{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T02:27:00Z","timestamp":1742956020674,"version":"3.40.3"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030496685"},{"type":"electronic","value":"9783030496692"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-49669-2_13","type":"book-chapter","created":{"date-parts":[[2020,6,17]],"date-time":"2020-06-17T23:09:17Z","timestamp":1592435357000},"page":"223-240","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Designing a Decision-Support Visualization for Live Digital Forensic Investigations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0023-6051","authenticated-orcid":false,"given":"Fabian","family":"B\u00f6hm","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8546-3017","authenticated-orcid":false,"given":"Ludwig","family":"Englbrecht","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"G\u00fcnther","family":"Pernul","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,6,18]]},"reference":[{"issue":"2","key":"13_CR1","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1145\/1113034.1113070","volume":"49","author":"F Adelstein","year":"2006","unstructured":"Adelstein, F.: Live forensics: diagnosing your system without killing it first. Commun. ACM 49(2), 63\u201366 (2006)","journal-title":"Commun. ACM"},{"key":"13_CR2","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-030-28752-8_2","volume-title":"Advances in Digital Forensics XV","author":"A Antwi-Boasiako","year":"2019","unstructured":"Antwi-Boasiako, A., Venter, H.: Implementing the harmonized model for digital evidence admissibility assessment. DigitalForensics 2019. IAICT, vol. 569, pp. 19\u201336. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-28752-8_2"},{"doi-asserted-by":"crossref","unstructured":"Arendt, D., Best, D., Burtner, R., Lyn Paul, C.: Cyberpetri at CDX 2016: real-time network situation awareness. In: 2016 IEEE Symposium on Visualization for Cyber Security (VizSec), pp. 1\u20134. IEEE (2016)","key":"13_CR3","DOI":"10.1109\/VIZSEC.2016.7739584"},{"doi-asserted-by":"crossref","unstructured":"Boschetti, A., Salgarelli, L., Muelder, C., Ma, K.L.: Tvi: a visual querying system for network monitoring and anomaly detection. In: Proceedings of the 8th International Symposium on Visualization for Cyber Security - VizSec 2011, pp. 1\u201310. ACM Press, New York (2011)","key":"13_CR4","DOI":"10.1145\/2016904.2016905"},{"issue":"12","key":"13_CR5","doi-asserted-by":"publisher","first-page":"2376","DOI":"10.1109\/TVCG.2013.124","volume":"19","author":"M Brehmer","year":"2013","unstructured":"Brehmer, M., Munzner, T.: A multi-level typology of abstract visualization tasks. IEEE Trans. Vis. Comput. Graph. 19(12), 2376\u20132385 (2013)","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"doi-asserted-by":"crossref","unstructured":"Cappers, B.C., Meessen, P.N., Etalle, S., van Wijk, J.J.: Eventpad: rapid malware analysis and reverse engineering using visual analytics. In: 2018 IEEE Symposium on Visualization for Cyber Security (VizSec), pp. 1\u20138. IEEE (2018)","key":"13_CR6","DOI":"10.1109\/VIZSEC.2018.8709230"},{"doi-asserted-by":"crossref","unstructured":"Catanese, S.A., Fiumara, G.: A visual tool for forensic analysis of mobile phone traffic. In: Proceedings of the 2nd ACM Workshop on Multimedia in Forensics, Security and Intelligence - MiFor 2010, p. 71. ACM Press, New York (2010)","key":"13_CR7","DOI":"10.1145\/1877972.1877992"},{"doi-asserted-by":"crossref","unstructured":"Englbrecht, L., Langner, G., Pernul, G., Quirchmayr, G.: Enhancing credibility of digital evidence through provenance-based incident response handling. In: Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES 2019, pp. 26:1\u201326:6. ACM (2019)","key":"13_CR8","DOI":"10.1145\/3339252.3339275"},{"key":"13_CR9","doi-asserted-by":"publisher","first-page":"S47","DOI":"10.1016\/j.diin.2018.04.021","volume":"26","author":"C Grajeda","year":"2018","unstructured":"Grajeda, C., Sanchez, L., Baggili, I., Clark, D., Breitinger, F.: Experience constructing the artifact genome project (AGP): managing the domain\u2019s knowledge one artifact at a time. Digit. Invest. 26, S47\u2013S58 (2018)","journal-title":"Digit. Invest."},{"key":"13_CR10","doi-asserted-by":"publisher","first-page":"S125","DOI":"10.1016\/j.diin.2016.04.005","volume":"18","author":"VS Harichandran","year":"2016","unstructured":"Harichandran, V.S., Walnycky, D., Baggili, I., Breitinger, F.: Cufa: a more formal definition for digital forensic artifacts. Digit. Invest. 18, S125\u2013S137 (2016)","journal-title":"Digit. Invest."