10.1016/ j.eswa.2020.114488 - [5]
- [6]



