{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T04:14:11Z","timestamp":1749615251274,"version":"3.41.0"},"publisher-location":"Cham","reference-count":50,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319472379"},{"type":"electronic","value":"9783319472386"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-47238-6_14","type":"book-chapter","created":{"date-parts":[[2016,10,4]],"date-time":"2016-10-04T18:36:56Z","timestamp":1475606216000},"page":"193-208","source":"Crossref","is-referenced-by-count":1,"title":["Secure Virtual Machine for Real Time Forensic Tools on Commodity Workstations"],"prefix":"10.1007","author":[{"given":"Dan","family":"Lu\u0163a\u015f","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrian","family":"Cole\u015fa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S\u00e1ndor","family":"Luk\u00e1cs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrei","family":"Lu\u0163a\u015f","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,5]]},"reference":[{"key":"14_CR1","unstructured":"Data Breach Investigations Report (DBIR). http:\/\/www.verizonenterprise.com\/DBIR\/2015\/"},{"key":"14_CR2","unstructured":"BusyBox. http:\/\/www.busybox.net\/about.html"},{"key":"14_CR3","unstructured":"Dropbear SSH. https:\/\/matt.ucc.asn.au\/dropbear\/dropbear.html"},{"key":"14_CR4","unstructured":"FTK Imager version 3.2.0 \u2013 AccessData. http:\/\/accessdata.com\/product-download\/digital-forensics\/ftk-imager-version-3.2.0"},{"key":"14_CR5","unstructured":"Immunity Inc: Knowing You\u2019re Secure. http:\/\/www.immunityinc.com\/products\/eljefe\/"},{"key":"14_CR6","unstructured":"Memoryze \u2013 FireEye. https:\/\/www.fireeye.com\/services\/freeware\/memoryze.html"},{"key":"14_CR7","unstructured":"MIG: Mozilla InvestiGator. http:\/\/mig.mozilla.org\/"},{"key":"14_CR8","unstructured":"Next-Generation Endpoint Protection \u2013 CrowdStrike Falcon Host. http:\/\/www.crowdstrike.com\/products\/falcon-host\/"},{"key":"14_CR9","unstructured":"OpenAttestation - OpenStack. https:\/\/wiki.openstack.org\/wiki\/OpenAttestation"},{"key":"14_CR10","unstructured":"Products \u2013 MoonSols. http:\/\/www.moonsols.com\/products\/"},{"key":"14_CR11","unstructured":"Rekall Memory Forensic Framework. http:\/\/www.rekall-forensic.com\/index.html"},{"key":"14_CR12","unstructured":"Rekall Memory Forensic Framework. http:\/\/www.rekall-forensic.com\/faq.html"},{"key":"14_CR13","unstructured":"RSA ECAT \u2013 Advanced Endpoint Threat Detection \u2013 EMC. http:\/\/www.emc.com\/security\/rsa-ecat.htm"},{"key":"14_CR14","unstructured":"TrouSerS - The open-source TCG Software Stack - FAQ. http:\/\/trousers.sourceforge.net\/faq.html#1.1"},{"key":"14_CR15","unstructured":"The Volatility Foundation - Open Source Memory Forensics. http:\/\/www.volatilityfoundation.org\/"},{"key":"14_CR16","unstructured":"vSphere ESXi Bare-Metal Hypervisor | United States. https:\/\/www.vmware.com\/products\/esxi-and-esx\/overview"},{"key":"14_CR17","unstructured":"Welcome to Python.org. https:\/\/www.python.org\/"},{"key":"14_CR18","unstructured":"Intel Trusted Execution Technology Software Development Guide, July 2015. http:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/guides\/intel-txt-software-development-guide.pdf"},{"issue":"1","key":"14_CR19","doi-asserted-by":"crossref","first-page":"65","DOI":"10.13052\/jcsm2245-1439.314","volume":"3","author":"S Balogh","year":"2014","unstructured":"Balogh, S.: Memory acquisition by using network card. J. Cyber Secur. Mobil. 3(1), 65\u201376 (2014)","journal-title":"J. Cyber Secur. Mobil."