{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T07:48:34Z","timestamp":1772005714950,"version":"3.50.1"},"reference-count":26,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2012,4,1]],"date-time":"2012-04-01T00:00:00Z","timestamp":1333238400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2012,4]]},"DOI":"10.1109\/tifs.2011.2176117","type":"journal-article","created":{"date-parts":[[2011,11,17]],"date-time":"2011-11-17T20:47:27Z","timestamp":1321562847000},"page":"635-650","source":"Crossref","is-referenced-by-count":33,"title":["A System for Formal Digital Forensic Investigation Aware of Anti-Forensic Attacks"],"prefix":"10.1109","volume":"7","author":[{"given":"Slim","family":"Rekhis","sequence":"first","affiliation":[]},{"given":"Noureddine","family":"Boudriga","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","article-title":"Anti-forensics: Techniques, detection and countermeasures","author":"garfinkel","year":"2007","journal-title":"Proc 2nd Int Conf i-Warfare and Security (ICIW)"},{"key":"ref11","first-page":"10","article-title":"Anti-forensics: Breaking the forensic process","author":"whitteker","year":"2008","journal-title":"Inf Syst Security Assoc J"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1368506.1368514"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04062-7_16"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1113034.1113069"},{"key":"ref15","article-title":"Hypothesis-based investigation of digital timestamps","author":"willassen","year":"2008","journal-title":"Proc 4th Annu IFIP WG 11 9 Int Conf Digital Forensics"},{"key":"ref16","doi-asserted-by":"crossref","DOI":"10.4108\/e-forensics.2008.2637","article-title":"Timestamp evidence correlation by model based clock hypothesis testing","author":"willassen","year":"2008","journal-title":"Proc 1st Int Conf Forensic Applications and Techniques in Telecommunications Information and Multimedia"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2010.9"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.164"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2009.8"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254321"},{"key":"ref3","first-page":"1","article-title":"Modeling of post-incident root cause analysis","volume":"2","author":"stephenson","year":"2003","journal-title":"Int J Digital Evidence"},{"key":"ref6","author":"carrier","year":"2006","journal-title":"A Hypothesis-Based Approach to Digital Forensic Investigations"},{"key":"ref5","article-title":"Finite state machine analysis of a blackmail investigation","volume":"4","author":"gladyshev","year":"2005","journal-title":"Int J Digital Evidence"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2007.06.013"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.06.011"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2009.06.003"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2008.05.015"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.06.005"},{"key":"ref20","first-page":"1","article-title":"Getting physical with the digital investigation process","volume":"2","author":"carrier","year":"2003","journal-title":"Int J Digital Evidence"},{"key":"ref22","first-page":"163","article-title":"Mapping process of digital forensic investigation framework","volume":"8","author":"selamat 1","year":"2008","journal-title":"Int J Comput Sci Netw Security"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-01112-2_19"},{"key":"ref24","article-title":"A common process model for incident response and computer forensics","author":"freiling","year":"2007","journal-title":"Int Conf IT-Incident Management & IT-Forensics"},{"key":"ref23","article-title":"Event-based digital forensic investigation framework","author":"carrier","year":"2004","journal-title":"Proc Digital Forensics Research Workshop"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2006.305"},{"key":"ref25","author":"lamport","year":"2002","journal-title":"Specifying Systems The TLA Language and Tools for Hardware and Software Engineers"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/10206\/6166811\/06081933.pdf?arnumber=6081933","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,10]],"date-time":"2021-10-10T23:52:04Z","timestamp":1633909924000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6081933\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,4]]},"references-count":26,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2011.2176117","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,4]]}}}