{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T14:34:24Z","timestamp":1775745264618,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":14,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,8,27]],"date-time":"2018-08-27T00:00:00Z","timestamp":1535328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,8,27]]},"DOI":"10.1145\/3230833.3232808","type":"proceedings-article","created":{"date-parts":[[2018,8,13]],"date-time":"2018-08-13T12:29:48Z","timestamp":1534163388000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Forensic APFS File Recovery"],"prefix":"10.1145","author":[{"given":"Jonas","family":"Plum","sequence":"first","affiliation":[{"name":"Siemens AG, M\u00fcnchen"}]},{"given":"Andreas","family":"Dewald","sequence":"additional","affiliation":[{"name":"ERNW Research GmbH, Heidelberg"}]}],"member":"320","published-online":{"date-parts":[[2018,8,27]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Future Information Technology, James J. (Jong Hyuk) Park","author":"Alghafli Khawla","unstructured":"Khawla Alghafli , Andrew Jones , and Thomas Martin . 2014. Investigating and Measuring Capabilities of the Forensics File Carving Techniques . In Future Information Technology, James J. (Jong Hyuk) Park , Ivan Stojmenovic, Min Choi, and Fatos Xhafa (Eds.). Springer Berlin Heidelberg , Berlin, Heidelberg , 329--336. Khawla Alghafli, Andrew Jones, and Thomas Martin. 2014. Investigating and Measuring Capabilities of the Forensics File Carving Techniques. In Future Information Technology, James J. (Jong Hyuk) Park, Ivan Stojmenovic, Min Choi, and Fatos Xhafa (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 329--336."},{"key":"e_1_3_2_1_2_1","unstructured":"Apple Inc. 2017. Apple File System Guide. https:\/\/developer.apple.com\/library\/content\/documentation\/FileManagement\/Conceptual\/APFS_Guide\/Introduction\/Introduction.html (last visited: 2018-01-10).  Apple Inc. 2017. Apple File System Guide. https:\/\/developer.apple.com\/library\/content\/documentation\/FileManagement\/Conceptual\/APFS_Guide\/Introduction\/Introduction.html (last visited: 2018-01-10)."},{"key":"e_1_3_2_1_3_1","unstructured":"Orlando Bassotto. 2017. APFS lib. https:\/\/github.com\/tienex\/apfs\/ (last visited: 2018-04-15).  Orlando Bassotto. 2017. APFS lib. https:\/\/github.com\/tienex\/apfs\/ (last visited: 2018-04-15)."},{"key":"e_1_3_2_1_4_1","volume-title":"File system forensic analysis","author":"Carrier Brian","unstructured":"Brian Carrier . 2005. File system forensic analysis . Addison-Wesley Professional , USA. Brian Carrier. 2005. File system forensic analysis. Addison-Wesley Professional, USA."},{"key":"e_1_3_2_1_5_1","unstructured":"A. Dewald and J. Plum. 2018. APFS INTERNALS FOR FORENSIC ANALYSIS. https:\/\/static.ernw.de\/whitepaper\/ERNW_Whitepaper65_APFS-forensics_signed.pdf (last visited: 2018-06-20).  A. Dewald and J. Plum. 2018. APFS INTERNALS FOR FORENSIC ANALYSIS. https:\/\/static.ernw.de\/whitepaper\/ERNW_Whitepaper65_APFS-forensics_signed.pdf (last visited: 2018-06-20)."},{"key":"e_1_3_2_1_6_1","unstructured":"EDRM. 2009. EDRM File Formats Data Set 1.0. https:\/\/www.edrm.net\/resources\/data-sets\/edrm-file-format-data-set\/ (last visited: 2018-01-18).  EDRM. 2009. EDRM File Formats Data Set 1.0. https:\/\/www.edrm.net\/resources\/data-sets\/edrm-file-format-data-set\/ (last visited: 2018-01-18)."},{"key":"e_1_3_2_1_7_1","unstructured":"Simon Gander. 