{"id":"https://openalex.org/W3095247050","doi":"https://doi.org/10.23919/mipro48935.2020.9245226","title":"Forensic analysis of Windows 10 Sandbox","display_name":"Forensic analysis of Windows 10 Sandbox","publication_year":2020,"publication_date":"2020-09-28","ids":{"openalex":"https://openalex.org/W3095247050","doi":"https://doi.org/10.23919/mipro48935.2020.9245226","mag":"3095247050"},"language":"en","primary_location":{"id":"doi:10.23919/mipro48935.2020.9245226","is_oa":false,"landing_page_url":"https://doi.org/10.23919/mipro48935.2020.9245226","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 43rd International Convention on Information, Communication and Electronic Technology (MIPRO)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5089507896","display_name":"A. Duranec","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"A. Duranec","raw_affiliation_strings":["INsig2 d.o.o., Zagreb, Croatia"],"affiliations":[{"raw_affiliation_string":"INsig2 d.o.o., Zagreb, Croatia","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050729385","display_name":"S. Gruicic","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"S. Gruicic","raw_affiliation_strings":["INsig2 d.o.o., Zagreb, Croatia"],"affiliations":[{"raw_affiliation_string":"INsig2 d.o.o., Zagreb, Croatia","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012687257","display_name":"Marinko \u017dagar","orcid":"https://orcid.org/0000-0002-4996-2978"},"institutions":[{"id":"https://openalex.org/I4210103466","display_name":"University of Applied Health Sciences","ror":"https://ror.org/019yxat94","country_code":"HR","type":"education","lineage":["https://openalex.org/I4210103466"]}],"countries":["HR"],"is_corresponding":false,"raw_author_name":"M. Zagar","raw_affiliation_strings":["Zagreb University of Applied Sciences, Zagreb, Croatia"],"affiliations":[{"raw_affiliation_string":"Zagreb University of Applied Sciences, Zagreb, Croatia","institution_ids":["https://openalex.org/I4210103466"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5089507896"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.5338,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.75671324,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"1224","last_page":"1229"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9865999817848206,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/sandbox","display_name":"Sandbox (software development)","score":0.9620181322097778},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7411367893218994},{"id":"https://openalex.org/keywords/microsoft-windows","display_name":"Microsoft Windows","score":0.6000725626945496},{"id":"https://openalex.org/keywords/documentation","display_name":"Documentation","score":0.5687779188156128},{"id":"https://openalex.org/keywords/windows-vista","display_name":"Windows Vista","score":0.556509256362915},{"id":"https://openalex.org/keywords/digital-forensics","display_name":"Digital forensics","score":0.510342538356781},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.5054090023040771},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.44212740659713745},{"id":"https://openalex.org/keywords/open-source","display_name":"Open source","score":0.415441632270813},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.41349682211875916},{"id":"https://openalex.org/keywords/event","display_name":"Event (particle physics)","score":0.4103620946407318},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.24588221311569214}],"concepts":[{"id":"https://openalex.org/C167981075","wikidata":"https://www.wikidata.org/wiki/Q2667186","display_name":"Sandbox (software development)","level":2,"score":0.9620181322097778},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7411367893218994},{"id":"https://openalex.org/C508378895","wikidata":"https://www.wikidata.org/wiki/Q1406","display_name":"Microsoft Windows","level":3,"score":0.6000725626945496},{"id":"https://openalex.org/C56666940","wikidata":"https://www.wikidata.org/wiki/Q788790","display_name":"Documentation","level":2,"score":0.5687779188156128},{"id":"https://openalex.org/C527868296","wikidata":"https://www.wikidata.org/wiki/Q11230","display_name":"Windows Vista","level":4,"score":0.556509256362915},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.510342538356781},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.5054090023040771},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.44212740659713745},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.415441632270813},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.41349682211875916},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.4103620946407318},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.24588221311569214},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.23919/mipro48935.2020.9245226","is_oa":false,"landing_page_url":"https://doi.org/10.23919/mipro48935.2020.9245226","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 43rd International Convention on Information, Communication and Electronic Technology (MIPRO)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7300000190734863}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":2,"referenced_works":["https://openalex.org/W24678375","https://openalex.org/W4236740106"],"related_works":["https://openalex.org/W2462491885","https://openalex.org/W2495294848","https://openalex.org/W4256444941","https://openalex.org/W2339609355","https://openalex.org/W26165096","https://openalex.org/W2482084385","https://openalex.org/W2281065640","https://openalex.org/W2490113473","https://openalex.org/W2494279214","https://openalex.org/W232475811"],"abstract_inverted_index":{"With":[0],"each":[1],"Windows":[2,37,42,95],"operating":[3],"system":[4],"Microsoft":[5],"introduces":[6],"new":[7,68],"features":[8,14],"to":[9,18,80],"its":[10],"users.":[11],"Newly":[12],"added":[13,74],"present":[15],"a":[16,44,106,117],"challenge":[17],"digital":[19,63],"forensics":[20],"examiners":[21,65],"as":[22,105,142,144],"they":[23],"are":[24,66],"not":[25],"analyzed":[26],"or":[27],"tested":[28],"enough.":[29],"One":[30],"of":[31,53,57,108,124,132,136],"the":[32,54,58,88,109,113,122,130,137,149],"latest":[33],"features,":[34],"introduced":[35],"in":[36],"10":[38],"version":[39],"1909":[40],"is":[41],"Sandbox;":[43],"lightweight,":[45],"temporary,":[46],"environment":[47,126],"for":[48,148],"running":[49],"untrusted":[50],"applications.":[51],"Because":[52],"temporary":[55],"nature":[56],"Sandbox":[59,114],"and":[60,97,134],"insufficient":[61],"documentation,":[62],"forensic":[64],"facing":[67],"challenges":[69],"when":[70],"examining":[71],"this":[72,86],"newly":[73],"feature":[75,115],"which":[76],"can":[77],"be":[78,91,128,140],"used":[79,147],"hide":[81],"different":[82,94],"illegal":[83],"activities.":[84],"Throughout":[85],"paper,":[87],"focus":[89],"will":[90,127,139],"on":[92,116],"analyzing":[93],"artifacts":[96],"event":[98],"logs,":[99],"with":[100,112],"various":[101],"tools,":[102],"left":[103],"behind":[104],"result":[107],"user":[110],"interaction":[111],"clear":[118],"virtual":[119],"environment.":[120],"Additionally,":[121],"setup":[123],"testing":[125,133],"explained,":[129],"results":[131],"interpretation":[135],"findings":[138],"presented,":[141],"well":[143],"open-source":[145],"tools":[146],"analysis.":[150]},"counts_by_year":[{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
