{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,10]],"date-time":"2024-09-10T13:40:42Z","timestamp":1725975642162},"publisher-location":"Cham","reference-count":56,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319788159"},{"type":"electronic","value":"9783319788166"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78816-6_7","type":"book-chapter","created":{"date-parts":[[2018,4,23]],"date-time":"2018-04-23T23:02:48Z","timestamp":1524524568000},"page":"85-103","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Identification of Forensic Artifacts in VMWare Virtualized Computing"],"prefix":"10.1007","author":[{"given":"Cory","family":"Smith","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Glenn","family":"Dietrich","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,25]]},"reference":[{"key":"7_CR1","unstructured":"Admin. Password Recovery. Password Recovery RSS. Top Password Software, Inc., 31 May 2013. https:\/\/www.top-password.com\/blog\/tag\/windows-samregistry-file\/ . Accessed 11 July 2017"},{"key":"7_CR2","unstructured":"Atkison, T., Cruz, J.C.F.: Digital Forensics on a Virtual Machine. Rep. (n.d.). http:\/\/atkison.cs.ua.edu\/papers\/ACMSE11_JF.pdf . Accessed 18 July 2017"},{"key":"7_CR3","series-title":"Intelligent Systems Reference Library","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-44270-9_1","volume-title":"Multimedia Forensics and Security","author":"ASA Aziz","year":"2017","unstructured":"Aziz, A.S.A., Fouad, M.M., Hassanien, A.E.: Cloud computing forensic analysis: trends and challenges. In: Hassanien, A.E., Fouad, M.M., Manaf, A.A., Zamani, M., Ahmad, R., Kacprzyk, J. (eds.) Multimedia Forensics and Security. ISRL, vol. 115, pp. 3\u201323. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-44270-9_1"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Martini, B., Choo, K.-K.R.: Remote programmatic vCloud forensics: a six-step collection process and a proof of concept. In: Proceedings of 13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2014, pp. 935\u2013942 (2014)","DOI":"10.1109\/TrustCom.2014.124"},{"key":"7_CR5","unstructured":"Kleyman, B.: Hypervisor 101: Understanding the Virtualization Market. Data Center Knowledge. Penton, 03 August 2012. http:\/\/www.datacenterknowledge.com\/archives\/2012\/08\/01\/hypervisor-101-a-lookhypervisor-market\/ . Accessed 14 June 2017"},{"key":"7_CR6","doi-asserted-by":"crossref","unstructured":"Birk, D., Christoph, W.: Technical Issues of Forensic Investigations in Cloud Computing Environments. Rep. (n.d.)","DOI":"10.1109\/SADFE.2011.17"},{"issue":"4","key":"7_CR7","doi-asserted-by":"publisher","first-page":"1054","DOI":"10.1111\/1556-4029.13393","volume":"62","author":"B Eterovic-Soric","year":"2017","unstructured":"Eterovic-Soric, B., Choo, K.-K.R., Mubarak, S., Ashman, H.: Windows 7 antiforensics: a review and a novel approach. J. Forensic Sci. 62(4), 1054\u20131070 (2017)","journal-title":"J. Forensic Sci."},{"issue":"2","key":"7_CR8","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1109\/MCC.2017.30","volume":"4","author":"C Esposito","year":"2017","unstructured":"Esposito, C., Castiglione, A., Pop, F., Choo, K.-K.R.: Challenges of connecting edge and cloud computing: a security and forensic perspective. IEEE Cloud Comput. 4(2), 13\u201317 (2017)","journal-title":"IEEE Cloud Comput."},{"issue":"6","key":"7_CR9","doi-asserted-by":"publisher","first-page":"1378","DOI":"10.1016\/j.future.2013.02.001","volume":"29","author":"D Quick","year":"2013","unstructured":"Quick, D., Choo, K.-K.R.: Digital droplets: microsoft SkyDrive forensic data remnants. Future Gener. Comput. Syst. 29(6), 1378\u20131394 (2013)","journal-title":"Future Gener. Comput. Syst."},{"issue":"1","key":"7_CR10","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1016\/j.diin.2013.02.003","volume":"10","author":"D Quick","year":"2013","unstructured":"Quick, D., Choo, K.-K.R.: Dropbox analysis: data remnants on user machines. Digit. Invest. 10(1), 3\u201318 (2013)","journal-title":"Digit. Invest."