Search Results

Documents authored by Timbermont, Bouke


Document
A Formal Model for Forensically Sound Timestamp Normalization

Authors: Lorenz Hornung, Carly Bakker, Bouke Timbermont, Roel van Dijk, Harm van Beek, and Natasha Alechina

Published in: OASIcs, Volume 146, 33rd International Symposium on Temporal Representation and Reasoning (TIME 2026)


Abstract
Digital forensic analysts interpret timestamps from digital systems to assess what happened in the past. Since these systems encode time according to different underlying domains, timestamps cannot be interpreted uniformly. To enable cross-system analysis, timestamps must therefore be normalized. In this paper, we propose a formal model for forensically sound timestamp normalization and examine its properties. We show that normalization generally does not guarantee the comparability of normalized timestamps. This means that the temporal order of digitally tracked events cannot always be determined. Furthermore, we illustrate that existing forensic tools do not adhere to the proposed normalization, resulting in violations of forensic soundness in the example discussed.

Cite as

Lorenz Hornung, Carly Bakker, Bouke Timbermont, Roel van Dijk, Harm van Beek, and Natasha Alechina. A Formal Model for Forensically Sound Timestamp Normalization. In 33rd International Symposium on Temporal Representation and Reasoning (TIME 2026). Open Access Series in Informatics (OASIcs), Volume 146, pp. 10:1-10:21, Schloss Dagstuhl – Leibniz-Zentrum für Informatik (2026)


Copy BibTex To Clipboard

@InProceedings{hornung_et_al:OASIcs.TIME.2026.10,
  author =	{Hornung, Lorenz and Bakker, Carly and Timbermont, Bouke and van Dijk, Roel and van Beek, Harm and Alechina, Natasha},
  title =	{{A Formal Model for Forensically Sound Timestamp Normalization}},
  booktitle =	{33rd International Symposium on Temporal Representation and Reasoning (TIME 2026)},
  pages =	{10:1--10:21},
  series =	{Open Access Series in Informatics (OASIcs)},
  ISBN =	{978-3-95977-448-2},
  ISSN =	{2190-6807},
  year =	{2026},
  volume =	{146},
  editor =	{Orlandini, AndreA and Pinchinat, Sophie},
  publisher =	{Schloss Dagstuhl -- Leibniz-Zentrum f{\"u}r Informatik},
  address =	{Dagstuhl, Germany},
  URL =		{https://drops.dagstuhl.de/entities/document/10.4230/OASIcs.TIME.2026.10},
  URN =		{urn:nbn:de:0030-drops-277061},
  doi =		{10.4230/OASIcs.TIME.2026.10},
  annote =	{Keywords: Digital Forensics, Formal Model, Timestamp, Normalization}
}

Any Issues?
X

Feedback on the Current Page

CAPTCHA

Thanks for your feedback!

Feedback submitted to Dagstuhl Publishing

Could not send message

Please try again later or send an E-mail