{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T22:23:03Z","timestamp":1761862983813,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2010,12,6]],"date-time":"2010-12-06T00:00:00Z","timestamp":1291593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000015","name":"U.S. Department of Energy","doi-asserted-by":"publisher","award":["DE-OE0000097"],"award-info":[{"award-number":["DE-OE0000097"]}],"id":[{"id":"10.13039\/100000015","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2010,12,6]]},"DOI":"10.1145\/1920261.1920307","type":"proceedings-article","created":{"date-parts":[[2010,12,20]],"date-time":"2010-12-20T16:13:47Z","timestamp":1292861627000},"page":"307-316","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Forenscope"],"prefix":"10.1145","author":[{"given":"Ellick","family":"Chan","sequence":"first","affiliation":[{"name":"University of Illinois"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shivaram","family":"Venkataraman","sequence":"additional","affiliation":[{"name":"University of Illinois"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francis","family":"David","sequence":"additional","affiliation":[{"name":"Microsoft"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amey","family":"Chaugule","sequence":"additional","affiliation":[{"name":"University of Illinois"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roy","family":"Campbell","sequence":"additional","affiliation":[{"name":"University of Illinois"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2010,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"SANS Top 7 New IR\/Forensic Trends In 2008. http:\/\/computer-forensics.sans.org\/community\/top7_forensic_trends.php.  SANS Top 7 New IR\/Forensic Trends In 2008. http:\/\/computer-forensics.sans.org\/community\/top7_forensic_trends.php."},{"key":"e_1_3_2_1_2_1","unstructured":"Columbia Pictures Indus. v. Bunnell U.S. Dist. LEXIS 46364. C.D. Cal. http:\/\/www.eff.org\/cases\/columbia-pictures-industries-v-bunnell 2007.  Columbia Pictures Indus. v. Bunnell U.S. Dist. LEXIS 46364. C.D. Cal. http:\/\/www.eff.org\/cases\/columbia-pictures-industries-v-bunnell 2007."},{"key":"e_1_3_2_1_3_1","unstructured":"Prosecuting Computer Crimes pages 141--142. US Department of Justice 2007. Prosecuting Computer Crimes pages 141--142. US Department of Justice 2007."},{"key":"e_1_3_2_1_4_1","first-page":"25","volume-title":"A Guide for First Responders","author":"Scene Investigation Electronic Crime","year":"2008","unstructured":"Electronic Crime Scene Investigation : A Guide for First Responders . pages 25 -- 27 , 2008 . Electronic Crime Scene Investigation: A Guide for First Responders. pages 25--27, 2008."},{"key":"e_1_3_2_1_5_1","unstructured":"Ramdisks - Now We are Talking Hyperspace! http:\/\/www.linux-mag.com\/cache\/7388\/1.html 2009.  Ramdisks - Now We are Talking Hyperspace! http:\/\/www.linux-mag.com\/cache\/7388\/1.html 2009."},{"key":"e_1_3_2_1_6_1","unstructured":"Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations pages 79 89. Computer Crime and Intellectual Property Section Criminal Division 2009. Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations pages 79 89. Computer Crime and Intellectual Property Section Criminal Division 2009."},{"key":"e_1_3_2_1_7_1","volume-title":"Techniques and Tools for Recovering and Analyzing Data from Volatile Memory","author":"Amari K.","year":"2009","unstructured":"K. Amari . Techniques and Tools for Recovering and Analyzing Data from Volatile Memory , 2009 . K. Amari. Techniques and Tools for Recovering and Analyzing Data from Volatile Memory, 2009."