{"id":"https://openalex.org/W4367042031","doi":"https://doi.org/10.1109/drcn57075.2023.10108330","title":"Forensic Investigation Using RAM Analysis on the Hadoop Distributed File System","display_name":"Forensic Investigation Using RAM Analysis on the Hadoop Distributed File System","publication_year":2023,"publication_date":"2023-04-17","ids":{"openalex":"https://openalex.org/W4367042031","doi":"https://doi.org/10.1109/drcn57075.2023.10108330"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/drcn57075.2023.10108330","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://napier-repository.worktribe.com/file/3061435/1/Forensic%20Investigation%20Using%20RAM%20Analysis%20On%20The%20Hadoop%20Distributed%20File%20System%20%28accepted%20version%29","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5110045668","display_name":"Stuart Laing","orcid":null},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Stuart Laing","raw_affiliation_strings":["School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008952606","display_name":"Robert Ludwiniak","orcid":null},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Robert Ludwiniak","raw_affiliation_strings":["School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041042697","display_name":"Brahim El Boudani","orcid":"https://orcid.org/0000-0001-5097-5808"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Brahim El Boudani","raw_affiliation_strings":["School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029353215","display_name":"Christos Chrysoulas","orcid":"https://orcid.org/0000-0001-9817-003X"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Christos Chrysoulas","raw_affiliation_strings":["School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom","institution_ids":["https://openalex.org/I251738"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079033333","display_name":"George Ubakanma","orcid":null},"institutions":[{"id":"https://openalex.org/I28257850","display_name":"London South Bank University","ror":"https://ror.org/02vwnat91","country_code":"GB","type":"education","lineage":["https://openalex.org/I28257850"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"George Ubakanma","raw_affiliation_strings":["School of Engineering, London South Bank University, London, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Engineering, London South Bank University, London, United Kingdom","institution_ids":["https://openalex.org/I28257850"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5082150685","display_name":"Nikolaos Pitropakis","orcid":"https://orcid.org/0000-0002-3392-9970"},"institutions":[{"id":"https://openalex.org/I251738","display_name":"Edinburgh Napier University","ror":"https://ror.org/03zjvnn91","country_code":"GB","type":"education","lineage":["https://openalex.org/I251738"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Nikolaos Pitropakis","raw_affiliation_strings":["School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom"],"affiliations":[{"raw_affiliation_string":"School of Computing, Engineering and the Build Environment, Edinburgh Napier University, Edinburgh, United Kingdom","institution_ids":["https://openalex.org/I251738"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":67},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.9945,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/heap","display_name":"Heap (data structure)","score":0.43724406},{"id":"https://openalex.org/keywords/distributed-file-system","display_name":"Distributed File System","score":0.41912314}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8062793},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.6583276},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5715107},{"id":"https://openalex.org/C93518851","wikidata":"https://www.wikidata.org/wiki/Q180160","display_name":"Metadata","level":2,"score":0.5656193},{"id":"https://openalex.org/C2780940931","wikidata":"https://www.wikidata.org/wiki/Q174989","display_name":"File system","level":2,"score":0.55698913},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.5395817},{"id":"https://openalex.org/C548217200","wikidata":"https://www.wikidata.org/wiki/Q251","display_name":"Java","level":2,"score":0.5199819},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.47654086},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.46346158},{"id":"https://openalex.org/C134757568","wikidata":"https://www.wikidata.org/wiki/Q274089","display_name":"Heap (data structure)","level":2,"score":0.43724406},{"id":"https://openalex.org/C152043487","wikidata":"https://www.wikidata.org/wiki/Q1229600","display_name":"Distributed File System","level":2,"score":0.41912314},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/drcn57075.2023.10108330","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://napier-repository.worktribe.com/file/3061435/1/Forensic%20Investigation%20Using%20RAM%20Analysis%20On%20The%20Hadoop%20Distributed%20File%20System%20%28accepted%20version%29","pdf_url":"https://napier-repository.worktribe.com/file/3061435/1/Forensic%20Investigation%20Using%20RAM%20Analysis%20On%20The%20Hadoop%20Distributed%20File%20System%20%28accepted%20version%29","source":{"id":"https://openalex.org/S4306402591","display_name":"Edinburgh Napier Research Repository (Edinburgh Napier University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I251738","host_organization_name":"Edinburgh Napier University","host_organization_lineage":["https://openalex.org/I251738"],"host_organization_lineage_names":["Edinburgh Napier University"],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://napier-repository.worktribe.com/file/3061435/1/Forensic%20Investigation%20Using%20RAM%20Analysis%20On%20The%20Hadoop%20Distributed%20File%20System%20%28accepted%20version%29","pdf_url":"https://napier-repository.worktribe.com/file/3061435/1/Forensic%20Investigation%20Using%20RAM%20Analysis%20On%20The%20Hadoop%20Distributed%20File%20System%20%28accepted%20version%29","source":{"id":"https://openalex.org/S4306402591","display_name":"Edinburgh Napier Research Repository (Edinburgh Napier University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I251738","host_organization_name":"Edinburgh Napier University","host_organization_lineage":["https://openalex.org/I251738"],"host_organization_lineage_names":["Edinburgh Napier University"],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":6,"referenced_works":["https://openalex.org/W2232576564","https://openalex.org/W2504813455","https://openalex.org/W2593654527","https://openalex.org/W2935961537","https://openalex.org/W2942435169","https://openalex.org/W2968402000"],"related_works":["https://openalex.org/W3042976586","https://openalex.org/W2571822082","https://openalex.org/W2488366707","https://openalex.org/W2364223899","https://openalex.org/W2225892199","https://openalex.org/W2168643770","https://openalex.org/W2069029637","https://openalex.org/W2060141855","https://openalex.org/W2036593806","https://openalex.org/W1480425691"],"abstract_inverted_index":{"The":[0,24,71,123],"usage":[1],"of":[2,49,82,102,144],"cloud":[3,35],"systems":[4],"is":[5,29],"at":[6],"an":[7],"all-time":[8],"high,":[9],"and":[10,37,58,79,136],"with":[11,38],"more":[12],"organizations":[13,39],"reaching":[14],"for":[15,54,99],"Big":[16],"Data":[17],"the":[18,46,67,80,83,118,141,145],"forensic":[19,47],"implications":[20],"must":[21],"be":[22,95],"analyzed.":[23],"Hadoop":[25,55,107],"Distributed":[26],"File":[27],"System":[28],"widely":[30],"used":[31],"both":[32],"as":[33,117],"a":[34,50,96,106],"service":[36],"implementing":[40],"it":[41,60],"themselves.":[42],"This":[43,88],"paper":[44],"analyzed":[45],"viability":[48],"RAM":[51,72,84,92],"analysis":[52,73,85,93,126],"method":[53],"based":[56],"investigations":[57],"compared":[59],"against":[61],"targeted":[62,124],"process":[63,125],"data":[64],"dumping":[65],"through":[66,76],"Java":[68],"heap":[69],"information.":[70],"was":[74,110],"done":[75],"string":[77],"searching":[78],"use":[81],"tool":[86,98],"Volatility.":[87],"work":[89],"found":[90],"that":[91],"can":[94],"valuable":[97],"discovering":[100],"artefacts":[101],"deleted":[103,134],"resources":[104,135],"from":[105],"cluster":[108],"but":[109],"unable":[111],"to":[112,120,128],"discover":[113],"further":[114],"information":[115,132],"such":[116],"block":[119],"node":[121],"mapping.":[122],"managed":[127],"provide":[129],"some":[130],"partial":[131],"about":[133],"produce":[137],"important":[138],"metadata":[139],"on":[140],"current":[142],"state":[143],"file":[146],"system.":[147]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4367042031","counts_by_year":[],"updated_date":"2025-01-07T01:24:15.574555","created_date":"2023-04-27"}