{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T18:17:20Z","timestamp":1761675440147,"version":"3.32.0"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2006,12,21]],"date-time":"2006-12-21T00:00:00Z","timestamp":1166659200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J Comput Virol"],"published-print":{"date-parts":[[2007,2,7]]},"DOI":"10.1007\/s11416-006-0033-x","type":"journal-article","created":{"date-parts":[[2006,12,20]],"date-time":"2006-12-20T10:04:34Z","timestamp":1166609074000},"page":"275-289","source":"Crossref","is-referenced-by-count":8,"title":["Using a virtual security testbed for digital forensic reconstruction"],"prefix":"10.1007","volume":"2","author":[{"given":"Andr\u00e9","family":"\u00c5rnes","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Haas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Richard A.","family":"Kemmerer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2006,12,21]]},"reference":[{"key":"33_CR1","unstructured":"Richmond, M.: ViSe: A virtual security testbed. Master\u2019s thesis, University of California, Santa Barbara (2005)"},{"key":"33_CR2","unstructured":"National Institute of Standards and Technology: (National software reference library (NSRL)) http:\/\/www.nsrl.nist.gov\/ index.html"},{"key":"33_CR3","unstructured":"Murilo, N., Steding-Jessen, K.: (chkrootkit\u2013locally checks for signs of a rootkit) http:\/\/www.chkrootkit.org\/"},{"key":"33_CR4","unstructured":"Harbour, N.: (dcfldd - latest version 1.3.4) http:\/\/dcfldd. sourceforge.net\/"},{"key":"33_CR5","unstructured":"Jacobson, V., Leres, C., McCanne, S.: (tcpdump\/libpcap) http:\/\/www.tcpdump.org\/"},{"key":"33_CR6","unstructured":"Betz, C.: (Memparser \u2013 a memory forensics analysis tool for microsoft windows systems) http:\/\/sourceforge.net\/projects\/memparser"},{"key":"33_CR7","unstructured":"Guidance Software, Inc.: Encase www.encase.com (2006)"},{"key":"33_CR8","unstructured":"Spencer, E.: ILook investigator toolsets www.ilook-forensics.org (2006)"},{"key":"33_CR9","unstructured":"Carrier, B.: The Sleuth Kit and Autopsy www.sleuthkit.org (2006)"},{"key":"33_CR10","unstructured":"AccessData: (Accessdata forensic toolkit (FTK)) http:\/\/www. accessdata.com\/products\/ftk\/"},{"key":"33_CR11","unstructured":"Filiol, E.: Strong cryptography armoured computer viruses forbidding code analysis: the bradley virus. In: EICAR2005 annual conference 14 (2005)"},{"key":"33_CR12","doi-asserted-by":"crossref","unstructured":"Carrier, B.D., Spafford, E.H.: Defining event reconstruction of digital crime scenes. J. Forensic Sci. 49 (2004)","DOI":"10.1520\/JFS2004127"},{"issue":"1","key":"33_CR13","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s11416-006-0018-9","volume":"2","author":"V. Broucek","year":"2006","unstructured":"Broucek V. and Turner P. (2006). Winning the battles, losing the war? rethinking methodology for forensic computing research. J. Compu. Virol. 2(1): 3\u201312","journal-title":"J. Compu. Virol."},{"key":"33_CR14","unstructured":"Chisum, W.J., Turvey, B.E.: Evidence dynamics: Locard\u2019s exchange principle crime reconstruction. J. Behav. Profiling 1(1) (2000)"},{"key":"33_CR15","unstructured":"O\u2019Connor, T.: Introduction to crime reconstruction. Lecture Notes for Criminal Investigation North Carolina Wesleyan College (2004)"},{"key":"33_CR16","doi-asserted-by":"crossref","unstructured":"Aitken, C., Taroni, F.: Statistics and the Evaluation of Evidence for Forensic Scientists. Wiley, London (2004)","DOI":"10.1002\/0470011238"},{"key":"33_CR17","unstructured":"Carney, M., Rogers, M.: