{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T13:58:27Z","timestamp":1760623107142,"version":"3.28.0"},"reference-count":27,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,10]]},"DOI":"10.1109\/ccst.2018.8585490","type":"proceedings-article","created":{"date-parts":[[2018,12,24]],"date-time":"2018-12-24T23:55:13Z","timestamp":1545695713000},"page":"1-6","source":"Crossref","is-referenced-by-count":2,"title":["The Next Generation of Robust Linux Memory Acquisition Technique via Sequential Memory Dumps at Designated Time Intervals"],"prefix":"10.1109","author":[{"given":"Saeed Shafiee","family":"Hasanabadi","sequence":"first","affiliation":[]},{"given":"Arash Habibi","family":"Lashkari","sequence":"additional","affiliation":[]},{"given":"Ali A.","family":"Ghorbani","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"journal-title":"Beyond the Cpu Defeating Hardware Based Ram Acquisition","year":"2007","author":"rutkowska","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.06.012"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1368506.1368516"},{"key":"ref13","first-page":"23","article-title":"Linux physical memory analysis","author":"movall","year":"2005","journal-title":"USENIX Annual Technical Conference Freenix track"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1113034.1113074"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.02.001"},{"key":"ref16","first-page":"305","article-title":"Forensic physical memory analysis: an overview of tools and techniques","author":"limon garcia","year":"2007","journal-title":"TKK T-110 5290 Seminar on Network Security"},{"key":"ref17","doi-asserted-by":"crossref","first-page":"65s","DOI":"10.1016\/j.diin.2008.05.008","article-title":"Face: Automated digital evidence discovery and correlation","volume":"5","author":"andrew","year":"2008","journal-title":"Digital Investigation"},{"journal-title":"Memory forensics over the IEEE 1394 interface","article-title":"Freddie Witherden","year":"2010","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2011.7"},{"key":"ref4","article-title":"Cardbus bus-mastering: Owning the laptop","volume":"6","author":"hulton","year":"2006","journal-title":"Proc ShmooCon"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.011"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2007.06.009"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-73614-1_12"},{"key":"ref5","article-title":"Physical security attacks on windows vista","author":"panholzer","year":"2008","journal-title":"SEC Consult Vulnerability Lab Vienna Tech Rep"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2016.04.006"},{"journal-title":"Memory dumping over firewire-uma issues","year":"2006","author":"vidstrom","key":"ref7"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2003.12.001"},{"key":"ref9","doi-asserted-by":"crossref","first-page":"23s","DOI":"10.1016\/j.diin.2016.04.009","article-title":"Robust bootstrapping memory analysis against anti-forensics","volume":"18","author":"kyoungho","year":"2016","journal-title":"Digital Investigation"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2011.06.002"},{"key":"ref20","first-page":"79","article-title":"When hardware meets software: a bulletproof solution to forensic memory acquisition","author":"alessandro","year":"2012","journal-title":"Proceedings of the 28th Annual Computer Security Applications Conference"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.06.004"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CSA.2009.5404199"},{"journal-title":"Digital forensic acquisition kit and methods of use thereof","year":"2014","author":"coulter","key":"ref24"},{"journal-title":"Test results for digital data acquisition tool tableau td3 forensic imager version 1 3 0","year":"2014","key":"ref23"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"87s","DOI":"10.1016\/j.diin.2016.04.004","article-title":"Deleting collected digital evidence by exploiting a widely adopted hardware write blocker","volume":"18","author":"christopher","year":"2016","journal-title":"Digital Investigation"},{"key":"ref25","first-page":"64s","volume":"7","author":"garfinkel","year":"2010","journal-title":"Digital Forensics Research The Next 10 Years Digital Investigation 7"}],"event":{"name":"2018 International Carnahan Conference on Security Technology (ICCST)","start":{"date-parts":[[2018,10,22]]},"location":"Montreal, QC","end":{"date-parts":[[2018,10,25]]}},"container-title":["2018 International Carnahan Conference on Security Technology (ICCST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8573569\/8585426\/08585490.pdf?arnumber=8585490","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,1,25]],"date-time":"2019-01-25T03:05:59Z","timestamp":1548385559000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8585490\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/ccst.2018.8585490","relation":{},"subject":[],"published":{"date-parts":[[2018,10]]}}}