},{"key":"13_CR11","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-3-642-24212-0_6","volume-title":"Advances in Digital Forensics VII","author":"B Hoelz","year":"2011","unstructured":"Hoelz, B., Ralha, C., Mesquita, F.: Case-based reasoning in live forensics. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2011. IAICT, vol. 361, pp. 77\u201388. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-24212-0_6"},{"key":"13_CR12","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.diin.2009.06.014","volume":"6","author":"D Kahvedzic","year":"2009","unstructured":"Kahvedzic, D., Kechadi, M.T.: Dialog: a framework for modeling, analysis and reuse of digital forensic knowledge. Digit. Invest. 6, 23\u201333 (2009)","journal-title":"Digit. Invest."},{"issue":"14","key":"13_CR13","first-page":"800","volume":"10","author":"K Kent","year":"2006","unstructured":"Kent, K., Chevalier, S., Grance, T., Dang, H.: Guide to integrating forensic techniques into incident response. NIST Spec. Publ. 10(14), 800\u2013886 (2006)","journal-title":"NIST Spec. Publ."},{"doi-asserted-by":"crossref","unstructured":"Leschke, T.R., Nicholas, C.: Change-link 2.0: a digital forensic tool for visualizing changes to shadow volume data. In: Proceedings of the Tenth Workshop on Visualization for Cyber Security - VizSec 2013, pp. 17\u201324. ACM Press, New York (2013)","key":"13_CR14","DOI":"10.1145\/2517957.2517960"},{"doi-asserted-by":"crossref","unstructured":"Leschke, T.R., Sherman, A.T.: Change-link: a digital forensic tool for visualizing changes to directory trees. In: Proceedings of the Ninth International Symposium on Visualization for Cyber Security - VizSec 2012, pp. 48\u201355. ACM Press, New York (2012)","key":"13_CR15","DOI":"10.1145\/2379690.2379697"},{"issue":"4","key":"13_CR16","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1016\/S1353-4858(17)30037-5","volume":"2017","author":"S Mansfield-Devine","year":"2017","unstructured":"Mansfield-Devine, S.: Fileless attacks: compromising targets without malware. Netw. Secur. 2017(4), 7\u201311 (2017)","journal-title":"Netw. Secur."},{"key":"13_CR17","series-title":"Safari Tech Books Online","volume-title":"Applied Security Visualization","author":"R Marty","year":"2009","unstructured":"Marty, R.: Applied Security Visualization. Safari Tech Books Online. Addison-Wesley, Boston (2009)"},{"doi-asserted-by":"crossref","unstructured":"McCurdy, N., Dykes, J., Meyer, M.: Action design research and visualization design. In: Proceedings of the Beyond Time and Errors on Novel Evaluation Methods for Visualization - BELIV 2016, pp. 10\u201318. ACM Press, New York (2016)","key":"13_CR18","DOI":"10.1145\/2993901.2993916"},{"issue":"3","key":"13_CR19","doi-asserted-by":"publisher","first-page":"234","DOI":"10.1177\/1473871613510429","volume":"14","author":"M Meyer","year":"2015","unstructured":"Meyer, M., Sedlmair, M., Quinan, P.S., Munzner, T.: The nested blocks and guidelines model. Inf. Vis. 14(3), 234\u2013249 (2015)","journal-title":"Inf. Vis."},{"issue":"3","key":"13_CR20","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1007\/s41870-018-0263-4","volume":"11","author":"NR Mistry","year":"2018","unstructured":"Mistry, N.R., Dahiya, M.S.: Signature based volatile memory forensics: a detection based approach for analyzing sophisticated cyber attacks. Int. J. Inf. Technol. 11(3), 583\u2013589 (2018). https:\/\/doi.org\/10.1007\/s41870-018-0263-4","journal-title":"Int. J. Inf. Technol."},{"issue":"6","key":"13_CR21","doi-asserted-by":"publisher","first-page":"921","DOI":"10.1109\/TVCG.2009.111","volume":"15","author":"T Munzner","year":"2009","unstructured":"Munzner, T.: A nested model for visualization design and validation. IEEE Trans. Vis. Comput. Graph. 15(6), 921\u2013928 (2009)","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"doi-asserted-by":"crossref","unstructured":"Nguyen, V.T., Namin, A.S., Dang, T.: Malviz: an interactive visualization tool for tracing malware. In: Proceedings of the 27th ACM SIGSOFT International Symposium on Software Testing and Analysis - ISSTA 2018, pp. 376\u2013379. ACM Press, New York (2018)","key":"13_CR22","DOI":"10.1145\/3213846.3229501"},{"key":"13_CR23","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1016\/j.diin.2009.06.008","volume":"6","author":"J Olsson","year":"2009","unstructured":"Olsson, J., Boldt, M.: Computer forensic timeline visualization tool. Digit. Invest. 6, 78\u201387 (2009)","journal-title":"Digit. Invest."