},{"issue":"3","key":"7_CR11","doi-asserted-by":"publisher","first-page":"266","DOI":"10.1016\/j.diin.2013.07.001","volume":"10","author":"D Quick","year":"2013","unstructured":"Quick, D., Choo, K.-K.R.: Forensic collection of cloud storage data: does the act of collection result in changes to the data or its metadata? Digit. Invest. 10(3), 266\u2013277 (2013)","journal-title":"Digit. Invest."},{"key":"7_CR12","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1016\/j.jnca.2013.09.016","volume":"40","author":"D Quick","year":"2014","unstructured":"Quick, D., Choo, K.-K.R.: Google drive: forensic analysis of data remnants. J. Netw. Comput. Appl. 40, 179\u2013193 (2014)","journal-title":"J. Netw. Comput. Appl."},{"key":"7_CR13","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1016\/j.jnca.2016.11.018","volume":"86","author":"D Quick","year":"2017","unstructured":"Quick, D., Choo, K.-K.R.: Pervasive social networking forensics: intelligence and evidence from mobile device extracts. J. Netw. Comput. Appl. 86, 24\u201333 (2017)","journal-title":"J. Netw. Comput. Appl."},{"key":"7_CR14","unstructured":"Dean, B.: Best Practices in Browser Forensics. IANS. IANS (n.d.). https:\/\/www.iansresearch.com\/insights\/reports\/best-practices-in-browser-forensics . Accessed 15 June 2017"},{"key":"7_CR15","unstructured":"Digital Evidence and Forensics. National Institute of Justice, 14 April 2016. https:\/\/www.nij.gov\/topics\/forensics\/evidence\/digital\/Pages\/welcome.aspx . Accessed 23 July 2017"},{"key":"7_CR16","unstructured":"Disabling Prefetch. Microsoft Developer Network. Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/ms940847(v=winembedded.5).aspx . Accessed 18 July 2017"},{"key":"7_CR17","unstructured":"Dkovar. Dkovar\/analyzeMFT. GitHub. GitHub, Inc., 16 July 2017. https:\/\/github.com\/dkovar\/analyzeMFT . Accessed 13 July 2017"},{"key":"7_CR18","unstructured":"Dykstra, J., Sherman, A.T.: Understanding Issues in Cloud Forensics: Two Hypothetical Case Studies. Rep. (2011)"},{"key":"7_CR19","unstructured":"Forensic Analysis of Prefetch Files in Windows. Magnet Forensics Inc. Magnet Forensics, 6 August 2014. https:\/\/www.magnetforensics.com\/computerforensics\/forensic-analysis-of-prefetch-files-in-windows\/ . Accessed 15 July 2017"},{"key":"7_CR20","unstructured":"Forensic Toolkit (FTK). AccessData (n.d.). http:\/\/accessdata.com\/products-services\/forensic-toolkit-ftk . Accessed 15 July 2017"},{"key":"7_CR21","unstructured":"FTK BootCamp Windows 7 Forensics - Recycle Bin. AccessData (n.d.). http:\/\/accessdata.com\/ . Accessed 16 July 2017"},{"key":"7_CR22","unstructured":"How To: Access the Application Event Log. Microsoft TechNet. Microsoft (n.d.). https:\/\/technet.microsoft.com\/en-us\/library\/ms166507(v=sql.90).aspx . Accessed 19 July 2017"},{"key":"7_CR23","unstructured":"How to Clear Cache, Cookies and History. What Is Cache, Cookies, and History and How Do You Clear Them\u2026 Content (n.d.). http:\/\/www.pgcconline.com\/technicalSupport\/clearCache\/clearCache.html . Accessed 17 July 2017"},{"key":"7_CR24","unstructured":"How to View the System Log in Event Viewer. Microsoft TechNet. Microsoft (n.d.). https:\/\/technet.microsoft.com\/en-us\/library\/aa996634(v=exchg.65).aspx . Accessed 19 July 2017"},{"key":"7_CR25","volume-title":"Incident Response & Computer Forensics","author":"J Luttgens","year":"2014","unstructured":"Luttgens, J., Pepe, M., Mandia, K.: Incident Response & Computer Forensics, 3rd edn. McGraw-Hill\/Osborne, New York (2014)","edition":"3"},{"key":"7_CR26","unstructured":"Jensen, C.: FTK Imager User Guide. AccessData, Lindon, 21 March 2012"},{"key":"7_CR27","unstructured":"Jensen, C.: FTK User Guide. AccessData, Lindon, 21 January 2015"},{"issue":"3","key":"7_CR28","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MCC.2017.39","volume":"4","author":"K-KR Choo","year":"2017","unstructured":"Choo, K.-K.R., Esposito, C., Castiglione, A.: Evidence and forensics in the cloud: challenges and future research directions. IEEE Cloud Comput. 4(3), 14\u201319 (2017)","journal-title":"IEEE Cloud Comput."