{"id":"https://openalex.org/W2288565242","doi":"https://doi.org/10.1109/iscc.2015.7405522","title":"Forensic analysis of windows user space applications through heap allocations","display_name":"Forensic analysis of windows user space applications through heap allocations","publication_year":2015,"publication_date":"2015-07-01","ids":{"openalex":"https://openalex.org/W2288565242","doi":"https://doi.org/10.1109/iscc.2015.7405522","mag":"2288565242"},"language":"en","primary_location":{"id":"doi:10.1109/iscc.2015.7405522","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iscc.2015.7405522","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE Symposium on Computers and Communication (ISCC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5113800269","display_name":"Michael Cohen","orcid":null},"institutions":[{"id":"https://openalex.org/I4210100430","display_name":"Google (Switzerland)","ror":"https://ror.org/014f9c269","country_code":"CH","type":"company","lineage":["https://openalex.org/I1291425158","https://openalex.org/I4210100430","https://openalex.org/I4210128969"]}],"countries":["CH"],"is_corresponding":true,"raw_author_name":"Michael Cohen","raw_affiliation_strings":["Google Inc., Zurich, Switzerland"],"affiliations":[{"raw_affiliation_string":"Google Inc., Zurich, Switzerland","institution_ids":["https://openalex.org/I4210100430"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5113800269"],"corresponding_institution_ids":["https://openalex.org/I4210100430"],"apc_list":null,"apc_paid":null,"fwci":5.6803,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.96049195,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"3a","issue":null,"first_page":"237","last_page":"244"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/heap","display_name":"Heap (data structure)","score":0.822195827960968},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7095414400100708},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.19660919904708862}],"concepts":[{"id":"https://openalex.org/C134757568","wikidata":"https://www.wikidata.org/wiki/Q274089","display_name":"Heap (data structure)","level":2,"score":0.822195827960968},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7095414400100708},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.19660919904708862}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/iscc.2015.7405522","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iscc.2015.7405522","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2015 IEEE Symposium on Computers and Communication (ISCC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.4000000059604645,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W134076915","https://openalex.org/W1531428478","https://openalex.org/W1916709771","https://openalex.org/W2072863245","https://openalex.org/W2081989812","https://openalex.org/W2091452626","https://openalex.org/W2092935428","https://openalex.org/W2106270115","https://openalex.org/W2113854927","https://openalex.org/W2128213437","https://openalex.org/W2128576967","https://openalex.org/W2229662347","https://openalex.org/W2462319771","https://openalex.org/W2730626270"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W3158777280","https://openalex.org/W2093687902","https://openalex.org/W2949158926","https://openalex.org/W4301885003","https://openalex.org/W2005058894","https://openalex.org/W1996981508","https://openalex.org/W1989205740","https://openalex.org/W4387561287","https://openalex.org/W2951476362"],"abstract_inverted_index":{"Memory":[0,74],"analysis":[1,14,31,51,60,80,146],"is":[2,128],"now":[3],"used":[4],"routinely":[5],"for":[6],"incident":[7],"response":[8],"and":[9,52,95,113],"forensic":[10,27],"applications.":[11,64],"Current":[12],"memory":[13],"techniques":[15],"are":[16],"very":[17],"effective":[18],"in":[19,50,58,96],"finding":[20],"kernel":[21],"artifacts":[22],"of":[23,32,47,61,69,81,107],"significance":[24],"to":[25,71,109,130,148],"the":[26,30,45,59,72,79,92,98,121,144,150,154],"investigator.":[28],"However,":[29],"user":[33,62,133],"space":[34,63,134],"applications":[35],"has":[36],"not":[37],"received":[38],"enough":[39],"attention":[40],"so":[41],"far.":[42],"We":[43,65,87,103,117],"identify":[44],"lack":[46],"pagefile":[48],"support":[49],"acquisition":[53],"as":[54,124],"a":[55,67,105,125],"major":[56],"hurdle":[57],"present":[66,104],"set":[68,106],"patches":[70],"Rekall":[73],"Forensic":[75],"platform":[76],"that":[77,119],"enable":[78],"pagefiles":[82],"on":[83],"all":[84],"operating":[85],"systems.":[86],"then":[88],"continue":[89],"by":[90,139,153],"studying":[91],"process":[93],"heaps,":[94],"particular":[97],"Windows":[99],"userspace":[100],"heap":[101,111,122,145],"allocator.":[102],"plugins":[108],"enumerate":[110],"allocations":[112,123,151],"discover":[114],"internal":[115],"references.":[116],"demonstrate":[118],"using":[120],"guide,":[126],"it":[127],"easier":[129],"reverse":[131],"engineer":[132],"private":[135],"data":[136],"structure":[137],"simply":[138],"observation.":[140],"Finally,":[141],"we":[142],"apply":[143],"technique":[147],"study":[149],"made":[152],"windows":[155],"DNS":[156],"client":[157],"cache.":[158]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":1},{"year":2019,"cited_by_count":2},{"year":2018,"cited_by_count":2},{"year":2017,"cited_by_count":4},{"year":2016,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