},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Barham, P., Dragovic, B., Fraser, K., Hand, S., Harris, T., Ho, A., Neugebauer, R., Pratt, I., Warfield, A.: Xen and the art of virtualization. In: Proceedings of the Nineteenth ACM Symposium on Operating Systems Principles, SOSP 2003, pp. 164\u2013177. ACM, New York (2003)","DOI":"10.1145\/945445.945462"},{"key":"14_CR21","unstructured":"Breuk, R., Spruyt, A.: Integrating DMA attacks in exploitation frameworks pp. 2011\u20132012 (2012). https:\/\/homepages.staff.os3.nl\/~delaat\/rp\/2011-2012\/p14\/report.pdf . Accessed 14 Jan 2014"},{"key":"14_CR22","doi-asserted-by":"crossref","unstructured":"Chen, X., Garfinkel, T., Lewis, E.C., Subrahmanyam, P., Waldspurger, C.A., Boneh, D., Dwoskin, J., Ports, D.R.: Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems. In: Proceedings of the 13th International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS XIII, pp. 2\u201313. ACM, New York (2008)","DOI":"10.1145\/1346281.1346284"},{"key":"14_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/978-3-642-30921-2_12","volume-title":"Trust and Trustworthy Computing","author":"Y Cheng","year":"2012","unstructured":"Cheng, Y., Ding, X.: Virtualization based password protection against malware in untrusted operating systems. In: Katzenbeisser, S., Weippl, E., Camp, L.J., Volkamer, M., Reiter, M., Zhang, X. (eds.) Trust 2012. LNCS, vol. 7344, pp. 201\u2013218. Springer, Heidelberg (2012)"},{"key":"14_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1007\/978-3-642-38908-5_2","volume-title":"Trust and Trustworthy Computing","author":"Y Cheng","year":"2013","unstructured":"Cheng, Y., Ding, X.: Guardian: hypervisor as security foothold for personal computers. In: Huth, M., Asokan, N., \u010capkun, S., Flechais, I., Coles-Kemp, L. (eds.) TRUST 2013. LNCS, vol. 7904, pp. 19\u201336. Springer, Heidelberg (2013)"},{"key":"14_CR25","unstructured":"Cheng, Y., Ding, X., Deng, R.H.: AppShield: protecting applications against untrusted operating system. Technical report, School of Information Systems, Singapore Management University, November 2013"},{"key":"14_CR26","doi-asserted-by":"crossref","first-page":"S101","DOI":"10.1016\/j.diin.2011.05.012","volume":"8","author":"M Cohen","year":"2011","unstructured":"Cohen, M., Bilby, D., Caronni, G.: Distributed forensics and incident response in the enterprise. Digit. Invest. 8, S101\u2013S110 (2011)","journal-title":"Digit. Invest."},{"key":"14_CR27","unstructured":"Cohen, M.: WinPMEM (2012). https:\/\/volatility.googlecode.com\/svn-history\/r2091\/branches\/scudette\/tools\/windows\/winpmem\/README"},{"key":"14_CR28","unstructured":"Dewan, P., Durham, D., Khosravi, H., Long, M., Nagabhushan, G.: A hypervisor-based system for protecting software runtime memory and persistent storage. In: Proceedings of the 2008 Spring Simulation Multiconference, pp. 828\u2013835. Society for Computer Simulation International (2008)"},{"key":"14_CR29","unstructured":"Dolan-Gavitt, B., Payne, B., Lee, W.: Leveraging forensic tools for virtual machine introspection (2011). https:\/\/smartech.gatech.edu\/handle\/1853\/38424"},{"key":"14_CR30","doi-asserted-by":"crossref","unstructured":"Hizver, J., Chiueh, T.C.: Real-time deep virtual machine introspection and its applications. In: Proceedings of the 10th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE 2014, pp. 3\u201314. ACM, New York (2014)","DOI":"10.1145\/2576195.2576196"},{"key":"14_CR31","doi-asserted-by":"crossref","unstructured":"Hofmann, O.S., Kim, S., Dunn, A.M., Lee, M.Z., Witchel, E.: InkTag: secure applications