{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T01:32:00Z","timestamp":1763429520677,"version":"build-2065373602"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,10,3]],"date-time":"2018-10-03T00:00:00Z","timestamp":1538524800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cloud Comp"],"published-print":{"date-parts":[[2018,12]]},"DOI":"10.1186\/s13677-018-0119-2","type":"journal-article","created":{"date-parts":[[2018,10,3]],"date-time":"2018-10-03T06:56:31Z","timestamp":1538549791000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["LogDrive: a proactive data collection and analysis framework for time-traveling forensic investigation in IaaS cloud environments"],"prefix":"10.1186","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9780-6454","authenticated-orcid":false,"given":"Manabu","family":"Hirano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Natsuki","family":"Tsuzuki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seishiro","family":"Ikeda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ryotaro","family":"Kobayashi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,10,3]]},"reference":[{"key":"119_CR1","volume-title":"The NIST definition of cloud computing, SP 800-145","author":"P Mell","year":"2011","unstructured":"Mell P, Grance T (2011) The NIST definition of cloud computing, SP 800-145. National Institute of Standards and Technology, Gaithersburg. https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-145\/final . Accessed 18 Sept 2018."},{"key":"119_CR2","doi-asserted-by":"publisher","unstructured":"Hirano M, Ogawa H (2016) A log-structured block preservation and restoration system for proactive forensic data collection in the cloud In: Availability, Reliability and Security (ARES), 2016 11th International Conference On, 355\u2013364.. IEEE. https:\/\/doi.org\/10.1109\/ARES.2016.8 .","DOI":"10.1109\/ARES.2016.8"},{"key":"119_CR3","doi-asserted-by":"publisher","unstructured":"Hirano M, Takase H, Yoshida K (2015) Evaluation of a sector-hash based rapid file detection method for monitoring infrastructure-as-a-service cloud platforms In: Availability, Reliability and Security (ARES), 2015 10th International Conference On, 584\u2013591.. IEEE. https:\/\/doi.org\/10.1109\/ARES.2015.15 .","DOI":"10.1109\/ARES.2015.15"},{"key":"119_CR4","volume-title":"Threat Modeling: Designing for Security","author":"A Shostack","year":"2014","unstructured":"Shostack A (2014) Threat Modeling: Designing for Security. Wiley, Hoboken."},{"key":"119_CR5","unstructured":"Palmer G (2001) A road map for digital forensic research In: First Digital Forensic Research Workshop, 27\u201330, Utica. http:\/\/dfrws.org\/sites\/default\/files\/session-files\/a_road_map_for_digital_forensic_research.pdf . Accessed 18 Sept 2018."},{"key":"119_CR6","volume-title":"SP800-86. Guide to integrating forensic techniques into incident response","author":"K Kent","year":"2006","unstructured":"Kent K, Chevalier S, Grance T, Dang H (2006) SP800-86. Guide to integrating forensic techniques into incident response. National Institute of Standards and Technology, Gaithersburg."},{"key":"119_CR7","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1016\/j.cose.2015.04.003","volume":"52","author":"M Elyas","year":"2015","unstructured":"Elyas M, Ahmad A, Maynard SB, Lonie A (2015) Digital forensic readiness: Expert perspectives on a theoretical framework. Comput Secur 52:70\u201389.","journal-title":"Comput Secur"},{"key":"119_CR8","first-page":"35","volume-title":"IFIP International Conference on Digital Forensics","author":"K Ruan","year":"2011","unstructured":"Ruan K, Carthy J, Kechadi T, Crosbie M (2011) Cloud forensics In: IFIP International Conference on Digital Forensics, 35\u201346.. Springer, Berlin Heidelberg."