The Trojan Made Me Do It: A first step in statistical based computer forensics event reconstruction. Int. J. Digit. Evid. 2 (2004)"},{"key":"33_CR18","unstructured":"Carrier, B.: An event-based digital forensic investigation framework. In: Digital forensic research workshop (2004)"},{"key":"33_CR19","doi-asserted-by":"crossref","unstructured":"Stephenson, P.: Formal modeling of post-incident root cause analysis. Int. J. Digit. Evid. 2 (2003)","DOI":"10.1016\/S1361-3723(03)04012-0"},{"key":"33_CR20","doi-asserted-by":"crossref","unstructured":"Gladyshev, P., Patel, A.: Finite state machine approach to digital event reconstruction. Digit. Invest. 1 (2004)","DOI":"10.1016\/S1742-2876(04)00027-1"},{"key":"33_CR21","unstructured":"Stallard, T.B.: Automated analysis for digital forensic science. Master\u2019s thesis, University of California, Davis (2002)"},{"key":"33_CR22","doi-asserted-by":"crossref","unstructured":"Stallard, T., Levitt, K.N.: Automated analysis for digital forensic science: Semantic integrity checking. In: ACSAC 160\u2013169 (2003)","DOI":"10.1109\/CSAC.2003.1254321"},{"key":"33_CR23","doi-asserted-by":"crossref","unstructured":"Abbott, J., Bell, J., Clark, A., Vel, O.D., Mohay, G.: Auto- mated recognition of event scenarios for digital forensics. In: SAC \u201906: Proceedings of the 2006 ACM symposium on applied computing pp. 293\u2013300. ACM Press, New York (2006)","DOI":"10.1145\/1141277.1141346"},{"key":"33_CR24","unstructured":"Elsaesser, C., Tanner, M.C.: Automated diagnosis for computer forensics. Technical report, The MITRE Corporation (2001)"},{"key":"33_CR25","unstructured":"Neuhaus, S., Zeller, A.: Isolating intrusions by automatic experiments. In: Proceedings of the 13th annual network and distributed system security symposium. pp. 71\u201380 (2006)"},{"key":"33_CR26","unstructured":"Baca, E.: Using linux VMware and SMART to create a virtual computer to recreate a suspect\u2019s computer www.linux-forensics.com (2003)"},{"key":"33_CR27","unstructured":"Provos, N.: The honeyd virtual honeypot www.honeyd.org (2005)"},{"key":"33_CR28","unstructured":"Honeynet Project: Know your enemy: Learning with VMware\u2013building virtual honeynets using VMware www.honeynet.org (2003)"},{"key":"33_CR29","unstructured":"Seifried, K.: Honeypotting with VMware www.seifried.org (2002)"},{"key":"33_CR30","doi-asserted-by":"crossref","unstructured":"Rossey, L., Cunningham, R., Fried, D., Rabek, J., Lippman, R., Haines, J., Zissman, M.: LARIAT: lincoln adaptable real-time information assurance testbed. In: 2002 IEEE aerospace conference proceedings (2002)","DOI":"10.1109\/AERO.2002.1036158"},{"key":"33_CR31","unstructured":"Haines, J., Goulet, S., Durst, R., Champion, T.: Llsim: Network simulation for correlation and response testing. In: IEEE workshop on information assurance, West Point (2003)"},{"key":"33_CR32","doi-asserted-by":"crossref","unstructured":"White, B., Lepreau, J., Stoller, L., Ricci, R., Guruprasad, S., Newbold, M., Hibler, M., Barb, C., Joglekar, A.: An integrated experimental environment for distributed systems and networks. In: 5th symposium on operating systems design and implementation. USENIX Association, Boston 255\u2013260 (2002)","DOI":"10.1145\/1060289.1060313"},{"key":"33_CR33","unstructured":"The DETER project: The DETER Testbed: Overview www.isi.edu\/deter (2004)"},{"key":"33_CR34","doi-asserted-by":"crossref","unstructured":"Jiang, X., Xu, D., Wang, H., Spafford, E.: Virtual playgrounds for worm behavior investigation. In: 8th International symposium on recent