{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T06:56:39Z","timestamp":1742972199873,"version":"3.40.3"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319992761"},{"type":"electronic","value":"9783319992778"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-99277-8_12","type":"book-chapter","created":{"date-parts":[[2018,8,30]],"date-time":"2018-08-30T01:58:12Z","timestamp":1535594292000},"page":"199-224","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Hashing Incomplete and Unordered Network Streams"],"prefix":"10.1007","author":[{"given":"Chao","family":"Zheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingyun","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yong","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Binxing","family":"Fang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,8,30]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"F. Breitinger and I. Baggili, File detection on network traffic using approximate matching, Journal of Digital Forensics, Security and Law, vol. 9(2), pp. 23\u201335, 2014.","key":"12_CR1","DOI":"10.15394\/jdfsl.2014.1168"},{"doi-asserted-by":"crossref","unstructured":"F. Breitinger and H. Baier, Performance issues about context-triggered piecewise hashing, Proceedings of the International Conference on Digital Forensics and Cyber Crime, pp. 141\u2013155, 2011.","key":"12_CR2","DOI":"10.1007\/978-3-642-35515-8_12"},{"doi-asserted-by":"crossref","unstructured":"F. Breitinger and H. Baier, Similarity preserving hashing: Eligible properties and a new algorithm MRSH-v2, Proceedings of the International Conference on Digital Forensics and Cyber Crime, pp. 167\u2013182, 2012.","key":"12_CR3","DOI":"10.1007\/978-3-642-39891-9_11"},{"unstructured":"A. Broder, On the resemblance and containment of documents, Proceedings of the Conference on Compression and Complexity of Sequences, pp. 21\u201329, 1997.","key":"12_CR4"},{"doi-asserted-by":"crossref","unstructured":"M. Charikar, Similarity estimation techniques from rounding algorithms, Proceedings of the Thirty-Fourth Annual ACM Symposium on the Theory of Computing, pp. 380\u2013388, 2002.","key":"12_CR5","DOI":"10.1145\/509907.509965"},{"doi-asserted-by":"crossref","unstructured":"L. Chen and G. Wang, An efficient piecewise hashing method for computer forensics, Proceedings of the First International Workshop on Knowledge Discovery and Data Mining, pp. 635\u2013638, 2008.","key":"12_CR6","DOI":"10.1109\/WKDD.2008.80"},{"unstructured":"T. Cormen, C. Leiserson, R. Rivest and C. Stein, Introduction to Algorithms, MIT Press, Cambridge, Massachusetts, 2009.","key":"12_CR7"},{"doi-asserted-by":"crossref","unstructured":"Y. Elovici, A. Shabtai, R. Moskovitch, G. Tahan and C. Glezer, Applying machine learning techniques for detection of malicious code in network traffic, Proceedings of the Annual Conference on Artificial Intelligence, pp. 44\u201350, 2007.","key":"12_CR8","DOI":"10.1007\/978-3-540-74565-5_5"},{"doi-asserted-by":"crossref","unstructured":"R. Fielding, J. Gettys, J. Mogul, H. Frystyk, L. Masinter, P. Leach and T. Berners-Lee, Hypertext Transfer Protocol \u2013 HTTP\/1.1, RFC 2616, 1999.","key":"12_CR9","DOI":"10.17487\/rfc2616"},{"doi-asserted-by":"crossref","unstructured":"M. Grassl, I. Ilic, S. Magliveras and R. Steinwandt, Cryptanalysis of the Tillich-Z\u00e9mor hash function, Journal of Cryptology, vol. 24(1), pp. 148\u2013156, 2011.","key":"12_CR10","DOI":"10.1007\/s00145-010-9063-0"},{"doi-asserted-by":"crossref","unstructured":"V. Harichandran, F. Breitinger and I. Baggili, Bytewise approximate matching: The good, the bad and the unknown, Journal of Digital Forensics, Security and Law, vol. 11(2), pp. 59\u201377, 2016.","key":"12_CR11","DOI":"10.15394\/jdfsl.2016.1379"},{"doi-asserted-by":"crossref","unstructured":"K. Joju and P. Lilly, Pre-image of Tillich-Z\u00e9mor hash function with new generators, Applied Mathematical Sciences, vol. 7(85), pp. 4237\u20134248, 2013.","key":"12_CR12","DOI":"10.12988\/ams.2013.36329"},{"unstructured":"K. Joju and P. Lilly, Improved form of Tillich-Z\u00e9mor hash function, International Journal of Theoretical Physics and Cryptography, vol. 6, pp. 24\u201329, 