},{"key":"7_CR29","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1016\/j.diin.2016.08.003","volume":"18","author":"K-KR Choo","year":"2016","unstructured":"Choo, K.-K.R., Herman, M., Iorga, M., Martini, B.: Cloud forensics: state-of-the-art and future directions. Digit. Invest. 18, 77\u201378 (2016)","journal-title":"Digit. Invest."},{"key":"7_CR30","unstructured":"Lee, R.: SANS Digital Forensics and Incident Response Blog. SANS Digital Forensics and Incident Response Blog | New Windows Forensics Evidence of Poster Released | SANS Institute. SANS Institute, 04 June 2015. https:\/\/digitalforensics.sans.org\/blog\/2015\/06\/04\/new-windows-forensics-evidence-of-poster-released . Accessed 18 June 2017"},{"key":"7_CR31","unstructured":"Master File Table. Master File Table (Windows). Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa365230(v=vs.85).aspx . Accessed 12 July 2017"},{"issue":"14","key":"7_CR32","doi-asserted-by":"publisher","first-page":"e3855","DOI":"10.1002\/cpe.3855","volume":"29","author":"Niken Dwi Wahyu Cahyani","year":"2016","unstructured":"Cahyani, N.D.W., Martini, B., Choo, K.-K.R., Muhammad Nuh Al-Azhar, A.K.B.P.: Forensic data acquisition from cloud-of-things devices: windows smartphones as a case study. Concurr. Comput.: Pract. Exp. 29(14) (2017)","journal-title":"Concurrency and Computation: Practice and Experience"},{"issue":"2","key":"7_CR33","first-page":"240","volume":"22","author":"NDW Cahyani","year":"2017","unstructured":"Cahyani, N.D.W., Ab Rahman, N.H., Glisson, W.B., Choo, K.-K.R.: The role of mobile forensics in terrorism investigations involving the use of cloud storage service and communication apps. MONET 22(2), 240\u2013254 (2017)","journal-title":"MONET"},{"issue":"14","key":"7_CR34","doi-asserted-by":"publisher","first-page":"e3868","DOI":"10.1002\/cpe.3868","volume":"29","author":"Nurul Hidayah Ab Rahman","year":"2016","unstructured":"Ab Rahman, N.H., Cahyani, N.D.W., Choo, K.-K.R.: Cloud incident handling and forensic-by-design: cloud storage as a case study. Concurr. Comput.: Pract. Exp. 29(14) (2017)","journal-title":"Concurrency and Computation: Practice and Experience"},{"issue":"1","key":"7_CR35","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MCC.2016.5","volume":"3","author":"NH Ab Rahman","year":"2016","unstructured":"Ab Rahman, N.H., Glisson, W.B., Yang, Y., Choo, K.-K.R.: Forensic-by-design framework for cyber-physical cloud systems. IEEE Cloud Comput. 3(1), 50\u201359 (2016)","journal-title":"IEEE Cloud Comput."},{"key":"7_CR36","unstructured":"Predefined Keys. Predefined Keys (Windows). Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ms724836(v=vs.85).aspx . Accessed 11 July 2017"},{"key":"7_CR37","unstructured":"Product Downloads. AccessData (n.d.). http:\/\/accessdata.com\/product-download\/registry-viewer-1.8.1.3 . Accessed 14 July 2017"},{"key":"7_CR38","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1007\/978-3-662-44952-3_7","volume-title":"Advances in Digital Forensics X","author":"Q Do","year":"2014","unstructured":"Do, Q., Martini, B., Looi, J., Wang, Y., Choo, K.-K.R.: Windows event forensic process. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2014. IAICT, vol. 433, pp. 87\u2013100. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44952-3_7"},{"key":"7_CR39","unstructured":"Registry Hives. Registry Hives (Windows). Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ms724877(v=vs.85).aspx . Accessed 16 July 2017"},{"key":"7_CR40","unstructured":"RightScale 2017 State of the Cloud Report. Rep. RightScale, Inc (n.d.). http:\/\/assets.rightscale.com\/uploads\/pdfs\/RightScale-2017-State-of-the-Cloud-Report.pdf?mkt_tok=eyJpIjoiTjJOaE1qTm1aRFJoTm1ZeSIsInQiOiJGQlB2WklLRWp4OFU1Mm1FS1dzRW9DOFQwaXhuT0lPYVlzcktCMmdUeEVaRk84dTlGQnFIaWNxM0k0WnNIaUgyS2ZRdGs3Nk9hUFZNeXFJVU94ZmFRdU55ZVB5NzF5WjNRQXUrbW1INlhLTUtYdEY5bmdtbFJ3VVFQbXV0YWczNCJ9 . Accessed 10 June 2017"},{"key":"7_CR41","first-page":"1","volume":"118","author":"R McKemmish","year":"1999","unstructured":"McKemmish, R.: What is forensic computing? Trends Issues Crime Crim. Justice 118, 1\u20136 (1999)","journal-title":"Trends Issues Crime Crim. Justice"},{"key":"7_CR42","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1016\/j.csi.2016.09.002","volume":"49","author":"S Pokharel","year":"2017","unstructured":"Pokharel, S., Choo, K.