{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:19:20Z","timestamp":1750220360956,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,17]],"date-time":"2021-08-17T00:00:00Z","timestamp":1629158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1900210"],"award-info":[{"award-number":["1900210"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,17]]},"DOI":"10.1145\/3465481.3470051","type":"proceedings-article","created":{"date-parts":[[2021,8,16]],"date-time":"2021-08-16T18:07:25Z","timestamp":1629137245000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Forensic Artifact Finder (ForensicAF): An Approach &amp; Tool for Leveraging Crowd-Sourced Curated Forensic Artifacts"],"prefix":"10.1145","author":[{"given":"Tyler","family":"Balon","sequence":"first","affiliation":[{"name":"University of New Haven, US"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Krikor","family":"Herlopian","sequence":"additional","affiliation":[{"name":"University of New Haven, US"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ibrahim","family":"Baggili","sequence":"additional","affiliation":[{"name":"University of New Haven, US"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cinthya","family":"Grajeda-Mendez","sequence":"additional","affiliation":[{"name":"University of New Haven, US"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,8,17]]},"reference":[{"volume-title":"Dutch National Police Agency","key":"e_1_3_2_1_1_1","unstructured":"[n.d.]. Dutch National Police Agency. http:\/\/ocfa.sourceforge.net\/. Accessed: 2010-12-12."},{"key":"e_1_3_2_1_2_1","unstructured":"[n.d.]. Encase Forensic. http:\/\/www.guidancesoftware.com\/products\/ef_index.asp. Accessed: 2007-12-12."},{"key":"e_1_3_2_1_3_1","unstructured":"[n.d.]. Forensic Toolkit (FTK). https:\/\/accessdata.com\/products-services\/forensic-toolkit-ftk. Accessed: 2021-02-04."},{"key":"e_1_3_2_1_4_1","first-page":"175","article-title":"A new approach of digital forensic model for digital forensic investigation","volume":"2","author":"Ademu O","year":"2011","unstructured":"Inikpi\u00a0O Ademu, Chris\u00a0O Imafidon, and David\u00a0S Preston. 2011. A new approach of digital forensic model for digital forensic investigation. Int. J. Adv. Comput. Sci. Appl 2, 12 (2011), 175\u2013178.","journal-title":"Int. J. Adv. Comput. Sci. Appl"},{"key":"e_1_3_2_1_5_1","unstructured":"Apache Foundation. [n.d.]. Class XSSFWorkbook. https:\/\/poi.apache.org\/apidocs\/dev\/org\/apache\/poi\/xssf\/usermodel\/XSSFWorkbook.html."},{"key":"e_1_3_2_1_6_1","volume-title":"AAAI Spring Symposium Series. https:\/\/www.aaai.org\/ocs\/index.php\/SSS\/SSS15\/paper\/view\/10227\/10092","author":"Baggili Ibrahim","year":"2015","unstructured":"Ibrahim Baggili and Frank Breitinger. 2015. Data Sources for Advancing Cyber Forensics: What the Social World Has to Offer. AAAI Spring Symposium Series. https:\/\/www.aaai.org\/ocs\/index.php\/SSS\/SSS15\/paper\/view\/10227\/10092"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44952-3_19"},{"key":"e_1_3_2_1_8_1","unstructured":"Willi Ballenthin. 2014. Rejistry. https:\/\/github.com\/williballenthin\/Rejistry."},{"key":"e_1_3_2_1_9_1","first-page":"1","article-title":"Standardizing cyber threat intelligence information with the structured threat information expression (stix)","volume":"11","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum. 2012. Standardizing cyber threat intelligence information with the structured threat information expression (stix). Mitre Corporation 11(2012), 1\u201322.","journal-title":"Mitre Corporation"},{"key":"e_1_3_2_1_10_1","unstructured":"Basis Technology. [n.d.]. Autopsy - Autopsy Forensic Browser Developer\u2019s Guide and API Reference. https:\/\/www.sleuthkit.org\/autopsy\/docs\/api-docs\/4.0\/mod_dev_py_page.html. Accessed: 2020-02-06."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04155-6_2"},{"key":"e_1_3_2_1_12_1","volume-title":"International Conference on Digital Forensics and Cyber Crime. Springer, 170\u2013186","author":"Breitinger Frank","year":"2013","unstructured":"Frank Breitinger, Huajian Liu, Christian Winter, Harald Baier, Alexey Rybalchenko, and Martin Steinebach. 2013. Towards a process model for hash functions in digital forensics. In International Conference on Digital Forensics and Cyber Crime. Springer, 170\u2013186."},{"key":"e_1_3_2_1_13_1","volume-title":"The Sleuth Kit and Autopsy: forensics tools for Linux and other Unixes","author":"Carrier Brian","year":"2005","unstructured":"Brian Carrier. 2009. The Sleuth Kit and Autopsy: forensics tools for Linux and other Unixes, 2005. URL http:\/\/www. sleuthkit. org(2009)."},{"key":"e_1_3_2_1_14_1","volume-title":"International Journal of digital evidence 1, 4","author":"Brian Carrier","year":"2003","unstructured":"Brian Carrier 2003. Defining digital forensic examination and analysis tools using abstraction layers. International Journal of digital evidence 1, 4 (2003), 1\u201312."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/1706428.1706451"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"crossref","unstructured":"MI Cohen. 2008. PyFlag\u2013An advanced network forensic framework. Digital investigation 5(2008) S112\u2013S120.","DOI":"10.1016\/j.diin.2008.05.016"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","unstructured":"D. Compton J.