{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T15:20:03Z","timestamp":1762010403197,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":51,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030105426"},{"type":"electronic","value":"9783030105433"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-10543-3_8","type":"book-chapter","created":{"date-parts":[[2019,3,22]],"date-time":"2019-03-22T18:03:29Z","timestamp":1553277809000},"page":"179-210","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Big Data Forensics: Hadoop Distributed File Systems as a Case Study"],"prefix":"10.1007","author":[{"given":"Mohammed","family":"Asim","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dean Richard","family":"McKinnel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reza M.","family":"Parizi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gregory","family":"Epiphaniou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,3,23]]},"reference":[{"key":"8_CR1","doi-asserted-by":"crossref","unstructured":"S. Tahir and W. Iqbal, \u201cBig Data-An evolving concern for forensic investigators,\u201d in 2015 1st International Conference on Anti-Cybercrime, ICACC 2015, 2015.","DOI":"10.1109\/Anti-Cybercrime.2015.7351932"},{"key":"8_CR2","doi-asserted-by":"crossref","unstructured":"W. Yang, G. Wang, K.-K. R. Choo, and S. Chen, \u201cHEPart: A balanced hypergraph partitioning algorithm for big data applications,\u201d Futur. Gener. Comput. Syst., Jan. 2018.","DOI":"10.1016\/j.future.2018.01.009"},{"key":"8_CR3","doi-asserted-by":"crossref","unstructured":"W. A. G\u00fcnther, M. H. Rezazade Mehrizi, M. Huysman, and F. Feldberg, \u201cDebating big data: A literature review on realizing value from big data,\u201d J. Strateg. Inf. Syst., 2017.","DOI":"10.1016\/j.jsis.2017.07.003"},{"key":"8_CR4","unstructured":"T. H. Davenport and J. Dyche, \u201cBig Data in Big Companies,\u201d Int. Inst. Anal., no. May, pp. 1\u201331, 2013."},{"key":"8_CR5","doi-asserted-by":"crossref","unstructured":"B. Fang and P. Zhang, \u201cBig data in finance,\u201d in Big Data Concepts, Theories, and Applications, 2016, pp. 391\u2013412.","DOI":"10.1007\/978-3-319-27763-9_11"},{"key":"8_CR6","doi-asserted-by":"crossref","unstructured":"S. Sharma, U. S. Tim, J. Wong, S. Gadia, and S. Sharma, \u201cA Brief Review on Leading Big Data Models,\u201d Data Sci. J., vol. 13, no. December, pp. 138\u2013157, 2014.","DOI":"10.2481\/dsj.14-041"},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"S. Yu and S. Guo, Big Data Concepts, Theories, and Applications, 1st ed. 20. Cham: Springer International Publishing, 2016.","DOI":"10.1007\/978-3-319-27763-9"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"X. Wu, X. Zhu, G. Q. Wu, and W. Ding, \u201cData mining with big data,\u201d IEEE Trans. Knowl. Data Eng., vol. 26, no. 1, pp. 97\u2013107, 2014.","DOI":"10.1109\/TKDE.2013.109"},{"key":"8_CR9","doi-asserted-by":"crossref","unstructured":"C. Vorapongkitipun and N. Nupairoj, \u201cImproving performance of small-file accessing in Hadoop,\u201d in 2014 11th Int. Joint Conf. on Computer Science and Software Engineering: \u201cHuman Factors in Computer Science and Software Engineering\u201d - e-Science and High Performance Computing: eHPC, JCSSE 2014, 2014, pp. 200\u2013205.","DOI":"10.1109\/JCSSE.2014.6841867"},{"key":"8_CR10","doi-asserted-by":"crossref","unstructured":"Y. Y. Teing, A. Dehghantanha, and K. K. R. Choo, \u201cCloudMe forensics: A case of big data forensic investigation,\u201d Concurrency Computation, 2017.","DOI":"10.1002\/cpe.4277"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"X. Fu, Y. Gao, B. Luo, X. Du, and M. Guizani, \u201cSecurity Threats to Hadoop: Data Leakage Attacks and Investigation,\u201d IEEE Netw., vol. 31, no. 2, pp. 67\u201371, 2017.","DOI":"10.1109\/MNET.2017.1500095NM"},{"key":"8_CR12","doi-asserted-by":"crossref","unstructured":"A. Azmoodeh, A. Dehghantanha, M. Conti, and K.