{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,7]],"date-time":"2024-09-07T20:05:08Z","timestamp":1725739508126},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,12,3]]},"DOI":"10.1145\/2420950.2420962","type":"proceedings-article","created":{"date-parts":[[2012,12,19]],"date-time":"2012-12-19T14:12:22Z","timestamp":1355926342000},"page":"79-88","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":24,"title":["When hardware meets software"],"prefix":"10.1145","author":[{"given":"Alessandro","family":"Reina","sequence":"first","affiliation":[{"name":"Universit\u00e0 degli Studi di Milano"}]},{"given":"Aristide","family":"Fattori","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi di Milano"}]},{"given":"Fabio","family":"Pagani","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi di Milano"}]},{"given":"Lorenzo","family":"Cavallaro","sequence":"additional","affiliation":[{"name":"University of London"}]},{"given":"Danilo","family":"Bruschi","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi di Milano"}]}],"member":"320","published-online":{"date-parts":[[2012,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"41","volume-title":"Proceedings of the USENIX Annual Technical Conference, FREENIX Track","author":"Bellard F.","year":"2005"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2003.12.001"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1460877.1460892"},{"key":"e_1_3_2_1_4_1","unstructured":"Intel. Intel Software Network. http:\/\/software.intel.com\/en-us\/forums\/showthread.php?t=63946. Intel. Intel Software Network. http:\/\/software.intel.com\/en-us\/forums\/showthread.php?t=63946."},{"key":"e_1_3_2_1_5_1","unstructured":"Intel. Intel I\/O Controller Hub 10 (ICH10) Family 2008. Intel. Intel I\/O Controller Hub 10 (ICH10) Family 2008."},{"key":"e_1_3_2_1_6_1","unstructured":"Intel Corporation. Preboot Execution Environment (PXE) Specification 1999. Intel Corporation. Preboot Execution Environment (PXE) Specification 1999."},{"key":"e_1_3_2_1_7_1","unstructured":"Intel Corporation. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3A May 2012. Intel Corporation. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3A May 2012."},{"key":"e_1_3_2_1_8_1","unstructured":"Intel Corporation. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3B May 2012. Intel Corporation. Intel 64 and IA-32 Architectures Software Developer's Manual - Volume 3B May 2012."},{"volume-title":"Proceedings of the 19th Annual Network and Distributed System Security Symposium (NDSS)","year":"2012","author":"Kun Sun F. Z.","key":"e_1_3_2_1_9_1"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368506.1368510"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/1894166.1894187"},{"key":"e_1_3_2_1_12_1","unstructured":"A. Martin. FireWire memory dump of a Windows XP computer: a forensic approach. http:\/\/www.friendsglobal.com\/papers\/FireWire%20Memory%20Dump%20of%20Windows%20XP.pdf. A. Martin. FireWire memory dump of a Windows XP computer: a forensic approach. http:\/\/www.friendsglobal.com\/papers\/FireWire%20Memory%20Dump%20of%20Windows%20XP.pdf."},{"key":"e_1_3_2_1_13_1","unstructured":"R. Minnich. coreboot. http:\/\/www.coreboot.org\/. R. Minnich. coreboot. http:\/\/www.coreboot.org\/."},{"key":"e_1_3_2_1_14_1","unstructured":"A. Ornaghi and M. Valleri. Man in the middle attacks demos. Blackhat {Online Document} 2003. A. Ornaghi and M. Valleri. Man in the middle attacks demos. Blackhat {Online Document} 2003."},{"key":"e_1_3_2_1_15_1","unstructured":"Phoenix. BIOS Undercover: Writing A Software SMI Handler 2008. http:\/\/blogs.phoenix.com\/phoenix_technologies_bios\/2008\/12\/bios-undercover-writing-a-software-smi-handler.html. Phoenix. BIOS Undercover: Writing A Software SMI Handler 2008. http:\/\/blogs.phoenix.com\/phoenix_technologies_bios\/2008\/12\/bios-undercover-writing-a-software-smi-handler.html."},{"key":"e_1_3_2_1_16_1","unstructured":"J. Rutkowska. Beyond the CPU: Defeating hardware based RAM acquisition tools 2007. http:\/\/invisiblethings.org\/papers\/cheating-hardware-memory-acquisition-updated.ppt. J. Rutkowska. Beyond the CPU: Defeating hardware based RAM acquisition tools 2007. http:\/\/invisiblethings.org\/papers\/cheating-hardware-memory-acquisition-updated.ppt."},{"volume-title":"IT Innovation and Research","year":"2005","author":"Schluessler T.","key":"e_1_3_2_1_17_1"},{"key":"e_1_3_2_1_18_1","unstructured":"S. Sokolov. 8042 keyboard controller. http:\/\/stanislavs.org\/helppc\/8042.html. S. Sokolov. 8042 keyboard controller. http:\/\/stanislavs.org\/helppc\/8042.html."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"T. Vidas. Acquisition and Forensic Analysis of Volatile Data Stores. PhD thesis University of Nebraska at Omaha 2006. T. Vidas. Acquisition and Forensic Analysis of Volatile Data Stores . PhD thesis University of Nebraska at Omaha 2006.","DOI":"10.15394\/jdfsl.2007.1026"},{"volume-title":"The SANS Institute","year":"2001","author":"Wagner R.","key":"e_1_3_2_1_20_1"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1894166.1894178"},{"volume-title":"George Mason University","year":"2011","author":"Wang J.","key":"e_1_3_2_1_22_1"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2011.7"},{"key":"e_1_3_2_1_24_1","first-page":"2008","article-title":"Subverting the Xen hypervisor","author":"Wojtczuk R.","year":"2008","journal-title":"Black Hat USA"},{"volume-title":"Invisible Things Lab","year":"2009","author":"Wojtczuk R.","key":"e_1_3_2_1_25_1"}],"event":{"name":"ACSAC '12: Annual Computer Security Applications Conference","sponsor":["ACSA Applied Computing Security Assoc"],"location":"Orlando Florida USA","acronym":"ACSAC '12"},"container-title":["Proceedings of the 28th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2420950.2420962","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,14]],"date-time":"2023-01-14T04:49:58Z","timestamp":1673671798000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2420950.2420962"}},"subtitle":["a bulletproof solution to forensic memory acquisition"],"short-title":[],"issued":{"date-parts":[[2012,12,3]]},"references-count":25,"alternative-id":["10.1145\/2420950.2420962","10.1145\/2420950"],"URL":"https:\/\/doi.org\/10.1145\/2420950.2420962","relation":{},"subject":[],"published":{"date-parts":[[2012,12,3]]},"assertion":[{"value":"2012-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}