{"id":"https://openalex.org/W1976273323","doi":"https://doi.org/10.1109/spw.2013.17","title":"Digital Forensic Reconstruction of a Program Action","display_name":"Digital Forensic Reconstruction of a Program Action","publication_year":2013,"publication_date":"2013-05-01","ids":{"openalex":"https://openalex.org/W1976273323","doi":"https://doi.org/10.1109/spw.2013.17","mag":"1976273323"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw.2013.17","pdf_url":"https://ieeexplore.ieee.org/ielx7/6564486/6565207/06565239.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://ieeexplore.ieee.org/ielx7/6564486/6565207/06565239.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5088653270","display_name":"Ahmed F. Shosha","orcid":null},"institutions":[{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Ahmed F. Shosha","raw_affiliation_strings":["Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland","institution_ids":["https://openalex.org/I100930933"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035151093","display_name":"Lee Tobin","orcid":"https://orcid.org/0000-0003-3038-6867"},"institutions":[{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Lee Tobin","raw_affiliation_strings":["Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland","institution_ids":["https://openalex.org/I100930933"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5052351535","display_name":"Pavel Gladyshev","orcid":"https://orcid.org/0000-0002-7449-4475"},"institutions":[{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Pavel Gladyshev","raw_affiliation_strings":["Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"Sch. of Comput. Sci. & Inf., Univ. Coll. Dublin, Dublin, Ireland","institution_ids":["https://openalex.org/I100930933"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.407,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":7,"citation_normalized_percentile":{"value":0.727754,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":83,"max":84},"biblio":{"volume":null,"issue":null,"first_page":"119","last_page":"122"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9917,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/suspect","display_name":"Suspect","score":0.9596428},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.7975608},{"id":"https://openalex.org/keywords/computer-forensics","display_name":"Computer forensics","score":0.7158439},{"id":"https://openalex.org/keywords/invocation","display_name":"Invocation","score":0.60185754},{"id":"https://openalex.org/keywords/digital-evidence","display_name":"Digital evidence","score":0.594993}],"concepts":[{"id":"https://openalex.org/C2778223634","wikidata":"https://www.wikidata.org/wiki/Q224952","display_name":"Suspect","level":2,"score":0.9596428},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.7975608},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.7593941},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7387228},{"id":"https://openalex.org/C556601545","wikidata":"https://www.wikidata.org/wiki/Q878553","display_name":"Computer forensics","level":3,"score":0.7158439},{"id":"https://openalex.org/C2780262971","wikidata":"https://www.wikidata.org/wiki/Q44554","display_name":"Law enforcement","level":2,"score":0.69986635},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.63579345},{"id":"https://openalex.org/C140505726","wikidata":"https://www.wikidata.org/wiki/Q495304","display_name":"Forensic science","level":2,"score":0.63080484},{"id":"https://openalex.org/C2776527387","wikidata":"https://www.wikidata.org/wiki/Q1671839","display_name":"Invocation","level":2,"score":0.60185754},{"id":"https://openalex.org/C2781357168","wikidata":"https://www.wikidata.org/wiki/Q5276084","display_name":"Digital evidence","level":3,"score":0.594993},{"id":"https://openalex.org/C2777855551","wikidata":"https://www.wikidata.org/wiki/Q12310021","display_name":"Subject (documents)","level":2,"score":0.56717706},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.494416},{"id":"https://openalex.org/C2779777834","wikidata":"https://www.wikidata.org/wiki/Q4202277","display_name":"Enforcement","level":2,"score":0.429628},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3300373},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.20740563},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.19070166},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.18967804},{"id":"https://openalex.org/C73484699","wikidata":"https://www.wikidata.org/wiki/Q161733","display_name":"Criminology","level":1,"score":0.16939384},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.12921354},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.070858836},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C166957645","wikidata":"https://www.wikidata.org/wiki/Q23498","display_name":"Archaeology","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C95457728","wikidata":"https://www.wikidata.org/wiki/Q309","display_name":"History","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw.2013.17","pdf_url":"https://ieeexplore.ieee.org/ielx7/6564486/6565207/06565239.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw.2013.17","pdf_url":"https://ieeexplore.ieee.org/ielx7/6564486/6565207/06565239.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"score":0.8,"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":15,"referenced_works":["https://openalex.org/W1491178396","https://openalex.org/W1497716074","https://openalex.org/W1544837488","https://openalex.org/W1553894716","https://openalex.org/W1565879960","https://openalex.org/W1721908487","https://openalex.org/W1842369958","https://openalex.org/W1978495386","https://openalex.org/W2002089154","https://openalex.org/W2066220442","https://openalex.org/W2119251836","https://openalex.org/W3123678609","https://openalex.org/W4302339081","https://openalex.org/W493438","https://openalex.org/W598294359"],"related_works":["https://openalex.org/W93745046","https://openalex.org/W4283205458","https://openalex.org/W4247205791","https://openalex.org/W4244711387","https://openalex.org/W4242633011","https://openalex.org/W4238452393","https://openalex.org/W2598491911","https://openalex.org/W2536999591","https://openalex.org/W2489557937","https://openalex.org/W2181728705"],"abstract_inverted_index":{"Forensic":[0],"analysis":[1,50],"of":[2,20,90],"a":[3,7,21,26,48,100],"suspect":[4,22,53],"program":[5,23],"is":[6,60],"daily":[8],"challenge":[9],"encounters":[10],"forensic":[11,49,70,88],"analysts":[12],"and":[13,32,72,92],"law-enforcement.":[14],"It":[15],"requires":[16],"determining":[17],"the":[18,42],"behavior":[19],"found":[24],"in":[25,41,55,87,99],"computer":[27],"system":[28,101],"subject":[29,102],"to":[30,34,66,103],"investigation":[31],"attempting":[33],"reconstruct":[35,67],"actions":[36,71,84],"that":[37],"have":[38],"been":[39],"invoked":[40],"system.":[43],"In":[44],"this":[45],"research":[46],"paper,":[47],"approach":[51,64],"for":[52],"programs":[54],"an":[56,96],"executable":[57],"binary":[58],"form":[59],"introduced.":[61],"The":[62],"proposed":[63],"aims":[65],"high":[68],"level":[69,78],"approximate":[73],"action":[74,97],"arguments":[75],"from":[76],"low":[77],"machine":[79],"instructions;":[80],"That":[81],"is,":[82],"reconstructed":[83],"will":[85],"assist":[86],"inferences":[89],"evidence":[91],"traces":[93],"caused":[94],"by":[95],"invocation":[98],"forensics":[104],"investigation.":[105]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W1976273323","counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":1},{"year":2013,"cited_by_count":1}],"updated_date":"2024-12-08T23:47:53.814920","created_date":"2016-06-24"}