2014.","key":"12_CR13"},{"doi-asserted-by":"crossref","unstructured":"J. Kornblum, Identifying almost identical files using context-triggered piecewise hashing, Digital Investigation, vol. 3(S), pp. S91\u2013S97, 2006.","key":"12_CR14","DOI":"10.1016\/j.diin.2006.06.015"},{"unstructured":"National Institute of Standards and Technology, National Software Reference Library (NSRL), Gaithersburg, Maryland (www.nist.gov\/software-quality-group\/national-software-reference-library-nsrl), 2018.","key":"12_CR15"},{"doi-asserted-by":"crossref","unstructured":"J. Oliver, C. Cheng and Y. Chen, TLSH \u2013 A locality sensitive hash, Proceedings of the Fourth Cybercrime and Trustworthy Computing Workshop, pp. 7\u201313, 2013.","key":"12_CR16","DOI":"10.1109\/CTC.2013.9"},{"doi-asserted-by":"crossref","unstructured":"C. Petit and J. Quisquater, Pre-images for the Tillich-Z\u00e9mor hash function, Proceedings of the International Workshop on Selected Areas in Cryptography, pp. 282\u2013301, 2010.","key":"12_CR17","DOI":"10.1007\/978-3-642-19574-7_20"},{"doi-asserted-by":"crossref","unstructured":"V. Roussev, Data fingerprinting with similarity digests, in Advances in Digital Forensics VI, K. Chow and S. Shenoi (Eds.), Springer, Heidelberg, Germany, pp. 207\u2013226, 2010.","key":"12_CR18","DOI":"10.1007\/978-3-642-15506-2_15"},{"doi-asserted-by":"crossref","unstructured":"V. Roussev, An evaluation of forensic similarity hashes, Digital Investigation, vol. 8(S), pp. S34\u2013S41, 2011.","key":"12_CR19","DOI":"10.1016\/j.diin.2011.05.005"},{"unstructured":"A. Shrivastava and P. Li, In defense of MinHash over SimHash, Proceedings of the Seventeenth International Conference on Artificial Intelligence and Statistics, pp. 886\u2013894, 2014.","key":"12_CR20"},{"doi-asserted-by":"crossref","unstructured":"X. Shu and D. Yao, Data leak detection as a service, Proceedings of the International Conference on Security and Privacy in Communications Systems, pp. 222\u2013240, 2012.","key":"12_CR21","DOI":"10.1007\/978-3-642-36883-7_14"},{"doi-asserted-by":"crossref","unstructured":"J. Tillich and G. Z\u00e9mor, Hashing with $$SL_2$$, Proceedings of the International Cryptology Conference, pp. 40\u201349, 1994.","key":"12_CR22","DOI":"10.1007\/3-540-48658-5_5"},{"unstructured":"A. Tridgell, spamsum (github.com\/tridge\/junkcode\/tree\/master\/spamsum), 2002.","key":"12_CR23"},{"doi-asserted-by":"crossref","unstructured":"S. Wandelt, J. Wang, S. Gerdjikov, S. Mishra, P. Mitankin, M. Patil, E. Siragusa, A. Tiskin, W. Wang, J. Wang and U. Lesser, State-of-the-art in string similarity search and join, ACM SIGMOD Record, vol. 43(1), pp. 64\u201376, 2014.","key":"12_CR24","DOI":"10.1145\/2627692.2627706"},{"unstructured":"Wikipedia, Nilsimsa Hash (en.wikipedia.org\/wiki\/Nilsimsa\\_Hash), 2018.","key":"12_CR25"},{"doi-asserted-by":"crossref","unstructured":"C. Winter, M. Schneider and Y. Yannikos, F2S2: Fast forensic similarity search through indexing piecewise hash signatures, Digital Investigation, vol. 10(4), pp. 361\u2013371, 2013.","key":"12_CR26","DOI":"10.1016\/j.diin.2013.08.003"}],"container-title":["IFIP Advances in Information and Communication Technology","Advances in Digital Forensics XIV"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-99277-8_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,8,29]],"date-time":"2022-08-29T00:03:20Z","timestamp":1661731400000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-99277-8_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319992761","9783319992778"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-99277-8_12","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"30 August 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DigitalForensics","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on Digital Forensics","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New Delhi","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 January 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5 January 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"digitalforensics2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip119.org\/Conferences\/WG11-9-CFP-2018.pdf","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}