{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T01:31:11Z","timestamp":1763429471863,"version":"3.40.3"},"publisher-location":"Cham","reference-count":19,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319672076"},{"type":"electronic","value":"9783319672083"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-67208-3_7","type":"book-chapter","created":{"date-parts":[[2017,8,30]],"date-time":"2017-08-30T12:21:00Z","timestamp":1504095660000},"page":"111-130","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Identifying Evidence for Cloud Forensic Analysis"],"prefix":"10.1007","author":[{"given":"Changwei","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anoop","family":"Singhal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Duminda","family":"Wijesekera","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,31]]},"reference":[{"unstructured":"Beck, F., Festor, O.: Syscall Interception in Xen Hypervisor, Technical Report no. 9999, INRIA Nancy - Grand Est, Villers-les-Nancy, France (2009)","key":"7_CR1"},{"doi-asserted-by":"crossref","unstructured":"Birk, D., Wegener, C.: Technical issues of forensic investigations in cloud computing environments. In: Proceedings of the Sixth International Workshop on Systematic Approaches to Digital Forensic Engineering (2011)","key":"7_CR2","DOI":"10.1109\/SADFE.2011.17"},{"doi-asserted-by":"crossref","unstructured":"Dykstra, J., Sherman, A.: Acquiring forensic evidence from infrastructure-as-a-service cloud computing: Exploring and evaluating tools, trust and techniques. Digital Investigation 9(S), S90\u2013S98 (2012)","key":"7_CR3","DOI":"10.1016\/j.diin.2012.05.001"},{"doi-asserted-by":"crossref","unstructured":"Dykstra, J., Sherman, A.: Design and implementation of FROST: Digital forensic tools for the OpenStack cloud computing platform. Digital Investigation 10(S), S87\u2013S95 (2013)","key":"7_CR4","DOI":"10.1016\/j.diin.2013.06.010"},{"issue":"3","key":"7_CR5","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/1368506.1368517","volume":"42","author":"B Hay","year":"2008","unstructured":"Hay, B., Nance, K.: Forensic examination of volatile system data using virtual introspection. ACM SIGOPS Operating Systems Review 42(3), 74\u201382 (2008)","journal-title":"ACM SIGOPS Operating Systems Review"},{"issue":"3","key":"7_CR6","doi-asserted-by":"publisher","first-page":"151","DOI":"10.3233\/JCS-980109","volume":"6","author":"S Hofmeyr","year":"1998","unstructured":"Hofmeyr, S., Forrest, S., Somayaji, A.: Intrusion detection using sequences of system calls. Journal of Computer Security 6(3), 151\u2013180 (1998)","journal-title":"Journal of Computer Security"},{"key":"7_CR7","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.500-291v1","volume-title":"NIST Cloud Computing Standards Roadmap, NIST Special Publication 500\u2013291","author":"M Hogan","year":"2011","unstructured":"Hogan, M., Liu, F., Sokol, A., Tong, J.: NIST Cloud Computing Standards Roadmap, NIST Special Publication 500\u2013291. National Institute of Standards and Technology, Gaithersburg (2011)"},{"unstructured":"Jaquith, A.: Security Metrics: Replacing Fear, Uncertainty and Doubt. Pearson Education, Boston (2007)","key":"7_CR8"},{"key":"7_CR9","volume-title":"Guide to Integrating Forensic Techniques into Incident Response, NIST Special Publication 800\u201386","author":"K Kent","year":"2006","unstructured":"Kent, K., Chevalier, S., Grance, T., Dang, H.: Guide to Integrating Forensic Techniques into Incident Response, NIST Special Publication 800\u201386. National Institute of Standards and Technology, Gaithersburg (2006)"},{"key":"7_CR10","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1007\/978-3-319-24123-4_8","volume-title":"Advances in Digital Forensics XI","author":"C Liu","year":"2015","unstructured":"Liu, C., Singhal, A., Wijesekera, D.: A logic-based network forensic model for evidence analysis. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2015. IAICT, vol. 462, pp. 129\u2013145. Springer, Cham (2015). doi:10.1007\/978-3-319-24123-4_8"},{"key":"7_CR11","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"189","DOI":"10.1007\/978-3-319-46279-0_10","volume-title":"Advances in Digital Forensics XII","author":"C Liu","year":"2016","unstructured":"Liu, C., Singhal, A., Wijesekara, D.: A probabilistic network forensic model for evidence analysis. In: Peterson, G., Shenoi, S. (eds.) Advances in Digital Forensics XII. IFIPAICT, vol. 484, pp. 189\u2013210. Springer, Cham (2016). doi:10.1007\/978-3-319-46279-0_10"},{"doi-asserted-by":"crossref","unstructured":"Mell, P., Grance, T.: NIST Definition of Cloud Computing, NIST Special Publication 800\u2013145. National Institute of Standards and Technology, Gaithersburg (2011)","key":"7_CR12","DOI":"10.6028\/NIST.SP.800-145"},{"unstructured":"Ou, X., Govindavajhala, S., Appel, A.: MulVAL: a logic-based network security analyzer. In: Proceedings of the Fourteenth USENIX Security Symposium (2005)","key":"7_CR13"},{"unstructured":"Palmer, G.: A Road Map for Digital Forensic Research, DFRWS Technical Report, DTR-T001-01 Final, Air Force Research Laboratory, Rome, New York (2001)","key":"7_CR14"},{"key":"7_CR15","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1016\/j.diin.2015.03.002","volume":"13","author":"A Pichan","year":"2015","unstructured":"Pichan, A., Lazarescu, M., Soh, S.: Cloud forensics: Technical challenges, solutions and comparative analysis. Digital Investigation 13, 38\u201357 (2015)","journal-title":"Digital Investigation"},{"doi-asserted-by":"crossref","unstructured":"Ruan, K., Carthy, J., Kechadi, T., Crosbie, M.: Cloud forensics. In: Peterson, G., Shenoi, S. (eds.) Advances in Digital Forensics V, pp. 35\u201346. Springer, Heidelberg (2011)","key":"7_CR16","DOI":"10.1007\/978-3-642-24212-0_3"},{"doi-asserted-by":"crossref","unstructured":"Sun, X., Dai, J., Liu, P., Singhal, A., Yen, J.: Towards probabilistic identification of zero-day attack paths. In: Proceedings of the IEEE Conference on Communications and Network Security, pp. 64\u201372 (2016)","key":"7_CR17","DOI":"10.1109\/CNS.2016.7860471"},{"doi-asserted-by":"crossref","unstructured":"Wang, W., Daniels, T.: A graph based approach toward network forensic analysis. ACM Transactions on Information and Systems Security 12(1), article no. 4 (2008)","key":"7_CR18","DOI":"10.1145\/1410234.1410238"},{"key":"7_CR19","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"271","DOI":"10.1007\/978-3-319-24123-4_16","volume-title":"Advances in Digital Forensics XI","author":"S Zawoad","year":"2015","unstructured":"Zawoad, S., Hasan, R.: A trustworthy cloud forensics environment. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2015. IAICT, vol. 462, pp. 271\u2013285. Springer, Cham (2015). doi:10.1007\/978-3-319-24123-4_16"}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics XIII"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-67208-3_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,31]],"date-time":"2021-08-31T00:05:18Z","timestamp":1630368318000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-67208-3_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319672076","9783319672083"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-67208-3_7","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"31 August 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DigitalForensics","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Digital Forensics","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Orlando","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 January 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 February 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"digitalforensics2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip119.org\/Conferences\/ConferenceProgram2017.pdf","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}