},{"issue":"2","key":"119_CR9","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1016\/j.diin.2012.07.001","volume":"9","author":"B Martini","year":"2012","unstructured":"Martini B, Choo K-KR (2012) An integrated conceptual digital forensic framework for cloud computing. Digit Investig 9(2):71\u201380.","journal-title":"Digit Investig"},{"issue":"1","key":"119_CR10","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MCC.2016.5","volume":"3","author":"NH Ab Rahman","year":"2016","unstructured":"Ab Rahman NH, Glisson WB, Yang Y, Choo K-KR (2016) Forensic-by-design framework for cyber-physical cloud systems. IEEE Cloud Comput 3(1):50\u201359.","journal-title":"IEEE Cloud Comput"},{"key":"119_CR11","doi-asserted-by":"publisher","first-page":"S64","DOI":"10.1016\/j.diin.2010.05.009","volume":"7","author":"SL Garfinkel","year":"2010","unstructured":"Garfinkel SL (2010) Digital forensics research: The next 10 years. Digit Investig 7:S64\u2013S73.","journal-title":"Digit Investig"},{"key":"119_CR12","unstructured":"Fox A, Griffith R, Joseph A, Katz R, Konwinski A, Lee G, Patterson D, Rabkin A, Stoica I (2009) Above the Clouds: A Berkeley View of Cloud Computing. Electrical Engineering and Computer Sciences. University of California at Berkeley. p. 1\u201323. Technical Report No UCB\/EECS-2009-28."},{"issue":"1","key":"119_CR13","doi-asserted-by":"publisher","first-page":"26","DOI":"10.20533\/ijmip.2042.4647.2011.0004","volume":"1","author":"D Reilly","year":"2011","unstructured":"Reilly D, Wren C, Berry Tq (2011) Cloud computing: Pros and cons for computer forensic investigations. Int J Multimed Image Process (IJMIP) 1(1):26\u201334.","journal-title":"Int J Multimed Image Process (IJMIP)"},{"issue":"3","key":"119_CR14","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1016\/S1353-4858(11)70024-1","volume":"2011","author":"M Taylor","year":"2011","unstructured":"Taylor M, Haggerty J, Gresty D, Lamb D (2011) Forensic investigation of cloud computing systems. Netw Secur 2011(3):4\u201310.","journal-title":"Netw Secur"},{"issue":"2","key":"119_CR15","doi-asserted-by":"publisher","first-page":"28","DOI":"10.4018\/jdcf.2012040103","volume":"4","author":"G Grispos","year":"2013","unstructured":"Grispos G, Storer T, Glisson WB (2013) Calm before the storm: the challenges of cloud. Int J Digit Crime Forensic (IJDCF) 4(2):28\u201348.","journal-title":"Int J Digit Crime Forensic (IJDCF)"},{"key":"119_CR16","first-page":"201","volume-title":"IFIP International Conference on Digital Forensics","author":"K Ruan","year":"2012","unstructured":"Ruan K, James J, Carthy J, Kechadi T (2012) Key terms for service level agreements to support cloud forensics In: IFIP International Conference on Digital Forensics, 201\u2013212.. Springer, Berlin Heidelberg."},{"key":"119_CR17","doi-asserted-by":"publisher","unstructured":"Nanda S, Hansen RA (2016) Forensics as a service: Three-tier architecture for cloud based forensic analysis In: 2016 15th International Symposium on Parallel and Distributed Computing (ISPDC), 178\u2013183. https:\/\/doi.org\/10.1109\/ISPDC.2016.31 .","DOI":"10.1109\/ISPDC.2016.31"},{"issue":"6","key":"119_CR18","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/MSP.2010.187","volume":"8","author":"D Harnik","year":"2010","unstructured":"Harnik D, Pinkas B, Shulman-Peleg A (2010) Side channels in cloud services: Deduplication in cloud storage. IEEE Secur Priv 8(6):40\u201347. https:\/\/doi.org\/10.1109\/MSP.2010.187 .","journal-title":"IEEE Secur Priv"},{"key":"119_CR19","unstructured":"Bonwick J, Moore B (2007) ZFS: the last word in file systems. https:\/\/wiki.illumos.org\/download\/attachments\/1146951\/zfs_last.pdf . Accessed 18 Sept 2018."},{"key":"119_CR20","unstructured":"Roussev V, Richard III GG (2004) Breaking the performance wall: The case for distributed digital forensics In: Proceedings of the 2004 Digital Forensics Research Workshop, vol. 94, Baltimore."},{"issue":"1","key":"119_CR21","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1145\/1327452.1327492","volume":"51","author":"J Dean","year":"2008","unstructured":"Dean J, Ghemawat S (2008) MapReduce: simplified data processing on large clusters. Commun ACM 51(1):107\u2013113.","journal-title":"Commun ACM"},{"key":"119_CR22","first-page":"201","volume-title":"IFIP International Conference on Digital Forensics","author":"V Roussev","year":"2009","unstructured":"Roussev V, Wang L, Richard G, Marziale L (2009) A cloud computing platform for large-scale forensic computing In: IFIP International Conference on Digital Forensics, 201\u2013214.. Springer, Berlin Heidelberg."