on an untrusted operating system. In: Proceedings of the Eighteenth International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 265\u2013278. ACM (2013)","DOI":"10.1145\/2451116.2451146"},{"key":"14_CR32","unstructured":"Kivity, A., Kamay, Y., Laor, D., Lublin, U., Liguori, A.: KVM: the Linux virtual machine monitor, pp. 225\u2013230, July 2007. http:\/\/www.kernel.org\/doc\/ols\/2007\/ols2007v1-pages-225-230.pdf"},{"key":"14_CR33","doi-asserted-by":"crossref","unstructured":"Lengyel, T.K., Maresca, S., Payne, B.D., Webster, G.D., Vogl, S., Kiayias, A.: Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. In: Proceedings of the 30th Annual Computer Security Applications Conference, pp. 386\u2013395. ACM (2014)","DOI":"10.1145\/2664243.2664252"},{"key":"14_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1007\/978-3-319-22846-4_15","volume-title":"Trust and Trustworthy Computing","author":"A Lu\u0163a\u015f","year":"2015","unstructured":"Lu\u0163a\u015f, A., Luk\u00e1cs, S., Cole\u015fa, A., Lu\u0163a\u015f, D.: Proposed processor extensions for significant speedup of hypervisor memory introspection. In: Conti, M., Schunter, M., Askoxylakis, I. (eds.) TRUST 2015. LNCS, vol. 9229, pp. 249\u2013267. Springer, Heidelberg (2015)"},{"key":"14_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1007\/978-3-642-15512-3_16","volume-title":"Recent Advances in Intrusion Detection","author":"L Martignoni","year":"2010","unstructured":"Martignoni, L., Fattori, A., Paleari, R., Cavallaro, L.: Live and trustworthy forensic analysis of commodity production systems. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 297\u2013316. Springer, Heidelberg (2010)"},{"key":"14_CR36","unstructured":"Martin, A.: FireWire memory dump of a windows XP computer: a forensic approach. Black Hat DC, pp. 1\u201313 (2007). http:\/\/www.friendsglobal.com\/papers\/FireWire%20Memory%20Dump%20of%20Windows%20XP.pdf"},{"issue":"2","key":"14_CR37","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1016\/j.diin.2013.03.003","volume":"10","author":"A Moser","year":"2013","unstructured":"Moser, A., Cohen, M.I.: Hunting in the enterprise: forensic triage and incident response. Digit. Invest. 10(2), 89\u201398 (2013)","journal-title":"Digit. Invest."},{"key":"14_CR38","doi-asserted-by":"crossref","unstructured":"Newsome, J., McCune, J.M., Zhou, Z., Gligor, V.D.: Building verifiable trusted path on commodity x86 computers. In: 2012 IEEE Symposium on Security and Privacy, SP 2012, pp. 616\u2013630. IEEE, May 2012","DOI":"10.1109\/SP.2012.42"},{"key":"14_CR39","unstructured":"Payne, B.D.: Simplifying virtual machine introspection using LibVMI. Sandia report (2012). http:\/\/prod.sandia.gov\/techlib\/access-control.cgi\/2012\/127818.pdf"},{"key":"14_CR40","doi-asserted-by":"crossref","unstructured":"Payne, B.D., De Carbone, M.D.P., Lee, W.: Secure and flexible monitoring of virtual machines. In: Twenty-Third Annual Computer Security Applications Conference, ACSAC 2007, pp. 385\u2013397. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.10"},{"key":"14_CR41","doi-asserted-by":"crossref","unstructured":"Reina, A., Fattori, A., Pagani, F., Cavallaro, L., Bruschi, D.: When hardware meets software: a bulletproof solution to forensic memory acquisition. In: Proceedings of the 28th Annual Computer Security Applications Conference, pp. 79\u201388. ACM (2012)","DOI":"10.1145\/2420950.2420962"},{"key":"14_CR42","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1016\/j.diin.2007.06.009","volume":"4","author":"B Schatz","year":"2007","unstructured":"Schatz, B.: BodySnatcher: towards reliable volatile memory acquisition by software. Digit. Invest. 