-K.R., Liu, J.: Mobile cloud security: an adversary model for lightweight browser security. Comput. Stand. Interfaces 49, 71\u201378 (2017)","journal-title":"Comput. Stand. Interfaces"},{"key":"7_CR43","unstructured":"Shavers, B.: Virtual Forensics: A Discussion of Virtual Machines Related to Forensic Analysis. Rep. Virtual Forensics (n.d.). https:\/\/www.forensicfocus.com\/downloads\/virtual-machines-forensics-analysis.pdf . Accessed 24 June 2017"},{"key":"7_CR44","unstructured":"Stam, M.: Lab FTK Imager: File Carving Using the MFT. 8 Bits. Techblog, 09 October 2009. http:\/\/stam.blogs.com\/8bits\/2009\/10\/lab-ftk-imager-file-carvingusing-the-mft-.html . Accessed 10 July 2017"},{"key":"7_CR45","volume-title":"The Cuckoo\u2019s Egg: Tracking a Spy Through the Maze of Computer Espionage","author":"C Stoll","year":"2005","unstructured":"Stoll, C.: The Cuckoo\u2019s Egg: Tracking a Spy Through the Maze of Computer Espionage. Pocket, New York (2005)"},{"key":"7_CR46","unstructured":"Task Scheduler. Task Scheduler (Windows). Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa383614(v=vs.85).aspx . Accessed 14 July 2017"},{"key":"7_CR47","unstructured":"Tholeti, B.P.: Learn about Hypervisors, System Virtualization, and How It Works in a Cloud Environment. Hypervisors, Virtualization, and the Cloud, 23 September 2011. https:\/\/www.ibm.com\/developerworks\/cloud\/library\/clhypervisorcompare\/ . Accessed 10 June 2017"},{"key":"7_CR48","unstructured":"2.4 .JOB File Format. [MS-TSCH]: .JOB File Format. Microsoft (n.d.). https:\/\/msdn.microsoft.com\/en-us\/library\/cc248285.aspx . Accessed 19 July 2017"},{"key":"7_CR49","doi-asserted-by":"crossref","unstructured":"Urias, V.E., Young, J.W.: Hypervisor assisted forensics and incident response in the cloud. Publication no. 10.1109. IEEE (2016)","DOI":"10.1109\/CIT.2016.104"},{"key":"7_CR50","unstructured":"Vandeven, S.: Forensic Images: For Your Viewing Pleasure. Publication. SANS Institute (2014)"},{"key":"7_CR51","unstructured":"Virtualization Technology & Virtual Machine Software. VMWare. VMware, Inc., 20 July 2017. https:\/\/www.vmware.com\/solutions\/virtualization.html . Accessed 22 July 2017"},{"key":"7_CR52","unstructured":"VMware Workstation 5.5. What Files Make Up a Virtual Machine? VMware, Inc (n.d.). https:\/\/www.vmware.com\/support\/ws55\/doc\/ws_learning_files_in_a_vm.html . Accessed 12 June 2017"},{"key":"7_CR53","unstructured":"Volume Shadow Copy Service. Windows Server. Microsoft (n.d.). https:\/\/technet.microsoft.com\/en-us\/library\/ee923636(v=ws.10).aspx . Accessed 15 July 2017"},{"key":"7_CR54","unstructured":"Welcome to MyKey Technology. MFT Ripper. MyKey Technology Inc (n.d.). http:\/\/mftripper.com\/ . Accessed 18 July 2017"},{"key":"7_CR55","unstructured":"WinPrefetchView V1.35. View the Content of Windows Prefetch (.pf) Files. Nir Sofer (n.d.). http:\/\/www.nirsoft.net\/utils\/win_prefetch_view.html . Accessed 16 July 2017"},{"key":"7_CR56","doi-asserted-by":"publisher","first-page":"350","DOI":"10.1016\/j.compeleceng.2016.08.020","volume":"58","author":"Y-Y Teing","year":"2017","unstructured":"Teing, Y.-Y., Dehghantanha, A., Choo, K.-K.R., Yang, L.T.: Forensic investigation of P2P cloud storage services and backbone for IoT networks: BitTorrent Sync as a case study. Comput. Electr. Eng. 58, 350\u2013363 (2017)","journal-title":"Comput. Electr. Eng."}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78816-6_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,16]],"date-time":"2019-10-16T18:47:04Z","timestamp":1571251624000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78816-6_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788159","9783319788166"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78816-6_7","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2018]]}}}