advances in intrusion detection, Seattle (2005)","DOI":"10.1007\/11663812_1"},{"key":"33_CR35","unstructured":"Dike, J.: User mode linux user-mode-linux.sourceforge.net (2005)"},{"key":"33_CR36","doi-asserted-by":"crossref","unstructured":"\u00c5rnes, A., Haas, P., Vigna, G., Kemmerer, R.A.: Digital forensic reconstruction and the virtual security testbed ViSe. In: proceedings of conference on detection of intrusions and malware and vulnerability assessment (DIMVA), LNCS 4064, Springer, Berlin Heidelberg New York (2006)","DOI":"10.1007\/11790754_9"},{"key":"33_CR37","unstructured":"Vada, H.: Rekonstruksjon av angrep mot IKT-systemer (reconstruction of attacks on ICT systems). Master\u2019s thesis, Norwegian University of Science and Technology, Trondheim, Norway (2004)"},{"key":"33_CR38","unstructured":"VMware: VMware 5.0 manual www.vmware.com (2005)"},{"key":"33_CR39","unstructured":"University of Cambridge Computer Laboratory: The Xen virtual machine monitor http:\/\/www.cl.cam.ac.uk\/ (2005)"},{"key":"33_CR40","unstructured":"Microsoft: Microsoft Virtual PC www.microsoft.com (2004)"},{"key":"33_CR41","unstructured":"The open web application security project: The ten most critical web application security vulnerabilities. Technical report, OWASP (2004)"},{"key":"33_CR42","unstructured":"Wang, X., Feng, D., Lai, X., Yu, H.: Collisions for hash functions MD4, MD5, HAVAL-128 and RIPEMD. Cryptology ePrint Archive, Report 2004\/199 (2004)"},{"key":"33_CR43","unstructured":"Honeynet Project: Detecting VMware www.honeynet.org (2005)"},{"key":"33_CR44","unstructured":"Shelton, T.: VMware Flaw in NAT Function Lets Remote Users Execute Arbitrary Code (2005) securitytracker.com"},{"key":"33_CR45","unstructured":"Cuff, A.: Talisker Anti Forensic Tools www.networkintrusion.co.uk (2004)"},{"key":"33_CR46","doi-asserted-by":"crossref","unstructured":"Leyden, J.: Trojan defence clears man on child porn charges http:\/\/www.theregister.co.uk\/2003\/04\/24\/trojan_defence_clears_man\/(2003)","DOI":"10.1016\/S1353-4858(03)00007-2"},{"key":"33_CR47","unstructured":"Rasch, M.: The giant wooden horse did it! http:\/\/www.securityfocus.com\/columnists\/208 (2004)"},{"key":"33_CR48","unstructured":"CERT: CERT Advisory CA-2003-20 W32\/Blaster worm http:\/\/www.cert.org\/advisories\/CA-2003-20.html (2003)"},{"key":"33_CR49","unstructured":"ronvdaal@zarathustra.linux666.com: PHPBB Viewtopic.PHP remote code execution vulnerability Bugtraq ID 14086 (2005)"},{"key":"33_CR50","unstructured":"aXiS: IWConfig Local ARGV command line buffer overflow vulnerability Bugtraq ID 8901 (2003)"},{"key":"33_CR51","unstructured":"Vozeler, M.: CDRTools RSH environment variable privilege escalation vulnerability Bugtraq ID 11075 (2004)"}],"container-title":["Journal in Computer Virology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-006-0033-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-006-0033-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-006-0033-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,12]],"date-time":"2025-01-12T17:34:36Z","timestamp":1736703276000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-006-0033-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,12,21]]},"references-count":51,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2007,2,7]]}},"alternative-id":["33"],"URL":"https:\/\/doi.org\/10.1007\/s11416-006-0033-x","relation":{},"ISSN":["1772-9890","1772-9904"],"issn-type":[{"type":"print","value":"1772-9890"},{"type":"electronic","value":"1772-9904"}],"subject":[],"published":{"date-parts":[[2006,12,21]]}}}