},{"key":"e_1_3_2_1_8_1","volume-title":"Feb.","author":"Brezinski D.","year":"2002","unstructured":"D. Brezinski and T. Killalea . Guidelines for Evidence Collection and Archiving. RFC 3227 (Best Current Practice) , Feb. 2002 . D. Brezinski and T. Killalea. Guidelines for Evidence Collection and Archiving. RFC 3227 (Best Current Practice), Feb. 2002."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653729"},{"key":"e_1_3_2_1_10_1","unstructured":"C. C. Center. How the FBI Investigates Computer Crime. http:\/\/www.cert.org\/tech_tips\/FBI_investigates_crime.html 2004.  C. C. Center. How the FBI Investigates Computer Crime. http:\/\/www.cert.org\/tech_tips\/FBI_investigates_crime.html 2004."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455840"},{"key":"e_1_3_2_1_12_1","volume-title":"BlackHat Briefings USA","author":"Zovi D. Dai","year":"2006","unstructured":"D. Dai Zovi . Hardware Virtualization Rootkits . BlackHat Briefings USA , August , 2006 . D. Dai Zovi. Hardware Virtualization Rootkits. BlackHat Briefings USA, August, 2006."},{"key":"e_1_3_2_1_13_1","volume-title":"USENIX Annual Technical Conference","author":"David F. M.","year":"2007","unstructured":"F. M. David , J. C. Carlyle , and R. H. Campbell . Exploring Recovery from Operating System Lockups . In USENIX Annual Technical Conference , Santa Clara, CA , June 2007 . F. M. David, J. C. Carlyle, and R. H. Campbell. Exploring Recovery from Operating System Lockups. In USENIX Annual Technical Conference, Santa Clara, CA, June 2007."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2007.06.008"},{"key":"e_1_3_2_1_15_1","unstructured":"Edge Jake. DR rootkit released under the GPL. http:\/\/lwn.net\/Articles\/297775\/.  Edge Jake. DR rootkit released under the GPL. http:\/\/lwn.net\/Articles\/297775\/."},{"key":"e_1_3_2_1_16_1","unstructured":"Fuzen Op. The FU rootkit. http:\/\/www.rootkit.com\/project.php?id=12.  Fuzen Op. The FU rootkit. http:\/\/www.rootkit.com\/project.php?id=12."},{"key":"e_1_3_2_1_17_1","volume-title":"Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI)","author":"Garfinkel T.","year":"2007","unstructured":"T. Garfinkel , K. Adams , A. Warfield , and J. Franklin . Compatibility is not transparency: VMM detection myths and realities . In Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI) , May 2007 . T. Garfinkel, K. Adams, A. Warfield, and J. Franklin. Compatibility is not transparency: VMM detection myths and realities. In Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI), May 2007."},{"key":"e_1_3_2_1_18_1","first-page":"77","volume-title":"Proceedings of the 6th USENIX Security Symposium","author":"Gutmann P.","year":"1996","unstructured":"P. Gutmann . Secure Deletion of Data from Magnetic and Solid-State Memory . In Proceedings of the 6th USENIX Security Symposium , pages 77 -- 90 , July 1996 . P. Gutmann. Secure Deletion of Data from Magnetic and Solid-State Memory. In Proceedings of the 6th USENIX Security Symposium, pages 77--90, July 1996."},{"key":"e_1_3_2_1_19_1","volume-title":"Proc of the 17th USENIX Security Symposium","author":"Halderman J. A.","year":"2008","unstructured":"J. A. Halderman , S. D. Schoen , N. Heninger , W. Clarkson , W. Paul , and J. A. Calandrino . Lest We Remember: Cold Boot Attacks on Encryption Keys . In Proc of the 17th USENIX Security Symposium , San Jose, CA , July 2008 . J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson, W. Paul, and J. A. Calandrino. Lest We Remember: Cold Boot Attacks on Encryption Keys. In Proc of the 17th USENIX Security Symposium, San Jose, CA, July 2008."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"e_1_3_2_1_21_1","first-page":"33","volume-title":"Archiv fur Elektronik und Ubertragungstechnik","author":"Link W.","year":"1979","unstructured":"W. Link and H. May . Eigenshaften von MOS-Ein-Transistorspeicherzellen bei tieften Temperaturen . In Archiv fur Elektronik und Ubertragungstechnik , pages 33 - 229 -235, June 1979 . W. Link and H. May. Eigenshaften von MOS-Ein-Transistorspeicherzellen bei tieften Temperaturen. In Archiv fur Elektronik und Ubertragungstechnik, pages 33-229-235, June 1979."