{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T18:31:44Z","timestamp":1761676304064,"version":"3.37.3"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2015,12,1]],"date-time":"2015-12-01T00:00:00Z","timestamp":1448928000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-15-1-2396","N00014-15-1-2012"],"award-info":[{"award-number":["N00014-15-1-2396","N00014-15-1-2012"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National 973 Program of China","award":["2013CB338001"],"award-info":[{"award-number":["2013CB338001"]}]},{"name":"Strategy Pilot Project of Chinese Academy of Sciences","award":["XDA06010702"],"award-info":[{"award-number":["XDA06010702"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2015,12]]},"DOI":"10.1109\/tifs.2015.2467356","type":"journal-article","created":{"date-parts":[[2015,8,13]],"date-time":"2015-08-13T21:40:13Z","timestamp":1439502013000},"page":"2547-2561","source":"Crossref","is-referenced-by-count":10,"title":["Reliable and Trustworthy Memory Acquisition on Smartphones"],"prefix":"10.1109","volume":"10","author":[{"given":"He","family":"Sun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kun","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuewu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23165"},{"key":"ref39","first-page":"71","article-title":"AdDroid: Privilege separation for applications and advertisers in Android","author":"pearce","year":"2012","journal-title":"Proc 7th ACM Symp Inf Comput Commun Secur (ASIACCS)"},{"key":"ref38","first-page":"393","article-title":"TaintDroid: An information-flow tracking system for realtime privacy monitoring on smartphones","author":"enck","year":"2010","journal-title":"Proc of USENIX Symp on Operating Systems Design and Implementation (OSDI)"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23049"},{"journal-title":"Cortex-M3 Devices Generic User Guide","year":"0","key":"ref32"},{"journal-title":"Interrupt Behavior of Cortex-M1","year":"0","key":"ref31"},{"journal-title":"ARM Cortex-A15 MPCore Processor Technical Reference Manual","year":"0","key":"ref30"},{"journal-title":"Suterusu Rootkit Inline Kernel Function Hooking on x86 and ARM","year":"0","key":"ref37"},{"journal-title":"PolarSSL","year":"0","author":"bakker","key":"ref36"},{"journal-title":"Android Debug Bridge","year":"0","key":"ref35"},{"journal-title":"Reference BSPs for Freescale i MX53 Quick Start Board","year":"0","key":"ref34"},{"key":"ref60","first-page":"1","article-title":"Internal forensic acquisition for mobile equipments","author":"me","year":"2008","journal-title":"Proc IEEE IPDPS"},{"journal-title":"Trusted Foundations by Trusted Logic Mobility","year":"0","key":"ref62"},{"journal-title":"MobiCore","year":"0","key":"ref61"},{"key":"ref63","first-page":"104","article-title":"On-board credentials with open provisioning","author":"kostiainen","year":"2009","journal-title":"Proc ACM Symp Inf Comput Commun Secur (ASIACCS)"},{"journal-title":"Cortex-A8 Technical Reference Manual","year":"0","key":"ref28"},{"key":"ref64","first-page":"1497","article-title":"Trusted execution environments on mobile devices","author":"ekberg","year":"2013","journal-title":"Proc ACM SIGSAC Conf Comput Commun Secur (CCS)"},{"key":"ref27","first-page":"202","article-title":"TrustDump: Reliable memory acquisition on smartphones","author":"sun","year":"2014","journal-title":"Proc European Symp Research in Computer Security (ESORICS)"},{"journal-title":"White Paper An Overview of Samsung Knox","year":"0","key":"ref65"},{"key":"ref66","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2015.23189","article-title":"SeCReT: Secure channel between rich execution environment and trusted execution environment","author":"jang","year":"2015","journal-title":"Proc 21st Annu Netw Distrib Syst Secur Symp (NDSS)"},{"journal-title":"Cortex-A9 Technical Reference Manual","year":"0","key":"ref29"},{"journal-title":"Android Forensics Investigation Analysis and Mobile Security for Google Android","year":"2011","author":"hoog","key":"ref67"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660350"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541949"},{"key":"ref2","first-page":"481","article-title":"Eureka: A framework for enabling static malware analysis","author":"sharif","year":"2008","journal-title":"Proc European Symp Research in Computer Security (ESORICS)"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2089125.2089126"},{"journal-title":"TrustZone Introduction","year":"0","key":"ref20"},{"journal-title":"Autopsy Open Source Digital Forensics","year":"0","key":"ref22"},{"key":"ref21","first-page":"18","article-title":"TrustZone: Integrated hardware and software security","volume":"3","author":"alves","year":"2004","journal-title":"ARM White paper"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2010.05.010"},{"journal-title":"Volatility-An Advanced Memory Forensics Framework","year":"0","key":"ref23"},{"journal-title":"MX53 Reference