},{"key":"119_CR23","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1016\/j.diin.2009.06.013","volume":"6","author":"D Ayers","year":"2009","unstructured":"Ayers D (2009) A second generation computer forensic analysis system. Digit Investig 6:34\u201342.","journal-title":"Digit Investig"},{"key":"119_CR24","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1016\/j.diin.2015.05.001","volume":"14","author":"SL Garfinkel","year":"2015","unstructured":"Garfinkel SL, McCarrin M (2015) Hash-based carving: Searching media for complete files and file fragments with sector hashing and hashdb. Digit Investig 14:95\u2013105. https:\/\/doi.org\/10.1016\/j.diin.2015.05.001 .","journal-title":"Digit Investig"},{"key":"119_CR25","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1016\/j.cose.2012.09.011","volume":"32","author":"SL Garfinkel","year":"2013","unstructured":"Garfinkel SL (2013) Digital media triage with bulk data analysis and bulk_extractor. Comput Secur 32:56\u201372.","journal-title":"Comput Secur"},{"issue":"12","key":"119_CR26","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/MC.2012.327","volume":"45","author":"J Young","year":"2012","unstructured":"Young J, Foster K, Garfinkel S, Fairbanks K (2012) Distinct sector hashes for target file detection. IEEE Computer 45(12):28\u201335. http:\/\/doi.ieeecomputersociety.org\/10.1109\/MC.2012.327 .","journal-title":"IEEE Computer"},{"key":"119_CR27","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1016\/j.diin.2012.05.011","volume":"9","author":"B Jones","year":"2012","unstructured":"Jones B, Pleno S, Wilkinson M (2012) The use of random sampling in investigations involving child abuse material. Digit Investig 9:99\u2013107.","journal-title":"Digit Investig"},{"key":"119_CR28","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1016\/j.diin.2006.06.005","volume":"3","author":"R Harris","year":"2006","unstructured":"Harris R (2006) Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem. Digit Investig 3:44\u201349.","journal-title":"Digit Investig"},{"key":"119_CR29","first-page":"77","volume-title":"2nd International Conference on i-Warfare and Security, vol. 20087","author":"S Garfinkel","year":"2007","unstructured":"Garfinkel S (2007) Anti-forensics: techniques, detection and countermeasures In: 2nd International Conference on i-Warfare and Security, vol. 20087, 77\u201384.. Edith Cowan University, Perth Western Australia."},{"key":"119_CR30","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4225\/75\/57ad39ee7ff25","volume-title":"Australian Digital Forensics Conference","author":"GC Kessler","year":"2007","unstructured":"Kessler GC (2007) Anti-forensics and the digital investigator In: Australian Digital Forensics Conference, 1.. Edith Cowan University, Perth Western Australia. https:\/\/doi.org\/10.4225\/75\/57ad39ee7ff25 ."},{"issue":"2","key":"119_CR31","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1145\/317087.317089","volume":"2","author":"B Schneier","year":"1999","unstructured":"Schneier B, Kelsey J (1999) Secure audit logs to support computer forensics. ACM Trans Inf Syst Secur (TISSEC) 2(2):159\u2013176.","journal-title":"ACM Trans Inf Syst Secur (TISSEC)"},{"key":"119_CR32","doi-asserted-by":"crossref","unstructured":"Zawoad S, Dutta AK, Hasan R (2013) SecLaaS: secure logging-as-a-service for cloud forensics In: Proceedings of the 8th ACM SIGSAC Symposium on Information, Computer and Communications Security, 219\u2013230.. ACM.","DOI":"10.1145\/2484313.2484342"},{"issue":"1","key":"119_CR33","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1145\/146941.146943","volume":"10","author":"M Rosenblum","year":"1992","unstructured":"Rosenblum M, Ousterhout JK (1992) The design and implementation of a log-structured file system. ACM Trans Comput Syst (TOCS) 10(1):26\u201352. https:\/\/doi.org\/10.1145\/146941.146943 .","journal-title":"ACM Trans Comput Syst (TOCS)"},{"key":"119_CR34","unstructured":"Cornell B, Dinda PA, Bustamante FE (2004) Wayback: A user-level versioning file system for linux In: Proceedings of USENIX Annual Technical Conference, FREENIX Track, 19\u201328, Boston."