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.10"},{"key":"e_1_3_2_1_23_1","first-page":"179","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Petroni N.","year":"2004","unstructured":"N. Petroni , T. Fraser , J. Molina , and W. Arbaugh . Copilot-A Coprocessor-based Kernel Runtime Integrity Monitor . In Proceedings of the 13th USENIX Security Symposium , pages 179 -- 194 , 2004 . N. Petroni, T. Fraser, J. Molina, and W. Arbaugh. Copilot-A Coprocessor-based Kernel Runtime Integrity Monitor. In Proceedings of the 13th USENIX Security Symposium, pages 179--194, 2004."},{"key":"e_1_3_2_1_24_1","volume-title":"Infoworld","author":"Pournelle J.","year":"1988","unstructured":"J. Pournelle . OS | 2 : What is is, What is isn't -- and some of the Alternatives . Infoworld , 1988 . J. Pournelle. OS | 2: What is is, What is isn't -- and some of the Alternatives. Infoworld, 1988."},{"key":"e_1_3_2_1_25_1","first-page":"39","volume":"1","author":"Rozier M.","year":"1991","unstructured":"M. Rozier , V. Abrossimov , F. Armand , I. Boule , M. Gien , M. Guillemont , F. Herrmann , C. Kaiser , S. Langlois , P. Lonard , and W. Neuhauser . Overview of the CHORUS Distributed Operating Systems. Computing Systems , 1 : 39 -- 69 , 1991 . M. Rozier, V. Abrossimov, F. Armand, I. Boule, M. Gien, M. Guillemont, F. Herrmann, C. Kaiser, S. Langlois, P. Lonard, and W. Neuhauser. Overview of the CHORUS Distributed Operating Systems. Computing Systems, 1:39--69, 1991.","journal-title":"Overview of the CHORUS Distributed Operating Systems. Computing Systems"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02633-1_16"},{"key":"e_1_3_2_1_27_1","volume-title":"Searching for Processes and Threads in Microsoft Windows Memory Dumps. The Proceedings of the 6th Annual Digital Forensics Research Workshop","author":"Schuster A.","year":"2006","unstructured":"A. Schuster . Searching for Processes and Threads in Microsoft Windows Memory Dumps. The Proceedings of the 6th Annual Digital Forensics Research Workshop , 2006 . A. Schuster. Searching for Processes and Threads in Microsoft Windows Memory Dumps. The Proceedings of the 6th Annual Digital Forensics Research Workshop, 2006."},{"key":"e_1_3_2_1_28_1","unstructured":"S. Sparks and J. Butler. Raising The Bar for Windows Rootkit Detection. Phrack 2005 11 63"},{"key":"e_1_3_2_1_29_1","unstructured":"D. A. Wheeler. SLOCCount. http:\/\/www.dwheeler.com\/sloccount.  D. A. Wheeler. SLOCCount. http:\/\/www.dwheeler.com\/sloccount."},{"key":"e_1_3_2_1_30_1","unstructured":"B. Zdrnja. More tricks from Conficker and VM detection. http:\/\/isc.sans.org\/diary.html?storyid=5842 2009.  B. Zdrnja. More tricks from Conficker and VM detection. http:\/\/isc.sans.org\/diary.html?storyid=5842 2009."}],"event":{"name":"ACSAC '10: 2010 Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Austin Texas USA","acronym":"ACSAC '10"},"container-title":["Proceedings of the 26th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920307","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1920261.1920307","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:59:43Z","timestamp":1750244383000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1920261.1920307"}},"subtitle":["a framework for live forensics"],"short-title":[],"issued":{"date-parts":[[2010,12,6]]},"references-count":30,"alternative-id":["10.1145\/1920261.1920307","10.1145\/1920261"],"URL":"https:\/\/doi.org\/10.1145\/1920261.1920307","relation":{},"subject":[],"published":{"date-parts":[[2010,12,6]]},"assertion":[{"value":"2010-12-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}