{"id":"https://openalex.org/W2112127916","doi":"https://doi.org/10.1145/1866307.1866314","title":"Trail of bytes","display_name":"Trail of bytes","publication_year":2010,"publication_date":"2010-10-04","ids":{"openalex":"https://openalex.org/W2112127916","doi":"https://doi.org/10.1145/1866307.1866314","mag":"2112127916"},"language":"en","primary_location":{"id":"doi:10.1145/1866307.1866314","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1866307.1866314","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 17th ACM conference on Computer and communications security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063703305","display_name":"Srinivas Krishnan","orcid":null},"institutions":[{"id":"https://openalex.org/I114027177","display_name":"University of North Carolina at Chapel Hill","ror":"https://ror.org/0130frc33","country_code":"US","type":"education","lineage":["https://openalex.org/I114027177"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Srinivas Krishnan","raw_affiliation_strings":["University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","University of North Carolina at Chapel Hill , Chapel Hill, NC, USA"],"affiliations":[{"raw_affiliation_string":"University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]},{"raw_affiliation_string":"University of North Carolina at Chapel Hill , Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019527145","display_name":"Kevin Z. Snow","orcid":"https://orcid.org/0009-0007-3666-9880"},"institutions":[{"id":"https://openalex.org/I114027177","display_name":"University of North Carolina at Chapel Hill","ror":"https://ror.org/0130frc33","country_code":"US","type":"education","lineage":["https://openalex.org/I114027177"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kevin Z. Snow","raw_affiliation_strings":["University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","University of North Carolina at Chapel Hill , Chapel Hill, NC, USA"],"affiliations":[{"raw_affiliation_string":"University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]},{"raw_affiliation_string":"University of North Carolina at Chapel Hill , Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069862528","display_name":"Fabian Monrose","orcid":"https://orcid.org/0000-0002-9805-2217"},"institutions":[{"id":"https://openalex.org/I114027177","display_name":"University of North Carolina at Chapel Hill","ror":"https://ror.org/0130frc33","country_code":"US","type":"education","lineage":["https://openalex.org/I114027177"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fabian Monrose","raw_affiliation_strings":["University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","University of North Carolina at Chapel Hill , Chapel Hill, NC, USA"],"affiliations":[{"raw_affiliation_string":"University of North Carolina at Chapel Hill, Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]},{"raw_affiliation_string":"University of North Carolina at Chapel Hill , Chapel Hill, NC, USA","institution_ids":["https://openalex.org/I114027177"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5063703305"],"corresponding_institution_ids":["https://openalex.org/I114027177"],"apc_list":null,"apc_paid":null,"fwci":5.3942,"has_fulltext":false,"cited_by_count":49,"citation_normalized_percentile":{"value":0.96329918,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"50","last_page":"60"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8673740029335022},{"id":"https://openalex.org/keywords/byte","display_name":"Byte","score":0.8071398735046387},{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.6919106245040894},{"id":"https://openalex.org/keywords/computer-forensics","display_name":"Computer forensics","score":0.6339637041091919},{"id":"https://openalex.org/keywords/network-forensics","display_name":"Network forensics","score":0.554932177066803},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.5489547252655029},{"id":"https://openalex.org/keywords/digital-forensics","display_name":"Digital forensics","score":0.5318125486373901},{"id":"https://openalex.org/keywords/audit-trail","display_name":"Audit trail","score":0.4441315233707428},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3712831139564514},{"id":"https://openalex.org/keywords/audit","display_name":"Audit","score":0.3509202003479004},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2630946934223175},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.2613670229911804},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.2543034553527832},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.1765976846218109}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8673740029335022},{"id":"https://openalex.org/C43364308","wikidata":"https://www.wikidata.org/wiki/Q8799","display_name":"Byte","level":2,"score":0.8071398735046387},{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.6919106245040894},{"id":"https://openalex.org/C556601545","wikidata":"https://www.wikidata.org/wiki/Q878553","display_name":"Computer forensics","level":3,"score":0.6339637041091919},{"id":"https://openalex.org/C50747538","wikidata":"https://www.wikidata.org/wiki/Q7001032","display_name":"Network forensics","level":3,"score":0.554932177066803},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.5489547252655029},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.5318125486373901},{"id":"https://openalex.org/C80958533","wikidata":"https://www.wikidata.org/wiki/Q1047174","display_name":"Audit