},{"key":"119_CR35","unstructured":"Strunk JD, Goodson GR, Scheinholtz ML, Soules CA, Ganger GR (2000) Self-securing storage: protecting data in compromised system In: Proceedings of the 4th Conference on Symposium on Operating System Design & Implementation (OSDI). Vol. 4, 12. USENIX Association."},{"key":"119_CR36","doi-asserted-by":"crossref","unstructured":"Morrey C, Grunwald D (2003) Peabody: The time travelling disk In: Mass Storage Systems and Technologies, 2003.(MSST 2003). Proceedings. 20th IEEE\/11th NASA Goddard Conference On, 241\u2013253.. IEEE.","DOI":"10.1109\/MASS.2003.1194861"},{"key":"119_CR37","unstructured":"Xu J, Swanson S (2016) NOVA: a log-structured file system for hybrid volatile\/non-volatile main memories In: 14th USENIX Conference on File and Storage Technologies (FAST \u201916), 323\u2013338, Santa Clara."},{"key":"119_CR38","unstructured":"Lee C, Sim D, Hwang JY, Cho S (2015) F2FS: a new file system for flash storage In: 13th USENIX Conference on File and Storage Technologies (FAST \u201915), 273\u2013286, Santa Clara."},{"key":"119_CR39","first-page":"19","volume-title":"Proceedings of the 10th USENIX Conference on File and Storage Technologies (FAST \u201912)","author":"M Vrable","year":"2012","unstructured":"Vrable M, Savage S, Voelker GM (2012) Bluesky: A cloud-backed file system for the enterprise In: Proceedings of the 10th USENIX Conference on File and Storage Technologies (FAST \u201912), 19.. USENIX Association, San Jose. https:\/\/www.usenix.org\/system\/files\/conference\/fast12\/vrable.pdf . Accessed 18 Sept 2018."},{"key":"119_CR40","unstructured":"McLoughlin M,The QCOW2 Image Format. http:\/\/people.gnome.org\/~markmc\/qcow-image-format.html , Accessed 1 March 2017."},{"key":"119_CR41","unstructured":"Microsoft (2006) Virtual Hard Disk Image Format Specification, Version 1.0. http:\/\/download.microsoft.com\/download\/f\/f\/e\/ffef50a5-07dd-4cf8-aaa3-442c0673a029Virtual%20Hard%20Disk%20Format%20Spec_10_18_06.doc . Accessed 18 Sept 2018."},{"key":"119_CR42","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1016\/j.diin.2010.05.003","volume":"7","author":"S Garfinkel","year":"2010","unstructured":"Garfinkel S, Nelson A, White D, Roussev V (2010) Using purpose-built functions and block hashes to enable small block and sub-file forensics. Digit Investig 7:13\u201323. https:\/\/doi.org\/10.1016\/j.diin.2010.05.003 .","journal-title":"Digit Investig"},{"key":"119_CR43","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1016\/j.diin.2007.06.017","volume":"4","author":"SL Garfinkel","year":"2007","unstructured":"Garfinkel SL (2007) Carving contiguous and fragmented files with fast object validation. Digit Investig 4:2\u201312. https:\/\/doi.org\/10.1016\/j.diin.2007.06.017 .","journal-title":"Digit Investig"},{"key":"119_CR44","unstructured":"Govdocs, 1, Digital Corpora. http:\/\/digitalcorpora.org\/corpora\/govdocs , Accessed 1 March 2017."},{"key":"119_CR45","unstructured":"Stevens CE (2008) Information technology - AT Attachment 8 - ATA\/ATAPI command set (ATA8-ACS). ANSI, Working Draft Project American National Standard, Revision, 6a."},{"key":"119_CR46","unstructured":"Borthakur D, et al. (2008) HDFS architecture guide. Hadoop Apache Proj. https:\/\/hadoop.apache.org\/docs\/r1.2.1\/hdfs_design.pdf . Accessed 18 Sept 2018."},{"key":"119_CR47","volume-title":"MapReduce Design Patterns: Building Effective Algorithms and Analytics for Hadoop and Other Systems","author":"D Miner","year":"2012","unstructured":"Miner D, Shook A (2012) MapReduce Design Patterns: Building Effective Algorithms and Analytics for Hadoop and Other Systems. \u201cO\u2019Reilly Media, Inc.\u201d, Sebastopol, California."},{"key":"119_CR48","doi-asserted-by":"crossref","unstructured":"Rivest R (1992) The MD5 message-digest algorithm. RFC 1321. http:\/\/www.rfc-editor.org\/info\/rfc1321 . Accessed 18 Sept 2018.","DOI":"10.17487\/rfc1321"},{"key":"119_CR49","unstructured":"Xen Blktap2 Driver. https:\/\/wiki.xen.org\/wiki\/Blktap2 , Accessed 1 March 2017."