-K. R. Choo, \u201cDetecting crypto-ransomware in IoT networks based on energy consumption footprint,\u201d J. Ambient Intell. Humaniz. Comput., pp. 1\u201312, Aug. 2017.","DOI":"10.1007\/s12652-017-0558-5"},{"key":"8_CR13","doi-asserted-by":"crossref","unstructured":"J. Baldwin and A. Dehghantanha, Leveraging support vector machine for opcode density based detection of crypto-ransomware, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_6"},{"key":"8_CR14","unstructured":"A. D. James Baldwin, Omar Alhawi, Leveraging Machine Learning Techniques for Windows Ransomware Network Traffic Detection. Cyber Threat Intelligence- Springer Book, 2017."},{"key":"8_CR15","doi-asserted-by":"crossref","unstructured":"D. Kiwia, A. Dehghantanha, K.-K. R. Choo, and J. Slaughter, \u201cA cyber kill chain based taxonomy of banking Trojans for evolutionary computational intelligence,\u201d J. Comput. Sci., Nov. 2017.","DOI":"10.1016\/j.jocs.2017.10.020"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"O. Osanaiye, H. Cai, K.-K. R. Choo, A. Dehghantanha, Z. Xu, and M. Dlodlo, \u201cEnsemble-based multi-filter feature selection method for DDoS detection in cloud computing,\u201d Eurasip J. Wirel. Commun. Netw., vol. 2016, no. 1, 2016.","DOI":"10.1186\/s13638-016-0623-3"},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"F. Daryabar, A. Dehghantanha, and K.-K. R. Choo, \u201cCloud storage forensics: MEGA as a case study,\u201d Aust. J. Forensic Sci., pp. 1\u201314, Apr. 2016.","DOI":"10.1080\/00450618.2016.1153714"},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"M. Shariati, A. Dehghantanha, and K.-K. R. Choo, \u201cSugarSync forensic analysis,\u201d Aust. J. Forensic Sci., vol. 48, no. 1, pp. 95\u2013117, Apr. 2015.","DOI":"10.1080\/00450618.2015.1021379"},{"key":"8_CR19","doi-asserted-by":"crossref","unstructured":"S. Almulla, Y. Iraqi, and A. Jones, \u201cCloud forensics: A research perspective,\u201d in 2013 9th International Conference on Innovations in Information Technology, IIT 2013, 2013, pp. 66\u201371.","DOI":"10.1109\/Innovations.2013.6544395"},{"key":"8_CR20","doi-asserted-by":"crossref","unstructured":"O. Tabona and A. Blyth, \u201cA forensic cloud environment to address the big data challenge in digital forensics,\u201d in 2016 SAI Computing Conference (SAI), 2016, pp. 579\u2013584.","DOI":"10.1109\/SAI.2016.7556039"},{"key":"8_CR21","doi-asserted-by":"crossref","unstructured":"Y. Gao and B. Li, \u201cA forensic method for efficient file extraction in HDFS based on three-level mapping,\u201d Wuhan Univ. J. Nat. Sci., vol. 22, no. 2, pp. 114\u2013126, 2017.","DOI":"10.1007\/s11859-017-1224-7"},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"A. Guarino, \u201cDigital Forensics as a Big Data Challenge,\u201d in ISSE 2013 Securing Electronic Business Processes, 2013, pp. 197\u2013203.","DOI":"10.1007\/978-3-658-03371-2_17"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"S. Zawoad and R. Hasan, \u201cDigital Forensics in the Age of Big Data: Challenges, Approaches, and Opportunities,\u201d in 2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security, and 2015 IEEE 12th International Conference on Embedded Software and Systems, 2015, pp. 1320\u20131325.","DOI":"10.1109\/HPCC-CSS-ICESS.2015.305"},{"key":"8_CR24","doi-asserted-by":"crossref","unstructured":"B. Agrawal, R. Hansen, C. Rong, and T. Wiktorski, \u201cSD-HDFS: Secure deletion in hadoop distributed file system,\u201d in Proceedings - 2016 IEEE International Congress on Big Data, BigData Congress 2016, 2016, pp. 181\u2013189.","DOI":"10.1109\/BigDataCongress.2016.30"},{"key":"8_CR25","doi-asserted-by":"crossref","unstructured":"J. Baldwin, O. M. K. Alhawi, S. Shaughnessy, A. Akinbi, and A. Dehghantanha, \u201cEmerging from the Cloud: A Bibliometric Analysis of Cloud Forensics Studies,\u201d Springer, Cham, 2018, pp. 311\u2013331.","DOI":"10.1007\/978-3-319-73951-9_16"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"F. Daryabar, A. Dehghantanha, B. Eterovic-Soric, and K.