trail","level":3,"score":0.4441315233707428},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3712831139564514},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.3509202003479004},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2630946934223175},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.2613670229911804},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.2543034553527832},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.1765976846218109},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/1866307.1866314","is_oa":false,"landing_page_url":"https://doi.org/10.1145/1866307.1866314","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 17th ACM conference on Computer and communications security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6700000166893005,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":44,"referenced_works":["https://openalex.org/W23711711","https://openalex.org/W47175211","https://openalex.org/W73598622","https://openalex.org/W1491237615","https://openalex.org/W1546317334","https://openalex.org/W1559528097","https://openalex.org/W1576397915","https://openalex.org/W1641762327","https://openalex.org/W1813040609","https://openalex.org/W1883937078","https://openalex.org/W1985961858","https://openalex.org/W1993295335","https://openalex.org/W1993694077","https://openalex.org/W2008662722","https://openalex.org/W2037017056","https://openalex.org/W2093406244","https://openalex.org/W2104839312","https://openalex.org/W2112731379","https://openalex.org/W2114891701","https://openalex.org/W2115175195","https://openalex.org/W2125767749","https://openalex.org/W2125788329","https://openalex.org/W2125895608","https://openalex.org/W2129278597","https://openalex.org/W2131726714","https://openalex.org/W2132280055","https://openalex.org/W2140807364","https://openalex.org/W2154081981","https://openalex.org/W2159265516","https://openalex.org/W2164845301","https://openalex.org/W2166004296","https://openalex.org/W2168264487","https://openalex.org/W2295705535","https://openalex.org/W2337826830","https://openalex.org/W2398150230","https://openalex.org/W2911630587","https://openalex.org/W3150003982","https://openalex.org/W4206796831","https://openalex.org/W4230700735","https://openalex.org/W4239223658","https://openalex.org/W4244704438","https://openalex.org/W4245671428","https://openalex.org/W4255411440","https://openalex.org/W4391725268"],"related_works":["https://openalex.org/W4238452393","https://openalex.org/W2489557937","https://openalex.org/W2161391695","https://openalex.org/W3018602826","https://openalex.org/W2480188389","https://openalex.org/W4240498326","https://openalex.org/W4283205458","https://openalex.org/W4385257722","https://openalex.org/W2972427363","https://openalex.org/W2067681493"],"abstract_inverted_index":{"For":[0],"the":[1,49,58,72,76,95,98,119,123,135,145,170,174,180,208],"most":[2],"part,":[3],"forensic":[4,103,152],"analysis":[5],"of":[6,43,79,97,138,169,182],"computer":[7,80],"systems":[8],"requires":[9],"that":[10,60,105,162],"one":[11],"first":[12],"identify":[13],"suspicious":[14],"objects":[15,130,146],"or":[16],"events,":[17],"and":[18,33,108,133,166,173,211],"then":[19],"examine":[20],"them":[21],"in":[22,157],"enough":[23],"detail":[24],"to":[25,30,39,63,84,92,129,203],"form":[26],"a":[27,102,114,158,192,214],"hypothesis":[28],"as":[29],"their":[31],"cause":[32],"effect.":[34],"Sadly,":[35],"while":[36],"our":[37,183,198],"ability":[38],"gather":[40],"vast":[41],"amounts":[42],"data":[44,110],"has":[45,216],"improved":[46],"significantly":[47],"over":[48],"past":[50],"two":[51],"decades,":[52],"it":[53,71],"is":[54],"all":[55],"too":[56],"often":[57],"case":[59,194],"we":[61,69,90,185],"tend":[62],"lack":[64],"detailed":[65],"information":[66,206],"just":[67],"when":[68],"need":[70],"most.":[73],"Simply":[74],"put,":[75],"current":[77],"state":[78,96],"forensics":[81],"leaves":[82],"much":[83],"be":[85,201],"desired.":[86],"In":[87],"this":[88],"paper,":[89],"attempt":[91],"improve":[93],"on":[94,131],"art":[99],"by":[100,122],"providing":[101],"platform":[104,199],"transparently":[106],"monitors":[107,127],"records":[109,154],"access":[111],"events":[112,172],"within":[113],"virtualized":[115],"environment":[116],"using":[117],"only":[118],"abstractions":[120],"exposed":[121],"hypervisor.":[124],"Our":[125,151],"approach":[126],"accesses":[128,140],"disk":[132],"follows":[134],"causal":[136],"chain":[137],"these":[139,155],"across":[141],"processes,":[142],"even":[143],"after":[144,213],"are":[147],"copied":[148],"into":[149],"memory.":[150],"layer":[153],"transactions":[156],"version-based":[159],"audit":[160],"log":[161],"allows":[163],"for":[164],"faithful,":[165],"efficient,":[167],"reconstruction":[168],"recorded":[171],"changes":[175],"they":[176],"induced.":[177],"To":[178],"demonstrate":[179],"utility":[181],"approach,":[184],"provide":[186],"an":[187],"extensive":[188],"empirical":[189],"evaluation,":[190],"including":[191],"real-world":[193],"study":[195],"demonstrating":[196],"how":[197],"can":[200],"used":[202],"reconstruct":[204],"valuable":[205],"about":[207],"what,":[209],"when,":[210],"how,":[212],"compromised":[215],"been":[217],"detected.":[218]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":3},{"year":2018,"cited_by_count":5},{"year":2017,"cited_by_count":2},{"year":2016,"cited_by_count":5},{"year":2015,"cited_by_count":6},{"year":2014,"cited_by_count":5},{"year":2013,"cited_by_count":4},{"year":2012,"cited_by_count":6}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2016-06-24T00:00:00"}