2017. APFS FUSE Driver for Linux. https:\/\/github.com\/sgan81\/apfs-fuse\/ (last visited: 2018-04-15).  Simon Gander. 2017. APFS FUSE Driver for Linux. https:\/\/github.com\/sgan81\/apfs-fuse\/ (last visited: 2018-04-15)."},{"key":"e_1_3_2_1_8_1","unstructured":"Christophe Grenier. 2011. Photorec. http:\/\/www.cgsecurity.org\/wiki\/PhotoRec.  Christophe Grenier. 2011. Photorec. http:\/\/www.cgsecurity.org\/wiki\/PhotoRec."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.07.003"},{"key":"e_1_3_2_1_10_1","first-page":"5","article-title":"Fletcher's Checksum","volume":"17","author":"Kodis John","year":"1992","unstructured":"John Kodis . 1992 . Fletcher's Checksum . Dr. Dobb's J. 17 , 5 (May 1992), 32--38. http:\/\/dl.acm.org\/citation.cfm?id=135011.135013 John Kodis. 1992. Fletcher's Checksum. Dr. Dobb's J. 17, 5 (May 1992), 32--38. http:\/\/dl.acm.org\/citation.cfm?id=135011.135013","journal-title":"Dr. Dobb's J."},{"key":"e_1_3_2_1_11_1","volume-title":"Security and Privacy Protection in Information Processing Systems, Lech J","author":"Laurenson Thomas","unstructured":"Thomas Laurenson . 2013. Performance Analysis of File Carving Tools . In Security and Privacy Protection in Information Processing Systems, Lech J . Janczewski, Henry B. Wolfe, and Sujeet Shenoi (Eds.). Springer Berlin Heidelberg , Berlin, Heidelberg , 419--433. Thomas Laurenson. 2013. Performance Analysis of File Carving Tools. In Security and Privacy Protection in Information Processing Systems, Lech J. Janczewski, Henry B. Wolfe, and Sujeet Shenoi (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 419--433."},{"key":"e_1_3_2_1_12_1","unstructured":"Paragon Technologie GmbH. 2017. APFS for Windows by Paragon Software. https:\/\/backstage.paragon-software.com\/home\/apfs-windows\/ (last visited: 2018-04-15).  Paragon Technologie GmbH. 2017. APFS for Windows by Paragon Software. https:\/\/backstage.paragon-software.com\/home\/apfs-windows\/ (last visited: 2018-04-15)."},{"key":"e_1_3_2_1_13_1","unstructured":"SysDev Laboratories GmbH. 2017. Recovery Explorer. http:\/\/r-explorer.com\/technical.php (last visited: 2018-04-15).  SysDev Laboratories GmbH. 2017. Recovery Explorer. http:\/\/r-explorer.com\/technical.php (last visited: 2018-04-15)."},{"key":"e_1_3_2_1_14_1","unstructured":"Thomas Tempelmann. 2017. Biskus APFS Capture. http:\/\/biskus.com\/ (last visited: 2018-04-15).  Thomas Tempelmann. 2017. Biskus APFS Capture. http:\/\/biskus.com\/ (last visited: 2018-04-15)."}],"event":{"name":"ARES 2018: International Conference on Availability, Reliability and Security","location":"Hamburg Germany","acronym":"ARES 2018","sponsor":["Universit\u00e4t Hamburg Universit\u00e4t Hamburg"]},"container-title":["Proceedings of the 13th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3232808","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3230833.3232808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:07:50Z","timestamp":1750212470000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3232808"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,27]]},"references-count":14,"alternative-id":["10.1145\/3230833.3232808","10.1145\/3230833"],"URL":"https:\/\/doi.org\/10.1145\/3230833.3232808","relation":{},"subject":[],"published":{"date-parts":[[2018,8,27]]},"assertion":[{"value":"2018-08-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}