{"id":"W2118558829","doi":"10.1016/j.diin.2007.06.010","title":"Forensic memory analysis: From stack and code to execution history","year":2007,"lang":"en","type":"article","venue":"Digital Investigation","topic":"Security and Verification in Computing","field":"Computer Science","cited_by":34,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University","funders":"","keywords":"Computer science; Thread (computing); Call stack; Stack (abstract data type); Process (computing); Virtual memory; Operating system; Programming language; Parallel computing; Memory management; Overlay","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001795747,0.000796774,0.0005651176,0.003828235,0.0007532024,0.003113632,0.001410913,0.001147656,0.001979275],"category_scores_gemma":[0.009806622,0.0006110737,0.0009880272,0.001457697,0.003664023,0.00688668,0.002245011,0.001214459,0.0004313785],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001118082,"about_ca_system_score_gemma":0.001679679,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003024624,"about_ca_topic_score_gemma":0.001435071,"domain_scores_codex":[0.9985523,0.0003275185,0.00009655095,0.000266676,0.0005615996,0.0001954086],"domain_scores_gemma":[0.9953716,0.001839842,0.0007768631,0.001308127,0.0006085034,0.00009504913],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"not_applicable","study_design_scores_codex":[0.0004710339,0.0001935309,0.01853928,0.0005892846,0.0001816218,0.001898517,0.002452133,0.136765,0.0439361,0.4956001,0.002867717,0.2965057],"study_design_scores_gemma":[0.00003206467,0.0001635616,0.003829462,0.0002843259,0.0001463194,0.001174364,0.0007484286,0.5457341,0.06158458,0.3735794,0.01261055,0.0001128737],"study_design_candidate":"not_applicable","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.08352719,0.001082392,0.9090225,0.0004982635,0.00003591845,0.0001010867,0.0002961661,0.002153784,0.003282823],"genre_scores_gemma":[0.7855122,0.001089043,0.2093779,0.0001822391,0.000083138,0.0001335207,0.0004425516,0.000473709,0.002705664],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.003828235,"threshold_uncertainty_score":0.009496987,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03766217992191722,"score_gpt":0.2444065722086764,"score_spread":0.2067443922867592,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}