},{"key":"119_CR50","first-page":"41","volume-title":"ACM SIGOPS Operating Systems Review, vol. 42","author":"DT Meyer","year":"2008","unstructured":"Meyer DT, Aggarwal G, Cully B, Lefebvre G, Feeley MJ, Hutchinson NC, Warfield A (2008) Parallax: virtual disks for virtual machines In: ACM SIGOPS Operating Systems Review, vol. 42, 41\u201354.. ACM, New York."},{"key":"119_CR51","unstructured":"Warfield A, Hand S, Fraser K, Deegan T (2005) Facilitating the development of soft devices In: USENIX Annual Technical Conference, General Track, 379\u2013382. http:\/\/usenix.org\/publications\/library\/proceedings\/usenix05\/tech\/general\/full_papers\/short_papers\/warfield\/warfield.pdf . Accessed 18 Sept 2018."},{"key":"119_CR52","first-page":"164","volume-title":"ACM SIGOPS Operating Systems Review, vol. 37","author":"P Barham","year":"2003","unstructured":"Barham P, Dragovic B, Fraser K, Hand S, Harris T, Ho A, Neugebauer R, Pratt I, Warfield A (2003) Xen and the art of virtualization In: ACM SIGOPS Operating Systems Review, vol. 37, 164\u2013177.. ACM, New York."},{"key":"119_CR53","doi-asserted-by":"publisher","first-page":"S2","DOI":"10.1016\/j.diin.2009.06.016","volume":"6","author":"S Garfinkel","year":"2009","unstructured":"Garfinkel S, Farrell P, Roussev V, Dinolt G (2009) Bringing science to digital forensics with standardized forensic corpora. Digit Investig 6:S2\u2013S11. https:\/\/doi.org\/10.1016\/j.diin.2009.06.016 .","journal-title":"Digit Investig"},{"key":"119_CR54","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/978-3-642-15506-2_15","volume-title":"Advances in Digital Forensics VI","author":"V Roussev","year":"2010","unstructured":"Roussev V (2010) Data fingerprinting with similarity digests. In: Chow K-P Shenoi S (eds)Advances in Digital Forensics VI, 207\u2013226.. Springer Berlin Heidelberg, Berlin, Heidelberg."},{"key":"119_CR55","first-page":"1","volume":"2006","author":"M Stevens","year":"2006","unstructured":"Stevens M (2006) Fast collision attack on md5. IACR Cryptol ePrint Arch 2006:1\u201313. https:\/\/eprint.iacr.org\/2006\/104.pdf . Accessed 18 Sept 2018.","journal-title":"IACR Cryptol ePrint Arch"},{"key":"119_CR56","first-page":"17","volume-title":"Annual International Cryptology Conference","author":"X Wang","year":"2005","unstructured":"Wang X, Yin YL, Yu H (2005) Finding collisions in the full SHA-1 In: Annual International Cryptology Conference, 17\u201336.. Springer, Berlin Heidelberg."},{"issue":"10","key":"119_CR57","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1145\/1022594.1022597","volume":"47","author":"H Wang","year":"2004","unstructured":"Wang H, Wang S (2004) Cyber warfare: steganography vs. steganalysis. Commun ACM 47(10):76\u201382.","journal-title":"Commun ACM"},{"issue":"3","key":"119_CR58","doi-asserted-by":"publisher","first-page":"361","DOI":"10.1109\/TC.2017.2647955","volume":"67","author":"P Maene","year":"2018","unstructured":"Maene P, G\u00f6tzfried J, de Clercq R, M\u00fcller T, Freiling F, Verbauwhede I (2018) Hardware-based trusted computing architectures for isolation and attestation. IEEE Trans Comput 67(3):361\u2013374.","journal-title":"IEEE Trans Comput"},{"key":"119_CR59","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1145\/1508293.1508311","volume-title":"Proceedings of the 2009 ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments","author":"T Shinagawa","year":"2009","unstructured":"Shinagawa T, Eiraku H, Tanimoto K, Omote K, Hasegawa S, Horie T, Hirano M, Kourai K, Oyama Y, Kawai E (2009) BitVisor: a thin hypervisor for enforcing I\/0 device security In: Proceedings of the 2009 ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, 121\u2013130.. ACM, New York. http:\/\/doi.acm.org\/10.1145\/1508293.1508311 ."