Manual With Fusemap Addendum","year":"0","key":"ref26"},{"journal-title":"IMX53QSB i MX53 Quick Start Board","year":"0","key":"ref25"},{"key":"ref50","article-title":"KVM for ARM","author":"dall","year":"2010","journal-title":"Proc 12th Annu Linux Symp"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/2541940.2541946"},{"key":"ref59","article-title":"Android forensics techniques","author":"jovanovic","year":"2012","journal-title":"Int Acad Design Technol"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.01.003"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420962"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2003.12.001"},{"key":"ref55","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/978-3-642-41284-4_2","article-title":"Hypervisor memory forensics","author":"graziano","year":"2013","journal-title":"Proc 16th Int Symp Res Attacks Intrusions Defenses (RAID)"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.134"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICMA.2014.6885969"},{"key":"ref52","article-title":"Virtualization dungeon on ARM","author":"kalkowski","year":"2014","journal-title":"Proceedings of Free and Open Source Software Developer?s European Meeting (FOSDEM)"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"ref40","article-title":"Towards taming privilege-escalation attacks on Android","author":"bugiel","year":"2012","journal-title":"Proc 19th Annu Netw Distrib Syst Security Symp (NDSS)"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"ref13","first-page":"29","article-title":"DroidScope: Seamlessly reconstructing the OS and Dalvik semantic views for dynamic Android malware analysis","author":"yan","year":"2012","journal-title":"Proc 21th USENIX Secur Symp"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1352592.1352625"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.17"},{"key":"ref16","first-page":"14","article-title":"Cloud terminal: Secure access to sensitive applications from untrusted systems","author":"martignoni","year":"2012","journal-title":"Proc USENIX Conf Annu Tech Conf"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866313"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046752"},{"key":"ref19","first-page":"267","article-title":"Shielding applications from an untrusted cloud with haven","author":"baumann","year":"2014","journal-title":"Proc of USENIX Symp on Operating Systems Design and Implementation (OSDI)"},{"key":"ref4","first-page":"517","article-title":"Mining malware specifications through static reachability analysis","author":"macedo","year":"2013","journal-title":"Proc European Symp Research in Computer Security (ESORICS)"},{"key":"ref3","first-page":"353","article-title":"DroidAlarm: An all-sided static analysis tool for Android privilege-escalation malware","author":"zhongyang","year":"2013","journal-title":"Proc 8th ACM Symp Inf Comput Commun Secur (ASIA CCS)"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2421000"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420979"},{"key":"ref8","first-page":"1","article-title":"CopperDroid: Automatic reconstruction of Android malware behaviors","author":"tam","year":"2015","journal-title":"Proc 22nd Annu Netw Distrib Syst Secur Symp (NDSS)"},{"key":"ref7","first-page":"287","article-title":"Barecloud: Bare-metal analysis-based evasive malware detection","author":"kirat","year":"2014","journal-title":"Proc 23rd USENIX Secur Symp"},{"journal-title":"Boot Into Recovery Mode&#x2014;For Rooted and Un-Rooted Android Devices","year":"0","author":"stevenson","key":"ref49"},{"key":"ref9","first-page":"128","article-title":"Stealthy malware detection through VMM-based &#x2018;out-of-the-box&#x2019; semantic view reconstruction","author":"jiang","year":"2007","journal-title":"Proc 14th ACM Conf Comput Commun Secur"},{"key":"ref46","article-title":"Procedures and tools for acquisition and analysis of volatile memory on Android smartphones","author":"heriyanto","year":"2013","journal-title":"Proc 11th Austral Digit Forensics Conf"},{"journal-title":"White Paper Red Hat Crash Utility","year":"2008","author":"anderson","key":"ref45"},{"journal-title":"Using DDMS for Debugging","year":"0","key":"ref48"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2011.10.003"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.11"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653691"},{"article-title":"Entrapment: Tricking malware with transparent, scalable malware analysis","year":"0","author":"royal","key":"ref44"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/7277179\/07185414.pdf?arnumber=7185414","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:03:08Z","timestamp":1642003388000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/7185414\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,12]]},"references-count":70,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tifs.2015.2467356","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2015,12]]}}}