4, 126\u2013134 (2007)","journal-title":"Digit. Invest."},{"issue":"6","key":"14_CR43","doi-asserted-by":"crossref","first-page":"335","DOI":"10.1145\/1323293.1294294","volume":"41","author":"A Seshadri","year":"2007","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: SecVisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity OSes. ACM SIGOPS Oper. Syst. Rev. 41(6), 335\u2013350 (2007)","journal-title":"ACM SIGOPS Oper. Syst. Rev."},{"key":"14_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/978-3-642-37300-8_2","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"P Stewin","year":"2013","unstructured":"Stewin, P., Bystrov, I.: Understanding DMA malware. In: Flegel, U., Markatos, E., Robertson, W. (eds.) DIMVA 2012. LNCS, vol. 7591, pp. 21\u201341. Springer, Heidelberg (2013)"},{"key":"14_CR45","doi-asserted-by":"crossref","first-page":"S105","DOI":"10.1016\/j.diin.2013.06.012","volume":"10","author":"J St\u00fcttgen","year":"2013","unstructured":"St\u00fcttgen, J., Cohen, M.: Anti-forensic resilient memory acquisition. Digit. Invest. 10, S105\u2013S115 (2013)","journal-title":"Digit. Invest."},{"issue":"2","key":"14_CR46","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1016\/j.diin.2012.04.005","volume":"9","author":"S V\u00f6mel","year":"2012","unstructured":"V\u00f6mel, S., Freiling, F.C.: Correctness, atomicity, and integrity: defining criteria for forensically-sound memory acquisition. Digit. Invest. 9(2), 125\u2013137 (2012)","journal-title":"Digit. Invest."},{"key":"14_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"158","DOI":"10.1007\/978-3-642-15512-3_9","volume-title":"Recent Advances in Intrusion Detection","author":"J Wang","year":"2010","unstructured":"Wang, J., Stavrou, A., Ghosh, A.: HyperCheck: a hardware-assisted integrity monitor. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 158\u2013177. Springer, Heidelberg (2010)"},{"key":"14_CR48","doi-asserted-by":"crossref","unstructured":"Yu, M., Lin, Q., Li, B., Qi, Z., Guan, H.: Vis: virtualization enhanced live acquisition for native system. In: Proceedings of the Second Asia-Pacific Workshop on Systems, p. 13. ACM (2011)","DOI":"10.1145\/2103799.2103815"},{"key":"14_CR49","doi-asserted-by":"crossref","unstructured":"Zaharia, M., Katti, S., Grier, C., Paxson, V., Shenker, S., Stoica, I., Song, D.: Hypervisors as a foothold for personal computer security: an agenda for the research community. Technical report, UCB\/EECS-2012-12, EECS Department, University of California, Berkeley (2012)","DOI":"10.21236\/ADA555877"},{"issue":"3","key":"14_CR50","doi-asserted-by":"crossref","first-page":"455","DOI":"10.1007\/s10766-013-0285-2","volume":"43","author":"X Zhong","year":"2015","unstructured":"Zhong, X., Xiang, C., Yu, M., Qi, Z., Guan, H.: A virtualization based monitoring system for mini-intrusive live forensics. Int. J. Parallel Program. 43(3), 455\u2013471 (2015)","journal-title":"Int. J. Parallel Program."}],"container-title":["Lecture Notes in Computer Science","Innovative Security Solutions for Information Technology and Communications"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-47238-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,10]],"date-time":"2025-06-10T22:49:30Z","timestamp":1749595770000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-47238-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319472379","9783319472386"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-47238-6_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}