},{"issue":"4","key":"119_CR60","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/MNET.2011.5958004","volume":"25","author":"L Yu","year":"2011","unstructured":"Yu L, Weng C, Li M, Luo Y (2011) SNPdisk: an efficient para-virtualization snapshot mechanism for virtual disks in private clouds. IEEE Netw 25(4):20\u201326. https:\/\/doi.org\/10.1109\/MNET.2011.5958004 .","journal-title":"IEEE Netw"},{"key":"119_CR61","unstructured":"King ST, Dunlap GW, Chen PM (2005) Debugging operating systems with time-traveling virtual machines In: Proceedings of the Annual Conference on USENIX Annual Technical Conference, 1\u201315, Anaheim. https:\/\/www.usenix.org\/legacy\/events\/usenix05\/tech\/general\/king\/king.pdf . Accessed 18 Sept 2018."},{"issue":"SI","key":"119_CR62","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1145\/844128.844148","volume":"36","author":"George W. Dunlap","year":"2002","unstructured":"Dunlap GW, King ST, Cinar S, Basrai MA, Chen PM (2002) ReVirt: enabling intrusion analysis through virtual-machine logging and replay. ACM SIGOPS Operating Systems Review In: OSDI \u201902: Proceedings of the 5th Symposium on Operating Systems Design and Implementation, 211\u2013224. https:\/\/doi.org\/10.1145\/844128.844148 .","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"119_CR63","unstructured":"Taguchi JK (2013) Optimal sector sampling for drive triage. NAVAL POSTGRADUATE SCHOOL MONTEREY CA. https:\/\/calhoun.nps.edu\/handle\/10945\/34750 . Accessed 18 Sept 2018."},{"issue":"7","key":"119_CR64","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1145\/362686.362692","volume":"13","author":"BH Bloom","year":"1970","unstructured":"Bloom BH (1970) Space\/time trade-offs in hash coding with allowable errors. Commun ACM 13(7):422\u2013426. https:\/\/doi.org\/10.1145\/362686.362692 .","journal-title":"Commun ACM"},{"key":"119_CR65","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1016\/j.diin.2012.05.001","volume":"9","author":"J Dykstra","year":"2012","unstructured":"Dykstra J, Sherman AT (2012) Acquiring forensic evidence from infrastructure-as-a-service cloud computing: Exploring and evaluating tools, trust, and techniques. Digit Investig 9:90\u201398. https:\/\/doi.org\/10.1016\/j.diin.2012.05.001 .","journal-title":"Digit Investig"},{"key":"119_CR66","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/j.diin.2013.06.010","volume":"10","author":"J Dykstra","year":"2013","unstructured":"Dykstra J, Sherman AT (2013) Design and implementation of FROST: Digital forensic tools for the OpenStack cloud computing platform. Digit Investig 10:87\u201395. https:\/\/doi.org\/10.1016\/j.diin.2013.06.010 .","journal-title":"Digit Investig"},{"key":"119_CR67","volume-title":"A TRUSTWORTHY CLOUD FORENSICS ENVIRONMENT, Advances in Digital Forensics XI","author":"S Zawoad","year":"2015","unstructured":"Zawoad S, Hasan R (2015) A TRUSTWORTHY CLOUD FORENSICS ENVIRONMENT, Advances in Digital Forensics XI. Springer International Publishing, Cham. pp 271\u2013285."},{"issue":"2","key":"119_CR68","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1145\/1113034.1113074","volume":"49","author":"GG Richard III","year":"2006","unstructured":"Richard III GG, Roussev V (2006) Next-generation digital forensics. Commun ACM 49(2):76\u201380.","journal-title":"Commun ACM"}],"container-title":["Journal of Cloud Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-018-0119-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s13677-018-0119-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-018-0119-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T03:30:08Z","timestamp":1761103808000},"score":1,"resource":{"primary":{"URL":"https:\/\/journalofcloudcomputing.springeropen.com\/articles\/10.1186\/s13677-018-0119-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,3]]},"references-count":68,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,12]]}},"alternative-id":["119"],"URL":"https:\/\/doi.org\/10.1186\/s13677-018-0119-2","relation":{},"ISSN":["2192-113X"],"issn-type":[{"type":"electronic","value":"2192-113X"}],"subject":[],"published":{"date-parts":[[2018,10,3]]},"assertion":[{"value":"6 April 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 September 2018","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 October 2018","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Publisher\u2019s Note"}}],"article-number":"18"}}