-K. R. Choo, \u201cForensic investigation of OneDrive, Box, GoogleDrive and Dropbox applications on Android and iOS devices,\u201d Aust. J. Forensic Sci., pp. 1\u201328, Mar. 2016.","DOI":"10.1080\/00450618.2015.1110620"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"F. Norouzizadeh Dezfouli, A. Dehghantanha, B. Eterovic-Soric, and K.-K. R. Choo, \u201cInvestigating Social Networking applications on smartphones detecting Facebook, Twitter, LinkedIn and Google+ artefacts on Android and iOS platforms,\u201d Aust. J. Forensic Sci., pp. 1\u201320, Aug. 2015.","DOI":"10.1080\/00450618.2015.1066854"},{"key":"8_CR28","doi-asserted-by":"crossref","unstructured":"S. H. Mohtasebi, A. Dehghantanha, and K.-K. R. Choo, Cloud Storage Forensics: Analysis of Data Remnants on SpiderOak, JustCloud, and pCloud. 2016.","DOI":"10.1016\/B978-0-12-805303-4.00013-7"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"A. Dehghantanha and T. Dargahi, Residual Cloud Forensics: CloudMe and 360Yunpan as Case Studies. 2016.","DOI":"10.1016\/B978-0-12-805303-4.00014-9"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"M. N. Yusoff, A. Dehghantanha, and R. Mahmod, Network Traffic Forensics on Firefox Mobile OS: Facebook, Twitter, and Telegram as Case Studies. 2016.","DOI":"10.1016\/B978-0-12-805303-4.00005-8"},{"key":"8_CR31","doi-asserted-by":"crossref","unstructured":"H. Haughey, G. Epiphaniou, H. Al-Khateeb, and A. Dehghantanha, Adaptive traffic fingerprinting for darknet threat intelligence, vol. 70. 2018.","DOI":"10.1007\/978-3-319-73951-9_10"},{"key":"8_CR32","doi-asserted-by":"crossref","unstructured":"Y.-Y. Teing, D. Ali, K. Choo, M. T. Abdullah, and Z. Muda, \u201cGreening Cloud-Enabled Big Data Storage Forensics: Syncany as a Case Study,\u201d IEEE Trans. Sustain. Comput., pp. 1\u20131, 2017.","DOI":"10.1109\/TSUSC.2017.2687103"},{"key":"8_CR33","doi-asserted-by":"crossref","unstructured":"B. Martini and K. K. R. Choo, \u201cDistributed filesystem forensics: XtreemFS as a case study,\u201d Digit. Investig., vol. 11, no. 4, pp. 295\u2013313, 2014.","DOI":"10.1016\/j.diin.2014.08.002"},{"key":"8_CR34","unstructured":"S. A. Thanekar, K. Subrahmanyam, and A. B. Bagwan, \u201cA study on digital forensics in hadoop,\u201d Int. J. Control Theory Appl., vol. 9, no. 18, pp. 8927\u20138933, 2016."},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"P. Leimich, J. Harrison, and W. J. Buchanan, \u201cA RAM triage methodology for Hadoop HDFS forensics,\u201d Digit. Investig., vol. 18, pp. 96\u2013109, 2016.","DOI":"10.1016\/j.diin.2016.07.003"},{"key":"8_CR36","doi-asserted-by":"crossref","unstructured":"Y. Gao, X. Fu, B. Luo, X. Du, and M. Guizani, \u201cHaddle: A framework for investigating data leakage attacks in hadoop,\u201d in 2015 IEEE Global Communications Conference, GLOBECOM 2015, 2015.","DOI":"10.1109\/GLOCOM.2015.7417387"},{"key":"8_CR37","doi-asserted-by":"crossref","unstructured":"S. Dinesh, S. Rao, and K. Chandrasekaran, \u201cTraceback: A Forensic Tool for Distributed Systems,\u201d Proc. 3rd Int. Conf. Adv. Comput. Netw. Informatics, pp. 17\u201327, 2016.","DOI":"10.1007\/978-81-322-2529-4_2"},{"key":"8_CR38","doi-asserted-by":"crossref","unstructured":"E. Alshammari, G. Al-Naymat, and A. Hadi, \u201cA New Technique for File Carving on Hadoop Ecosystem,\u201d in The International Conference on new Trends in Computing Sciences (ICTCS\u20192017), At Jordan-Amman, 2017.","DOI":"10.1109\/ICTCS.2017.16"},{"key":"8_CR39","doi-asserted-by":"crossref","unstructured":"Y.