{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:10:59Z","timestamp":1772039459486,"version":"3.50.1"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319112022","type":"print"},{"value":"9783319112039","type":"electronic"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-11203-9_12","type":"book-chapter","created":{"date-parts":[[2014,8,14]],"date-time":"2014-08-14T20:36:46Z","timestamp":1408048606000},"page":"202-218","source":"Crossref","is-referenced-by-count":23,"title":["TrustDump: Reliable Memory Acquisition on Smartphones"],"prefix":"10.1007","author":[{"given":"He","family":"Sun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kun","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sushil","family":"Jajodia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"12_CR1","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: NDSS (2003)"},{"key":"12_CR2","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through vmm-based \u201cout-of-the-box\u201d semantic view reconstruction. In: ACM Conference on Computer and Communications Security, pp. 128\u2013138 (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"12_CR3","doi-asserted-by":"crossref","unstructured":"Fu, Y., Lin, Z.: Space traveling across vm: Automatically bridging the semantic gap in virtual machine introspection via online kernel data redirection. In: IEEE Symposium on Security and Privacy, pp. 586\u2013600 (2012)","DOI":"10.1109\/SP.2012.40"},{"key":"12_CR4","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J.T., Lee, W.: Virtuoso: Narrowing the semantic gap in virtual machine introspection. In: IEEE Symposium on Security and Privacy, pp. 297\u2013312 (2011)","DOI":"10.1109\/SP.2011.11"},{"key":"12_CR5","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M.I., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: ACM Conference on Computer and Communications Security, pp. 51\u201362 (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"12_CR6","doi-asserted-by":"crossref","unstructured":"Deng, Z., Zhang, X., Xu, D.: Spider: stealthy binary program instrumentation and debugging via hardware virtualization. In: ACSAC, pp. 289\u2013298 (2013)","DOI":"10.1145\/2523649.2523675"},{"key":"12_CR7","unstructured":"Yan, L.K., Yin, H.: Droidscope: Seamlessly reconstructing the os and dalvik semantic views for dynamic android malware analysis. In: Proceedings of the 21st USENIX Conference on Security Symposium, Security 2012, p. 29. USENIX Association (2012)"},{"key":"12_CR8","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Parno, B., Perrig, A., Reiter, M.K., Isozaki, H.: Flicker: an execution infrastructure for tcb minimization. In: EuroSys, pp. 315\u2013328 (2008)","DOI":"10.1145\/1357010.1352625"},{"key":"12_CR9","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Li, Y., Qu, N., Zhou, Z., Datta, A., Gligor, V.D., Perrig, A.: Trustvisor: Efficient tcb reduction and attestation. In: IEEE Symposium on Security and Privacy, pp. 143\u2013158 (2010)","DOI":"10.1109\/SP.2010.17"},{"key":"12_CR10","unstructured":"Martignoni, L., Poosankam, P., Zaharia, M., Han, J., McCamant, S., Song, D., Paxson, V., Perrig, A., Shenker, S., Stoica, I.: Cloud terminal: secure access to sensitive applications from untrusted systems. In: Proceedings of the 2012 USENIX Conference on Annual Technical Conference, p. 14. USENIX Association (2012)"},{"key":"12_CR11","doi-asserted-by":"crossref","unstructured":"Zhang, F., Leach, K., Sun, K., Stavrou, A.: Spectre: A dependable introspection framework via system management mode. In: DSN, pp. 1\u201312 (2013)","DOI":"10.1109\/DSN.2013.6575343"},{"key":"12_CR12","doi-asserted-by":"crossref","unstructured":"Azab, A.M., Ning, P., Wang, Z., Jiang, X., Zhang, X., Skalsky, N.C.: Hypersentry: enabling stealthy in-context measurement of hypervisor integrity. In: ACM Conference on Computer and Communications Security, pp. 38\u201349 (2010)","DOI":"10.1145\/1866307.1866313"},{"key":"12_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1007\/978-3-642-15512-3_9","volume-title":"Recent Advances in Intrusion Detection","author":"J. Wang","year":"2010","unstructured":"Wang, J., Stavrou, A., Ghosh, A.: Hypercheck: A hardware-assisted integrity monitor. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol.