{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T11:30:44Z","timestamp":1725622244446},"publisher-location":"Berlin, Heidelberg","reference-count":8,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642236013"},{"type":"electronic","value":"9783642236020"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-23602-0_8","type":"book-chapter","created":{"date-parts":[[2011,10,18]],"date-time":"2011-10-18T00:31:35Z","timestamp":1318897895000},"page":"90-98","source":"Crossref","is-referenced-by-count":2,"title":["Network Connections Information Extraction of 64-Bit Windows 7 Memory Images"],"prefix":"10.1007","author":[{"given":"Lianhai","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lijuan","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuhui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"8_CR1","doi-asserted-by":"crossref","unstructured":"Wang, L., Zhang, R., Zhang, S.: A Model of Computer Live Forensics Based on Physical Memory Analysis. In: ICISE 2009, Nanjing China (December 2009)","DOI":"10.1109\/ICISE.2009.69"},{"key":"8_CR2","doi-asserted-by":"crossref","unstructured":"Schuster, A.: Searching for Processes and Threads in Microsoft Windows Memory Dumps. In: Proceedings of the 2006 Digital Forensic Research Workshop, DFRWS (2006)","DOI":"10.1016\/j.diin.2006.06.010"},{"key":"8_CR3","unstructured":"Burdach, M.: An Introduction to Windows Memory Forensic[OL] (July 2005), \n                  \n                    http:\/\/forensic.seccure.net\/pdf\/introduction_to_windows_memory_forensic.pdf"},{"key":"8_CR4","unstructured":"Burdachz, M.: Digital Forensics of the Physical Memory [OL] (March 2005), \n                  \n                    http:\/\/forensic.seccure.net\/pdf\/mburdach_digital_forensics_of_physical_memory.pdf"},{"key":"8_CR5","unstructured":"Walters, A., Petronni Jr., N.L.: Volatools: Integrating volatile Memory Forensics into the Digital Investigation Process. In: Black Hat DC (2007)"},{"key":"8_CR6","unstructured":"Volatile Systems: The Volatility Framework: Volatile memory artifact extraction utility framework (accessed, June 2009), \n                  \n                    https:\/\/www.volatilesystems.com\/default\/volatility\/"},{"key":"8_CR7","unstructured":"Andreas, S.: Pool allocations as an information source in windows memory forensics. In: Oliver, G., Dirk, S., Sandra, F., Hardo, H., Detlef, G., Jens, N. (eds.) IT-incident management & IT-forensics-IMF 2006, October 18. Lecture notes in informatics, vol.\u00a0P-97, pp. 104\u2013115 (2006b)"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Zhang, R., Wang, L., Zhang, S.: Windows Memory Analysis Based on KPCR. In: Fifth International Conference on Information Assurance and Security, IAS 2009, vol.\u00a02, pp. 677\u2013680 (2009)","DOI":"10.1109\/IAS.2009.103"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Forensics in Telecommunications, Information, and Multimedia"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-23602-0_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,4,12]],"date-time":"2019-04-12T19:01:20Z","timestamp":1555095680000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-23602-0_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642236013","9783642236020"],"references-count":8,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-23602-0_8","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2011]]}}}