-Y. Teing, A. Dehghantanha, K.-K. R. Choo, T. Dargahi, and M. Conti, \u201cForensic Investigation of Cooperative Storage Cloud Service: Symform as a Case Study,\u201d J. Forensic Sci., vol. 62, no. 3, pp. 641\u2013654, May 2017.","DOI":"10.1111\/1556-4029.13271"},{"key":"8_CR40","doi-asserted-by":"crossref","unstructured":"Y. Y. Teing, A. Dehghantanha, K. K. R. Choo, and L. T. Yang, \u201cForensic investigation of P2P cloud storage services and backbone for IoT networks: BitTorrent Sync as a case study,\u201d Comput. Electr. Eng., vol. 58, pp. 350\u2013363, 2017.","DOI":"10.1016\/j.compeleceng.2016.08.020"},{"key":"8_CR41","unstructured":"M. Kohn, J. H. P. Eloff, and M. S. Olivier, \u201cFramework for a Digital Forensic Investigation,\u201d Communications, no. March, pp. 1\u20137, 2006."},{"key":"8_CR42","doi-asserted-by":"crossref","unstructured":"M. E. Alex and R. Kishore, \u201cForensics framework for cloud computing,\u201d Comput. Electr. Eng., vol. 60, pp. 193\u2013205, 2017.","DOI":"10.1016\/j.compeleceng.2017.02.006"},{"key":"8_CR43","doi-asserted-by":"crossref","unstructured":"B. Martini and K. K. R. Choo, \u201cAn integrated conceptual digital forensic framework for cloud computing,\u201d Digit. Investig., vol. 9, no. 2, pp. 71\u201380, 2012.","DOI":"10.1016\/j.diin.2012.07.001"},{"key":"8_CR44","unstructured":"M. Rathbone, \u201cA Beginner\u2019s Guide to Hadoop Storage Formats (or File Formats).\u201d"},{"key":"8_CR45","unstructured":"P. Zeyliger, \u201cHadoop Default Ports Quick Reference \u2013 Cloudera Engineering Blog.\u201d"},{"key":"8_CR46","unstructured":"Apache Hadoop, \u201cApache Hadoop 2.9.0 \u2013 MapReduce Tutorial.\u201d"},{"key":"8_CR47","doi-asserted-by":"crossref","unstructured":"M. Conti, A. Dehghantanha, K. Franke, and S. Watson, \u201cInternet of Things security and forensics: Challenges and opportunities,\u201d Futur. Gener. Comput. Syst., vol. 78, pp. 544\u2013546, Jan. 2018.","DOI":"10.1016\/j.future.2017.07.060"},{"key":"8_CR48","unstructured":"S. Watson and A. Dehghantanha, \u201cDigital forensics: the missing piece of the Internet of Things promise,\u201d Comput. Fraud Secur., vol. 2016, no. 6, pp. 5\u20138, Jun. 2016."},{"key":"8_CR49","unstructured":"N. Milosevic, A. Dehghantanha, and K.-K. R. Choo, \u201cMachine learning aided Android malware classification,\u201d Comput. Electr. Eng."},{"key":"8_CR50","doi-asserted-by":"crossref","unstructured":"S. Homayoun, A. Dehghantanha, M. Ahmadzadeh, S. Hashemi, and R. Khayami, \u201cKnow Abnormal, Find Evil: Frequent Pattern Mining for Ransomware Threat Hunting and Intelligence,\u201d IEEE Trans. Emerg. Top. Comput., pp. 1\u20131, 2017.","DOI":"10.1109\/TETC.2017.2756908"},{"key":"8_CR51","doi-asserted-by":"crossref","unstructured":"H. H. Pajouh, A. Dehghantanha, R. Khayami, and K. K. R. Choo, \u201cIntelligent OS X malware threat detection with code inspection,\u201d Journal of Computer Virology and Hacking Techniques, pp. 1\u201311, 2017.","DOI":"10.1007\/s11416-017-0307-5"}],"container-title":["Handbook of Big Data and IoT Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-10543-3_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,14]],"date-time":"2022-09-14T06:33:53Z","timestamp":1663137233000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-10543-3_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030105426","9783030105433"],"references-count":51,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-10543-3_8","relation":{},"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"23 March 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}