{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T01:57:29Z","timestamp":1743127049983,"version":"3.40.3"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031160745"},{"type":"electronic","value":"9783031160752"}],"license":[{"start":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T00:00:00Z","timestamp":1661990400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,9,1]],"date-time":"2022-09-01T00:00:00Z","timestamp":1661990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-16075-2_43","type":"book-chapter","created":{"date-parts":[[2022,8,31]],"date-time":"2022-08-31T10:02:42Z","timestamp":1661940162000},"page":"590-599","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Ambient Intelligence Security Checks: Identifying Integrity Vulnerabilities in Industry Scripts"],"prefix":"10.1007","author":[{"given":"Suzanna","family":"Schmeelk","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shannon","family":"Roth","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Julia","family":"Rooney","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mughees","family":"Tariq","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Khalil","family":"Wood","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John","family":"Kamen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Denise","family":"Dragos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,1]]},"reference":[{"key":"43_CR1","unstructured":"S&P Global Market Intelligence: 451 research digital pulse: coronavirus flash survey, October 2020. https:\/\/go.451research.com\/MC-2020-10-CoronavirusFlashSurveyOct2020_LandingPage.html"},{"key":"43_CR2","unstructured":"Amazon Web Services: Installing the AWS tools for PowerShell on windows (2022). https:\/\/docs.aws.amazon.com\/PowerShell\/latest\/userguide\/pstools-getting-set-up-windows.html"},{"key":"43_CR3","unstructured":"FutureTense: Windows PowerShell scripting to control your home assistant (and other) virtual machines! (2020). https:\/\/community.home-assistant.io\/t\/windows-PowerShell-scripting-to-control-your-home-assistant-and-other-virtual-machines\/198998"},{"key":"43_CR4","unstructured":"NIST: NIST policy on hash functions (2015). https:\/\/csrc.nist.gov\/Projects\/Hash-Functions\/NIST-Policy-on-Hash-Functions"},{"key":"43_CR5","unstructured":"Microsoft: Get-FileHash reference (2021). https:\/\/docs.microsoft.com\/en-us\/PowerShell\/module\/microsoft.PowerShell.utility\/get-filehash?view=PowerShell-7.1"},{"key":"43_CR6","unstructured":"Zeifman, I.: Deprecating SHA-1 \u2014 why, what and when (2014). https:\/\/www.imperva.com\/blog\/sha-1-hash-algorithm-deprecation\/"},{"key":"43_CR7","unstructured":"Velvindron, L., Moriarty, K.: Deprecating MD5 and SHA1 in TLS 1.2 (2019). https:\/\/tools.ietf.org\/id\/draft-lvelvindron-tls-md5-sha1-deprecate-01.html"},{"key":"43_CR8","unstructured":"Constantin, L.: The SHA1 hash function is now completely unsafe (2017). https:\/\/www.computerworld.com\/article\/3173616\/the-sha1-hash-function-is-now-completely-unsafe.html"},{"key":"43_CR9","unstructured":"Privacy Canada: Hash collision attack (n.d.). https:\/\/privacycanada.net\/hash-functions\/hash-collision-attack"},{"key":"43_CR10","unstructured":"Science Direct: Static analysis in engineering (n.d.). https:\/\/www.sciencedirect.com\/topics\/engineering\/static-analysis"},{"key":"43_CR11","doi-asserted-by":"crossref","unstructured":"Hosmer, C.: PowerShell and Python Together. Apress, Longs (2019)","DOI":"10.1007\/978-1-4842-4504-0"},{"key":"43_CR12","unstructured":"Bencherchali, N.: Malware analysis techniques \u2014 basic static analysis (2019). https:\/\/nasbench.medium.com\/malware-analysis-techniques-basic-static-analysis-335a7286a176"},{"key":"43_CR13","unstructured":"Sheth, M.: Message digests, aka hashing functions (2017). https:\/\/www.veracode.com\/blog\/research\/message-digests-aka-hashing-functions"},{"key":"43_CR14","unstructured":"TechTarget (n.d.). https:\/\/www.techtarget.com\/search\/query?q=Static-source-code-analysis-tools-Pros-and-cons"},{"key":"43_CR15","unstructured":"Elkhalifa, I., Ilyas, B.: Static code analysis: a systematic literature review and an industrial survey. M.S. thesis. Computing at Blekinge Institute of Technology, Karlskrona, Sweden. https:\/\/www.diva-portal.org\/smash\/get\/diva2:947354\/FULLTEXT03"},{"key":"43_CR16","unstructured":"Science Direct: Static analysis in computer science (n.d.). https:\/\/www.sciencedirect.com\/topics\/computer-science\/static-analysis"},{"key":"43_CR17","unstructured":"JScrambler: Hashing Algorithms (2020). https:\/\/blog.jscrambler.com\/hashing-algorithms"},{"key":"43_CR18","unstructured":"Fugate, D.: Productivity Through PowerShell. (Conference) | OSTI.GOV (2013). www.osti.gov\/servlets\/purl\/1115672"},{"key":"43_CR19","unstructured":"Kazanciyan, R., Hastings, M.: Investigating PowerShell attacks (2014). https:\/\/www.blackhat.com\/docs\/us-14\/materials\/us-14-Kazanciyan-Investigating-PowerShell-Attacks-WP.pdf"},{"key":"43_CR20","unstructured":"Poston, H.: Secure coding: cryptography-based vulnerabilities in applications (2020). https:\/\/resources.infosecinstitute.com\/topic\/cryptography-based-vulnerabilities-in-applications\/"},{"key":"43_CR21","doi-asserted-by":"publisher","unstructured":"Hendler, D., Kels, S., Rubin, A.: AMSI-based detection of malicious PowerShell code using contextual embeddings. In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security (ASIA CCS 2020), pp. 679\u2013693. Association for Computing Machinery, New York (2020). https:\/\/doi.org\/10.1145\/3320269.3384742","DOI":"10.1145\/3320269.3384742"},{"key":"43_CR22","volume-title":"Windows PowerShell: TFM","author":"D Jones","year":"2006","unstructured":"Jones, D., Hicks, J.: Windows PowerShell: TFM. SAPIEN Press, Napa (2006)"},{"key":"43_CR23","unstructured":"Positive Technologies: How to approach secure software development (2020). https:\/\/www.ptsecurity.com\/ww-en\/analytics\/knowledge-base\/how-to-approach-secure-software-development"},{"key":"43_CR24","unstructured":"Martin, L.: A software engineer\u2019s guide to encryption: how not to fail (n.d.). https:\/\/techbeacon.com\/security\/software-engineers-guide-encryption-how-not-fail"},{"key":"43_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/978-3-030-22038-9_12","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"D Ugarte","year":"2019","unstructured":"Ugarte, D., Maiorca, D., Cara, F., Giacinto, G.: PowerDrive: accurate de-obfuscation and analysis of PowerShell malware. In: Perdisci, R., Maurice, C., Giacinto, G., Almgren, M. (eds.) DIMVA 2019. LNCS, vol. 11543, pp. 240\u2013259. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-22038-9_12"},{"key":"43_CR26","unstructured":"Mitschke, K., Schill, M., Tanasovski, T., Thomas Lee, T.: Windows PowerShell 2.0 Bible. Wiley, Indianapolis (2011)"},{"key":"43_CR27","unstructured":"OWASP: Testing for weak encryption (n.d.). https:\/\/owasp.org\/www-project-web-security-testing-guide\/latest\/4-Web_Application_Security_Testing\/09-Testing_for_Weak_Cryptography\/04-Testing_for_Weak_Encryption"},{"key":"43_CR28","unstructured":"Snover, J., MSFT PowerShell Team: RFC: deprecating parameters. Microsoft (2007). https:\/\/devblogs.microsoft.com\/PowerShell\/rfc-deprecating-parameters"},{"key":"43_CR29","unstructured":"MITRE: CWE-326: Inadequate encryption strength (2021). https:\/\/cwe.mitre.org\/data\/definitions\/326.html"},{"key":"43_CR30","unstructured":"MITRE: CWE-327: Use of a broken or risky cryptographic algorithm (2021). https:\/\/cwe.mitre.org\/data\/definitions\/327.html"},{"key":"43_CR31","unstructured":"NIST: FIPS 140-3 development (2019). https:\/\/csrc.nist.gov\/projects\/fips-140-3-development"},{"key":"43_CR32","unstructured":"Microsoft: PSScriptAnalyzer reference (n.d.). https:\/\/docs.microsoft.com\/en-us\/PowerShell\/module\/psscriptanalyzer\/?view=ps-modules"},{"key":"43_CR33","unstructured":"ScriptCop: Github repository (n.d.). https:\/\/github.com\/StartAutomating\/ScriptCop"},{"key":"43_CR34","doi-asserted-by":"publisher","unstructured":"Schmeelk, S., Tao, L.: A case study of mobile health applications: the OWASP risk of insufficient cryptography. J. Comput. Sci. Res. 4(1) (2022). https:\/\/doi.org\/10.30564\/jcsr.v4i1.4271","DOI":"10.30564\/jcsr.v4i1.4271"}],"container-title":["Lecture Notes in Networks and Systems","Intelligent Systems and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-16075-2_43","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,31]],"date-time":"2022-08-31T10:03:57Z","timestamp":1661940237000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-16075-2_43"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,1]]},"ISBN":["9783031160745","9783031160752"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-16075-2_43","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"type":"print","value":"2367-3370"},{"type":"electronic","value":"2367-3389"}],"subject":[],"published":{"date-parts":[[2022,9,1]]},"assertion":[{"value":"1 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IntelliSys","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Proceedings of SAI Intelligent Systems Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Amsterdam","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"intellisys2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/saiconference.com\/IntelliSys","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}