{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T21:56:24Z","timestamp":1765230984214,"version":"build-2065373602"},"publisher-location":"Berlin, Heidelberg","reference-count":15,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642355141"},{"type":"electronic","value":"9783642355158"}],"license":[{"start":{"date-parts":[[2012,1,1]],"date-time":"2012-01-01T00:00:00Z","timestamp":1325376000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-35515-8_10","type":"book-chapter","created":{"date-parts":[[2012,11,22]],"date-time":"2012-11-22T16:36:13Z","timestamp":1353602173000},"page":"115-130","source":"Crossref","is-referenced-by-count":10,"title":["Finding Anomalous and Suspicious Files from Directory Metadata on a Large Corpus"],"prefix":"10.1007","author":[{"given":"Neil C.","family":"Rowe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Simson L.","family":"Garfinkel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"3","key":"10_CR1","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1145\/1288783.1288788","volume":"3","author":"N. Agrawal","year":"2007","unstructured":"Agrawal, N., Bolosky, W., Douceur, J., Lorch, J.: A Five-Year Study of File-System Metadata. ACM Transactions on Storage\u00a03(3), 9 (2007)","journal-title":"ACM Transactions on Storage"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Alsagoff, C.: Microsoft Excel as a Tool for Digital Forensic Accounting. In: Intl. Conf. on Information Retrieval and Management, Shah Alam, Malaysia, p. 97 (March 2010)","DOI":"10.1109\/INFRKM.2010.5466938"},{"key":"10_CR3","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1016\/j.diin.2004.10.002","volume":"1","author":"F. Buchholz","year":"2004","unstructured":"Buchholz, F., Spafford, E.: On the Role of File System Metadata in Digital Forensics. Digital Investigation\u00a01, 298\u2013309 (2004)","journal-title":"Digital Investigation"},{"key":"10_CR4","volume-title":"Cheating and Deception","author":"J. Bell","year":"1991","unstructured":"Bell, J., Whaley, B.: Cheating and Deception. Transaction Publishing, New York (1991)"},{"key":"10_CR5","unstructured":"Carrier, B., Spafford, E.: Automated Digital Evidence Target Definition Using Outlier Analysis and Existing Evidence. In: Proc. Fifth Digital Forensic Research Workshop (2005)"},{"key":"10_CR6","doi-asserted-by":"crossref","unstructured":"Doraimani, S., Iamnitchi, A.: File Grouping for Scientific Data Management: Lessons from Experimenting with Real Traces. In: Proc. HPDC 2008, Boston, MA (2008)","DOI":"10.1145\/1383422.1383429"},{"key":"10_CR7","doi-asserted-by":"crossref","unstructured":"Garfinkel, S.: Automating Disk Forensic Processing with SleuthKit, XML and Python. In: Proc. Systematic Approaches to Digital Forensics Engineering, Oakland, CA (2009)","DOI":"10.1109\/SADFE.2009.12"},{"key":"10_CR8","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1016\/j.diin.2009.06.016","volume":"6","author":"S. Garfinkel","year":"2009","unstructured":"Garfinkel, S., Farrell, P., Roussev, V., Dinolt, G.: Bringing Science to Digital Forensics with Standardized Forensic Corpora. Digital Investigation\u00a06, S2\u2013S11 (2009)","journal-title":"Digital Investigation"},{"key":"10_CR9","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.diin.2006.10.005","volume":"3","author":"E. Huebner","year":"2006","unstructured":"Huebner, E., Bem, D., Wee, C.: Data Hiding in the NTFS File System. Digital Investigation\u00a03, 211\u2013226 (2006)","journal-title":"Digital Investigation"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Lee, G., Lee, S., Tsomko, E., Lee, S.: Discovering Methodology and Scenario to Detect Covert Database System. In: Proc. Future Generation Communication and Networking, Jeju, China, p. 130 (December 2007)","DOI":"10.1109\/FGCN.2007.106"},{"key":"10_CR11","unstructured":"Munson, S.: Defense in Depth and the Home User: Securing the Home PC, \n                    \n                      http:\/\/www.sans.org\/reading_room\/hsoffice\/defense-in-depth-home-user-securing-home-pc_894"},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Naiqi, L., Zhongshan, W., Yujie, H.: QuiKe: Computer Forensics Research and Implementation Based on NTFS File System. In: Proc. Intl. Colloquium on Computing, Communication, Control, and Management, Guangzhou, China, pp. 519\u2013523 (August 2008)","DOI":"10.1109\/CCCM.2008.236"},{"key":"10_CR13","unstructured":"Rowe, N.: A Taxonomy of Deception in Cyberspace. In: Proc. Intl. Conf. on Information Warfare and Security, Princess Anne, MD, pp. 173-181 (March 2006)"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Rowe, N., Garfinkel, S.: Global Analysis of Disk File Times. In: Fifth International Workshop on Systematic Approaches to Digital Forensic Engineering, Oakland CA (May 2010)","DOI":"10.1109\/SADFE.2010.21"},{"key":"10_CR15","doi-asserted-by":"publisher","DOI":"10.1002\/9780470382776","volume-title":"Clustering","author":"R. Xu","year":"2008","unstructured":"Xu, R., Wunsch, D.: Clustering. Wiley-IEEE, New York (2008)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-35515-8_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,9]],"date-time":"2019-05-09T00:46:40Z","timestamp":1557362800000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-35515-8_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642355141","9783642355158"],"references-count":15,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-35515-8_10","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2012]]}}}