},{"unstructured":"O\u2019Murchu, L., Gutierrez, F.P.: The evolution of the fileless click-fraud malware poweliks (2015). https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/security-center\/white-papers\/evolution-of-fileless-click-fraud-15-en.pdf. Accessed 24 Feb 2020","key":"13_CR24"},{"key":"13_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1007\/978-3-030-22479-0_12","volume-title":"Data and Applications Security and Privacy XXXIII","author":"A Puchta","year":"2019","unstructured":"Puchta, A., B\u00f6hm, F., Pernul, G.: Contributing to current challenges in identity and access management with visual analytics. In: Foley, S.N. (ed.) DBSec 2019. LNCS, vol. 11559, pp. 221\u2013239. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-22479-0_12"},{"doi-asserted-by":"crossref","unstructured":"Quist, D.A., Liebrock, L.M.: Visualizing compiled executables for malware analysis. In: 2009 6th International Workshop on Visualization for Cyber Security, pp. 27\u201332. IEEE (2009)","key":"13_CR26","DOI":"10.1109\/VIZSEC.2009.5375539"},{"issue":"3","key":"13_CR27","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1109\/MCG.2009.48","volume":"29","author":"H Read","year":"2009","unstructured":"Read, H., Xynos, K., Blyth, A.: Presenting devise: data exchange for visualizing security events. IEEE Comput. Graph. Appl. 29(3), 6\u201311 (2009)","journal-title":"IEEE Comput. Graph. Appl."},{"issue":"4","key":"13_CR28","doi-asserted-by":"publisher","first-page":"288","DOI":"10.1177\/1473871615621602","volume":"15","author":"A Rind","year":"2016","unstructured":"Rind, A., Aigner, W., Wagner, M., Miksch, S., Lammarsch, T.: Task cube: a three-dimensional conceptual space of user tasks in visualization design and evaluation. Inf. Vis. 15(4), 288\u2013300 (2016)","journal-title":"Inf. Vis."},{"issue":"12","key":"13_CR29","doi-asserted-by":"publisher","first-page":"1604","DOI":"10.1109\/TVCG.2014.2346481","volume":"20","author":"D Sacha","year":"2014","unstructured":"Sacha, D., Stoffel, A., Stoffel, F., Kwon, B.C., Ellis, G., Keim, D.A.: Knowledge generation model for visual analytics. IEEE Trans. Vis. Comput. Graph. 20(12), 1604\u20131613 (2014)","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"unstructured":"Simon, S., Mittelst\u00e4dt, S., Keim, D.A., Sedlmair, M.: Bridging the gap of domain and visualization experts with a liaison. In: Eurographics Conference on Visualization (EuroVis) - Short Papers. The Eurographics Association (2015)","key":"13_CR30"},{"doi-asserted-by":"crossref","unstructured":"Sudhakar, Kumar, S.: An emerging threat fileless malware: a survey and research challenges. Cybersecurity, 3(1), 1\u201312 (2020)","key":"13_CR31","DOI":"10.1186\/s42400-019-0043-x"},{"issue":"6","key":"13_CR32","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1109\/MCG.2006.120","volume":"26","author":"JJ van Wijk","year":"2006","unstructured":"van Wijk, J.J.: Bridging the gaps. IEEE Comput. Graph. Appl. 26(6), 6\u20139 (2006)","journal-title":"IEEE Comput. Graph. Appl."},{"unstructured":"Wueest, C., Anand, H.: Internet security threat report: living off the land and fileless attack techniques (2017). https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/security-center\/white-papers\/istr-living-off-the-land-and-fileless-attack-techniques-en.pdf. Accessed 24 Feb 2020","key":"13_CR33"}],"container-title":["Lecture Notes in Computer Science","Data and Applications Security and Privacy XXXIV"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-49669-2_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,17]],"date-time":"2024-06-17T23:04:08Z","timestamp":1718665448000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-49669-2_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030496685","9783030496692"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-49669-2_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"18 June 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DBSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP Annual Conference on Data and Applications Security and Privacy","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Regensburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 June 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"34","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dbsec2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dbsec2020.ur.de\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"14","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"36% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held virutally due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}