{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:45:28Z","timestamp":1759092328365,"version":"3.40.3"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030687335"},{"type":"electronic","value":"9783030687342"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-68734-2_6","type":"book-chapter","created":{"date-parts":[[2021,2,9]],"date-time":"2021-02-09T01:14:09Z","timestamp":1612833249000},"page":"98-120","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Efficient Fingerprint Matching for Forensic Event Reconstruction"],"prefix":"10.1007","author":[{"given":"Tobias","family":"Latzo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,2,7]]},"reference":[{"key":"6_CR1","unstructured":"The xymon monitor. https:\/\/xymon.sourceforge.io\/"},{"key":"6_CR2","unstructured":"Linux programmer\u2019s manual (2018). http:\/\/man7.org\/linux\/man-pages\/dir_section_2.html"},{"key":"6_CR3","unstructured":"18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/13th IEEE International Conference On Big Data Science And Engineering, TrustCom\/BigDataSE 2019, Rotorua, New Zealand, 5\u20138 August 2019. IEEE (2019). https:\/\/ieeexplore.ieee.org\/xpl\/conhome\/8883860\/proceeding"},{"key":"6_CR4","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1016\/j.diin.2015.07.005","volume":"15","author":"Y Chabot","year":"2015","unstructured":"Chabot, Y., Bertaux, A., Nicolle, C., Kechadi, T.: An ontology-based approach for the reconstruction and analysis of digital incidents timelines. Digit. Invest. 15, 83\u2013100 (2015)","journal-title":"Digit. Invest."},{"issue":"6","key":"6_CR5","first-page":"339","volume":"57","author":"A Dewald","year":"2015","unstructured":"Dewald, A.: Characteristic evidence, counter evidence and reconstruction problems in forensic computing. IT - Inf. Technol. 57(6), 339\u2013346 (2015). http:\/\/www.degruyter.com\/view\/j\/itit.2015.57.issue-6\/itit-2015-0017\/itit-2015-0017.xml","journal-title":"IT - Inf. Technol."},{"key":"6_CR6","unstructured":"Elasticsearch B.V.: Filebeat - lightweight shipper for logs (2020). https:\/\/www.elastic.co\/products\/beats\/filebeat"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Gerhards, R.: The syslog protocol. Technical report (2009)","DOI":"10.17487\/rfc5424"},{"key":"6_CR8","unstructured":"Gladyshev, P., Enbacka, A.: Rigorous development of automated inconsistency checks for digital evidence using the B method. IJDE 6(2) (2007). http:\/\/www.utica.edu\/academic\/institutes\/ecii\/publications\/articles\/1C35450B-E896-6876-9E80DA0F9FEEF98B.pdf"},{"issue":"2","key":"6_CR9","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1016\/j.diin.2004.03.001","volume":"1","author":"P Gladyshev","year":"2004","unstructured":"Gladyshev, P., Patel, A.: Finite state machine approach to digital eventreconstruction. Digit. Invest. 1(2), 130\u2013149 (2004). https:\/\/doi.org\/10.1016\/j.diin.2004.03.001","journal-title":"Digit. Invest."},{"issue":"3","key":"6_CR10","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/s10207-014-0249-6","volume":"14","author":"JI James","year":"2015","unstructured":"James, J.I., Gladyshev, P.: Automated inference of past action instances indigital investigations. Int. J. Inf. Sec. 14(3), 249\u2013261 (2015). https:\/\/doi.org\/10.1007\/s10207-014-0249-6","journal-title":"Int. J. Inf. Sec."},{"issue":"3\u20134","key":"6_CR11","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1016\/j.diin.2007.11.001","volume":"4","author":"MNA Khan","year":"2007","unstructured":"Khan, M.N.A., Chatwin, C.R., Young, R.C.D.: A framework for post-event timelinereconstruction using neural networks. Digit. Invest. 4(3\u20134), 146\u2013157 (2007). https:\/\/doi.org\/10.1016\/j.diin.2007.11.001","journal-title":"Digit. Invest."},{"key":"6_CR12","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-319-50127-7_11","volume-title":"AI 2016: Advances in Artificial Intelligence","author":"B Kolosnjaji","year":"2016","unstructured":"Kolosnjaji, B., Zarras, A., Webster, G., Eckert, C.: Deep learning for classification of malware system call sequences. In: Kang, B.H., Bai, Q. (eds.) AI 2016. LNCS (LNAI), vol. 9992, pp. 137\u2013149. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-50127-7_11"},{"key":"6_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1007\/978-3-540-39650-5_19","volume-title":"Computer Security \u2013 ESORICS 2003","author":"C Kruegel","year":"2003","unstructured":"Kruegel, C., Mutz, D., Valeur, F., Vigna, G.: On the detection of anomalous system call arguments. In: Snekkenes, E., Gollmann, D. (eds.) ESORICS 2003. LNCS, vol. 2808, pp. 326\u2013343. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-39650-5_19"},{"key":"6_CR14","doi-asserted-by":"publisher","unstructured":"Latzo, T., Freiling, F.C.: Characterizing the limitations of forensic event reconstruction based on log files. In: 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/13th IEEE International Conference on Big Data Science and Engineering, TrustCom\/BigDataSE 2019, Rotorua, New Zealand, 5\u20138 August 2019 [3], pp. 466\u2013475 (2019). https:\/\/doi.org\/10.1109\/TrustCom\/BigDataSE.2019.00069","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00069"},{"key":"6_CR15","unstructured":"Li, Z., et al.: UCLog: a unified, correlated logging architecture for intrusion detection. In: the 12th International Conference on Telecommunication Systems-Modeling and Analysis (ICTSM) (2004)"},{"key":"6_CR16","doi-asserted-by":"publisher","unstructured":"Marrington, A., Mohay, G.M., Morarji, H., Clark, A.J.: A model for computer profiling. In: ARES 2010, Fifth International Conference on Availability, Reliability and Security, 15\u201318 February 2010, Krakow, Poland, pp. 635\u2013640 (2010). https:\/\/doi.org\/10.1109\/ARES.2010.95","DOI":"10.1109\/ARES.2010.95"},{"key":"6_CR17","doi-asserted-by":"publisher","unstructured":"Menges, F., et al.: Introducing DINGfest: an architecture for next generation SIEM systems. In: Langweg, H., Meier, M., Witt, B.C., Reinhardt, D. (eds.) Sicherheit 2018, Beitr\u00e4ge der 9. Jahrestagung des Fachbereichs Sicherheit der Gesellschaft f\u00fcr Informatik e.V. (GI), 25\u201327 April 2018, Konstanz. LNI, vol. P-281, pp. 257\u2013260. Gesellschaft f\u00fcr Informatik e.V. (2018). https:\/\/doi.org\/10.18420\/sicherheit2018_21","DOI":"10.18420\/sicherheit2018_21"},{"key":"6_CR18","unstructured":"Microsoft Corporation: Event logging (2019). https:\/\/docs.microsoft.com\/en-us\/windows\/desktop\/msi\/event-logging"},{"key":"6_CR19","unstructured":"Ravi, S., Balakrishnan, N., Venkatesh, B.: Behavior-based malware analysis using profile hidden Markov models. In: 2013 International Conference on Security and Cryptography (SECRYPT), pp. 1\u201312. IEEE (2013)"},{"issue":"4","key":"6_CR20","doi-asserted-by":"publisher","first-page":"639","DOI":"10.3233\/JCS-2010-0410","volume":"19","author":"K Rieck","year":"2011","unstructured":"Rieck, K., Trinius, P., Willems, C., Holz, T.: Automatic analysis of malwarebehavior using machine learning. J. Comput. Secur. 19(4), 639\u2013668 (2011). https:\/\/doi.org\/10.3233\/JCS-2010-0410","journal-title":"J. Comput. Secur."},{"key":"6_CR21","doi-asserted-by":"publisher","unstructured":"Taubmann, B., Kolosnjaji, B.: Architecture for resource-aware VMI-based cloud malware analysis. In: Proceedings of the 4th Workshop on Security in Highly Connected IT Systems, SHCIS@DAIS 2017, Neuch\u00e2tel, Switzerland, 21\u201322 June 2017, pp. 43\u201348 (2017). https:\/\/doi.org\/10.1145\/3099012.3099015","DOI":"10.1145\/3099012.3099015"},{"key":"6_CR22","unstructured":"The Apache Software Foundation: Apache kafka - a distributed streaming platform (2020). https:\/\/kafka.apache.org\/"},{"issue":"2","key":"6_CR23","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.C.: Toward automated dynamic malware analysis using CWSandbox. IEEE Secur. Priv. 5(2), 32\u201339 (2007). https:\/\/doi.org\/10.1109\/MSP.2007.45","journal-title":"IEEE Secur. Priv."},{"key":"6_CR24","unstructured":"Yadwadkar, N.J., Bhattacharyya, C., Gopinath, K., Niranjan, T., Susarla, S.: Discovery of application workloads from network file traces. In: FAST, pp. 183\u2013196 (2010)"},{"key":"6_CR25","unstructured":"Yurcik, W., Abad, C., Hasan, R., Saleem, M., Sridharan, S.: UCLog+: a security data management system for correlating alerts, incidents, and raw data from remote logs. arXiv preprint cs\/0607111 (2006)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-68734-2_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,24]],"date-time":"2021-04-24T14:04:00Z","timestamp":1619273040000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-68734-2_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030687335","9783030687342"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-68734-2_6","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"7 February 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICDF2C","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Digital Forensics and Cyber Crime","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Boston, MA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 October 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 October 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icdf2c2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/d-forensics.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confyplus","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"11","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"31% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4.7","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Due to COVID 19 pandemic teh conference was held virtually.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}