\u00a06307, pp. 158\u2013177. Springer, Heidelberg (2010)"},{"key":"12_CR14","doi-asserted-by":"crossref","unstructured":"Azab, A.M., Ning, P., Zhang, X.: Sice: a hardware-level strongly isolated computing environment for x86 multi-core platforms. In: ACM Conference on Computer and Communications Security, pp. 375\u2013388 (2011)","DOI":"10.1145\/2046707.2046752"},{"key":"12_CR15","unstructured":"ARM: TrustZone Introduction, http:\/\/www.arm.com\/products\/processors\/technologies\/trustzone\/index.php"},{"key":"12_CR16","unstructured":"Alves, T., Felton, D.: Trustzone: Integrated hardware and software security. ARM White Paper 3(4) (2004)"},{"key":"12_CR17","unstructured":"ARM: Cortex-A8 Technical Reference Manual, http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.ddi0344k\/DDI0344K_cortex_a8_r3p2_trm.pdf"},{"key":"12_CR18","unstructured":"ARM: Cortex-A9 Technical Reference Manual, http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.ddi0388f\/DDI0388F_cortex_a9_r2p2_trm.pdf"},{"key":"12_CR19","unstructured":"ARM: ARM Cortex-A15 MPCore Processor Technical Reference Manual, http:\/\/infocenter.arm.com\/help\/index.jsp?topic=\/com.arm.doc.ddi0438i\/index.html"},{"key":"12_CR20","unstructured":"ARM: Interrupt Behavior of Cortex-M1, http:\/\/infocenter.arm.com\/help\/index.jsp?topic=\/com.arm.doc.dai0211a\/index.html"},{"key":"12_CR21","unstructured":"ARM: Cortex-M4 Devices Generic User Guide, http:\/\/infocenter.arm.com\/help\/index.jsp?topic=\/com.arm.doc.dui0553a\/Cihfaaha.html"},{"key":"12_CR22","unstructured":"Freescale: Imx53qsb: i.mx53 quick start board, http:\/\/www.freescale.com\/webapp\/sps\/site\/prod_summary.jsp?code=IMX53QSB&tid=vanIMXQUICKSTART"},{"key":"12_CR23","unstructured":"Adeneo Embedded: Reference BSPs for Freescale i.MX53 Quick Start Board, http:\/\/www.adeneo-embedded.com\/en\/Products\/Board-Support-Packages\/Freescale-i.MX53-QSB"},{"key":"12_CR24","unstructured":"Paul Bakker: PolarSSL, https:\/\/polarssl.org\/"},{"key":"12_CR25","unstructured":"Michael Coppola: Suterusu Rootkit: Inline Kernel Function Hooking on x86 and ARM, http:\/\/poppopret.org\/2013\/01\/07\/suterusu-rootkit-inline-kernel-function-hooking-on-x86-and-arm\/"},{"key":"12_CR26","unstructured":"Heriyanto, A.P.: Procedures and tools for acquisition and analysis of volatile memory on android smartphones. In: Proceedings of The 11th Australian Digital Forensics Conference. SRI Security Research Institute, Edith Cowan University, Perth, Western Australia (2013)"},{"issue":"3-4","key":"12_CR27","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1016\/j.diin.2011.10.003","volume":"8","author":"J. Sylve","year":"2012","unstructured":"Sylve, J., Case, A., Marziale, L., Richard III, G.G.: Acquisition and analysis of volatile memory from android devices. Digital Investigation\u00a08(3-4), 175\u2013184 (2012)","journal-title":"Digital Investigation"},{"key":"12_CR28","unstructured":"Google: Using ddms for debugging, http:\/\/developer.android.com\/tools\/debugging\/ddms.html"},{"key":"12_CR29","unstructured":"Stevenson, A.: Boot into Recovery Mode for Rooted and Un-rooted Android devices, http:\/\/androidflagship.com\/605-enter-recovery-mode-rooted-un-rooted-android"},{"key":"12_CR30","unstructured":"Dall, C., Nieh, J.: Kvm for arm. In: Proceedings of the 12th Annual Linux Symposium (2010)"},{"key":"12_CR31","doi-asserted-by":"crossref","unstructured":"Dall, C., Nieh, J.: Kvm\/arm: The design and implementation of the linux arm hypervisor. In: Proceedings of the 19th International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2014 (2014)","DOI":"10.1145\/2541940.2541946"},{"issue":"1","key":"12_CR32","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1016\/j.diin.2003.12.001","volume":"1","author":"B.D. Carrier","year":"2004","unstructured":"Carrier, B.D., Grand, J.: A hardware-based memory acquisition procedure for digital investigations. Digital Investigation\u00a01(1), 50\u201360 (2004)","journal-title":"Digital Investigation"},{"key":"12_CR33","doi-asserted-by":"crossref","unstructured":"Breeuwsma, I.M.F.: Forensic Imaging of Embedded Systems Using JTAG (Boundary-scan). Digit. Investig.\u00a03(1) (March 2006)","DOI":"10.1016\/j.diin.2006.01.003"},{"key":"12_CR34","unstructured":"Jovanovic, Z., Redd, I.D.D.: Android forensics techniques. International Academy of Design and Technology (2012)"},{"key":"12_CR35","doi-asserted-by":"crossref","unstructured":"Me, G., Rossi, M.: Internal forensic acquisition for mobile equipments. In: IPDPS, pp. 1\u20137 (2008)","DOI":"10.1109\/IPDPS.2008.4536557"}],"container-title":["Lecture Notes in Computer Science","Computer Security - ESORICS 2014"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-11203-9_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,14]],"date-time":"2022-04-14T15:16:32Z","timestamp":1649949392000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-11203-9_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319112022","9783319112039"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-11203-9_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014]]}}}