\u00a0A. Hamilton and Jr.2011. An Examination of the Techniques and Implications of the Crowd-Sourced Collection of Forensic Data. In 2011 IEEE Third International Conference on Privacy Security Risk and Trust and 2011 IEEE Third International Conference on Social Computing. 892\u2013895. https:\/\/doi.org\/10.1109\/PASSAT\/SocialCom.2011.232","DOI":"10.1109\/PASSAT"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2002.1067738"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.06.010"},{"key":"e_1_3_2_1_20_1","unstructured":"Forensic Artifacts. 2021. artifacts. https:\/\/github.com\/ForensicArtifacts\/artifacts."},{"key":"e_1_3_2_1_21_1","unstructured":"Baguelin Frederic Jacob Solal Mounier Jeremy and Percot Francois. 2010. Digital forensics framework."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Simson\u00a0L Garfinkel. 2007. Carving contiguous and fragmented files with fast object validation. digital investigation 4(2007) 2\u201312.","DOI":"10.1016\/j.diin.2007.06.017"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2009.12"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Simson\u00a0L Garfinkel. 2010. Digital forensics research: The next 10 years. digital investigation 7(2010) S64\u2013S73.","DOI":"10.1016\/j.diin.2010.05.009"},{"key":"e_1_3_2_1_25_1","volume-title":"Future of Information and Communication Conference. Springer, 1227\u20131243","author":"Gentry Eric","year":"2019","unstructured":"Eric Gentry, Ryan McIntyre, Michael Soltys, and Frank Lyu. 2019. SEAKER: A tool for fast digital forensic triage. In Future of Information and Communication Conference. Springer, 1227\u20131243."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2018.04.021"},{"key":"e_1_3_2_1_27_1","volume-title":"Digital Forensics Market Size is expected to grow to USD 6.95 billion by","author":"Research Grand View","year":"2025","unstructured":"Grand View Research. 2019. Digital Forensics Market Size is expected to grow to USD 6.95 billion by 2025. https:\/\/www.grandviewresearch.com\/industry-analysis\/digital-forensics-market. Accessed: 2021-02-02."},{"key":"e_1_3_2_1_28_1","first-page":"4","article-title":"Bytewise approximate matching: the good, the bad, and the unknown","volume":"11","author":"Harichandran S","year":"2016","unstructured":"Vikram\u00a0S Harichandran, Frank Breitinger, and Ibrahim Baggili. 2016. Bytewise approximate matching: the good, the bad, and the unknown. Journal of Digital Forensics, Security and Law 11, 2 (2016), 4.","journal-title":"Journal of Digital Forensics, Security and Law"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.10.007"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2016.04.005"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi6030584"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.3390\/sym9040049"},{"key":"e_1_3_2_1_34_1","unstructured":"log2timeline. 2021. Plaso. https:\/\/github.com\/log2timeline\/plaso."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3232813"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1418"},{"key":"e_1_3_2_1_37_1","volume-title":"Scalpel: A Frugal, High Performance File Carver.. In DFRWS. Citeseer.","author":"Vassil Roussev G","year":"2005","unstructured":"Golden\u00a0G Richard\u00a0III and Vassil Roussev. 2005. Scalpel: A Frugal, High Performance File Carver.. In DFRWS. Citeseer."},{"key":"e_1_3_2_1_38_1","volume-title":"Paper Session II: Computer Forensics Field Triage Process Model.","author":"Rogers K","year":"2016","unstructured":"Marcus\u00a0K Rogers, James Goldman, Rick Mislan, Timothy Wedge, and Steve Debrota. 2016. Paper Session II: Computer Forensics Field Triage Process Model. (2016)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2004.01.003"},{"key":"e_1_3_2_1_40_1","volume-title":"md5bloom: Forensic filesystem hashing revisited. digital investigation 3, 1","author":"Roussev Vassil","year":"2006","unstructured":"Vassil Roussev, Yixin Chen, Timothy Bourg, and Golden\u00a0G Richard\u00a0III. 2006. md5bloom: Forensic filesystem hashing revisited. digital investigation 3, 1 (2006), 82\u201390."},{"key":"e_1_3_2_1_41_1","unstructured":"Keyun Ruan Ibrahim Baggili Joe Carthy and Tahar Kechadi. 2011. Survey on cloud forensics and critical criteria for cloud forensic capability: A preliminary analysis. (2011)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2013.02.004"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2019.04.005"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"George Sibiya Hein\u00a0S Venter and Thomas Fogwill. 2012. Digital forensic framework for a cloud environment. (2012).","DOI":"10.1109\/AFRCON.2013.6757831"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2020.301021"}],"event":{"name":"ARES 2021: The 16th International Conference on Availability, Reliability and Security","acronym":"ARES 2021","location":"Vienna Austria"},"container-title":["Proceedings of the 16th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470051","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3465481.3470051","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3465481.3470051","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:17:24Z","timestamp":1750191444000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3465481.3470051"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,17]]},"references-count":44,"alternative-id":["10.1145\/3465481.3470051","10.1145\/3465481"],"URL":"https:\/\/doi.org\/10.1145\/3465481.3470051","relation":{},"subject":[],"published":{"date-parts":[[2021,8,17]]},"assertion":[{"value":"2021-08-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}