{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,21]],"date-time":"2025-04-21T04:26:25Z","timestamp":1745209585183},"publisher-location":"Berlin, Heidelberg","reference-count":20,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642380327"},{"type":"electronic","value":"9783642380334"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-642-38033-4_19","type":"book-chapter","created":{"date-parts":[[2013,5,7]],"date-time":"2013-05-07T00:51:00Z","timestamp":1367887860000},"page":"263-277","source":"Crossref","is-referenced-by-count":3,"title":["A Digital Forensic Framework for Automated User Activity Reconstruction"],"prefix":"10.1007","author":[{"given":"Jungin","family":"Kang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sangwook","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Heejo","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"19_CR1","unstructured":"Regional Computer Forensics Laboratory: Annual report for fiscal year 2003-2011 (2011)"},{"key":"19_CR2","doi-asserted-by":"crossref","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","volume":"7","author":"S.L. Garfinkel","year":"2010","unstructured":"Garfinkel, S.L.: Digital forensics research: The next 10 years. Digital Investigation\u00a07, S64\u2013S73 (2010)","journal-title":"Digital Investigation"},{"issue":"2","key":"19_CR3","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.diin.2007.06.019","volume":"4","author":"W.S. Dongen Van","year":"2007","unstructured":"Van Dongen, W.S.: Forensic artefacts left by Windows Live Messenger 8.0. Digital Investigation\u00a04(2), 73\u201387 (2007)","journal-title":"Digital Investigation"},{"key":"19_CR4","unstructured":"Palmer, G.: A road map for digital forensics research-report from the first Digital Forensics Research Workshop (DFRWS), Utica, New York (2001)"},{"issue":"3","key":"19_CR5","first-page":"1","volume":"2","author":"R. Rowlingson","year":"2004","unstructured":"Rowlingson, R.: A ten step process for forensic readiness. International Journal of Digital Evidence\u00a02(3), 1\u201328 (2004)","journal-title":"International Journal of Digital Evidence"},{"issue":"4","key":"19_CR6","first-page":"1","volume":"1","author":"B. Carrier","year":"2003","unstructured":"Carrier, B.: Defining digital forensic examination and analysis tools using abstraction layers. International Journal of Digital Evidence\u00a01(4), 1\u201312 (2003)","journal-title":"International Journal of Digital Evidence"},{"key":"19_CR7","unstructured":"EnCase forensic, \n                    \n                      http:\/\/www.guidancesoftware.com\/forensic.htm"},{"key":"19_CR8","unstructured":"Forensic toolkit, \n                    \n                      http:\/\/accessdata.com\/products\/computer-forensics\/ftk"},{"key":"19_CR9","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1016\/j.diin.2007.06.005","volume":"4","author":"N.L. Beebe","year":"2007","unstructured":"Beebe, N.L., Clark, J.G.: Digital forensic text string searching: Improving information retrieval effectiveness by thematically clustering search results. Digital Investigation\u00a04, 49\u201354 (2007)","journal-title":"Digital Investigation"},{"key":"19_CR10","unstructured":"log2timeline, \n                    \n                      http:\/\/log2timeline.net\/"},{"issue":"2","key":"19_CR11","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1145\/1113034.1113073","volume":"49","author":"S. Teelink","year":"2006","unstructured":"Teelink, S., Erbacher, R.F.: Improving the computer forensic analysis process through visualization. Communications of the ACM\u00a049(2), 71\u201375 (2006)","journal-title":"Communications of the ACM"},{"key":"19_CR12","doi-asserted-by":"crossref","unstructured":"Arnes, A., Haas, P., Vigna, G., Kemmerer, R.: Digital forensic reconstruction and the virtual security testbed ViSe. Detection of Intrusions and Malware & Vulnerability Assessment, 144\u2013163 (2006)","DOI":"10.1007\/11790754_9"},{"issue":"4","key":"19_CR13","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1016\/j.diin.2006.10.009","volume":"3","author":"J. Reust","year":"2006","unstructured":"Reust, J.: Case study: AOL instant messenger trace evidence. Digital Investigation\u00a03(4), 238\u2013243 (2006)","journal-title":"Digital Investigation"},{"issue":"1","key":"19_CR14","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.diin.2010.08.005","volume":"7","author":"M. Yasin","year":"2010","unstructured":"Yasin, M., Cheema, A.R., Kausar, F.: Analysis of Internet Download Manager for collection of digital forensic artefacts. Digital Investigation\u00a07(1), 90\u201394 (2010)","journal-title":"Digital Investigation"},{"issue":"2","key":"19_CR15","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1016\/j.diin.2005.04.006","volume":"2","author":"H. Carvey","year":"2005","unstructured":"Carvey, H., Altheide, C.: Tracking USB storage: Analysis of windows artifacts generated by USB storage devices. Digital Investigation\u00a02(2), 94\u2013100 (2005)","journal-title":"Digital Investigation"},{"key":"19_CR16","doi-asserted-by":"crossref","first-page":"S62","DOI":"10.1016\/j.diin.2011.05.008","volume":"8","author":"J. Oh","year":"2011","unstructured":"Oh, J., Lee, S., Lee, S.: Advanced evidence collection and analysis of web browser activity. Digital Investigation\u00a08, S62\u2013S70 (2011)","journal-title":"Digital Investigation"},{"key":"19_CR17","doi-asserted-by":"crossref","unstructured":"James, J.I., Gladyshev, P., Zhu, Y.: Signature Based Detection of User Events for Post-mortem Forensic Analysis. Digital Forensics and Cyber Crime, 96\u2013109 (2011)","DOI":"10.1007\/978-3-642-19513-6_8"},{"key":"19_CR18","doi-asserted-by":"crossref","first-page":"S69","DOI":"10.1016\/j.diin.2012.05.006","volume":"9","author":"C. Hargreaves","year":"2012","unstructured":"Hargreaves, C., Patterson, J.: An automated timeline reconstruction approach for digital forensic investigations. Digital Investigation\u00a09, S69\u2013S79 (2012)","journal-title":"Digital Investigation"},{"issue":"4","key":"19_CR19","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1145\/371578.371593","volume":"32","author":"D.M. Hilbert","year":"2000","unstructured":"Hilbert, D.M., Redmiles, D.F.: Extracting usability information from user interface events. ACM Computing Surveys (CSUR)\u00a032(4), 384\u2013421 (2000)","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"19_CR20","unstructured":"National Institute of standards and technology, National software reference library, \n                    \n                      http:\/\/www.nsrl.nist.gov\/"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-38033-4_19","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,12]],"date-time":"2019-05-12T22:01:46Z","timestamp":1557698506000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-38033-4_19"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783642380327","9783642380334"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-38033-4_19","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}