{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:18:53Z","timestamp":1783610333433,"version":"3.55.0"},"publisher-location":"Boston, MA","reference-count":29,"publisher":"Springer US","isbn-type":[{"value":"9780387687667","type":"print"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-0-387-68768-1_4","type":"book-chapter","created":{"date-parts":[[2007,10,22]],"date-time":"2007-10-22T11:27:09Z","timestamp":1193052429000},"page":"65-88","source":"Crossref","is-referenced-by-count":99,"title":["Automatically Identifying Trigger-based Behavior in Malware"],"prefix":"10.1007","author":[{"given":"David","family":"Brumley","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cody","family":"Hartwig","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenkai","family":"Liang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"James","family":"Newsome","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dawn","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heng","family":"Yin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","reference":[{"key":"4_CR1","unstructured":"Blazingtools perfect keylogger. http:\/\/www.blazingtools.com\/bpk.html."},{"key":"4_CR2","unstructured":"QEMU. http:\/\/www.qemu.org."},{"key":"4_CR3","unstructured":"Tribal flood network. http:\/\/www.cert.org\/incident_notes\/IN-99-07.html."},{"key":"4_CR4","unstructured":"David Brumley, Cody Hartwig, Min Gyang Kang, Zhenkai Liang, James Newsome, Pongsin Poosankam, Dawn Song, and Heng Yin. Automatically dissecting malicious binaries. Technical Report CMU-CS-07-133, 2007."},{"key":"4_CR5","unstructured":"David Brumley and James Newsome. Alias analysis for assembly. Technical Report CMU-CS-06-180, Carnegie Mellon University School of Computer Science, 2006."},{"key":"4_CR6","doi-asserted-by":"crossref","unstructured":"Cristian Cadar, Vijay Ganesh, Peter Pawlowski, David Dill, and Dawson Engler. EXE: A system for automatically generating inputs of death using symbolic execution. In Proceedings of the 13th ACM Conference on Computer and Communications Security (CCS), October 2006.","DOI":"10.1145\/1180405.1180445"},{"key":"4_CR7","doi-asserted-by":"crossref","unstructured":"Edmund Clarke, Daniel Kroening, and Flavio Lerda. A tool for checking ANSI-C programs. In Kurt Jensen and Andreas Podelski, editors, Tools and Algorithms for the Construction and Analysis of Systems (TACAS 2004), volume 2988 of Lecture Notes in Computer Science, pages 168\u2013176. Springer, 2004.","DOI":"10.1007\/978-3-540-24730-2_15"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Jedidiah R. Crandall, Gary Wassermann, Daniela A. S. de Oliveira, Zhendong Su, S. Felix Wu, and Frederic T. Chong. Temporal search: Detecting hidden malware timebombs with virtual machines. In Proceedings of the Twelfth International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS XII), October 2006.","DOI":"10.1145\/1168857.1168862"},{"key":"4_CR9","unstructured":"Tony LeePeter Ferrie. Win32.Netsky.C. http:\/\/www.symantec.com\/ security_response\/writeup.jsp?docid=2004-022417%-4628-99."},{"key":"4_CR10","doi-asserted-by":"crossref","unstructured":"C. Flanagan and J.B. Saxe. Avoiding exponential explosion: Generating compact verification conditions. In Proceedings of the 28th ACM Symposium on the Principles of Programming Languages (POPL), 2001.","DOI":"10.1145\/360204.360220"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Cormac Flanagan, K. Rustan M. Leino, Mark Lillibridge, Greg Nelson, James B. Saxe, and Raymie Stata. Estended static checking for java. In ACM Conference on the Programming Language Design and Implementation (PLDI), 2002.","DOI":"10.1145\/512529.512558"},{"key":"4_CR12","unstructured":"Vijay Ganesh and David Dill. STP: A decision procedure for bitvectors and arrays. http:\/\/theory.stanford.edu\/~vganesh\/stp.html."},{"key":"4_CR13","unstructured":"Scott Gettis. W32.Mydoom.B@mm. http:\/\/www.symantec.com\/security_ response\/writeup.jsp?docid=2004-022011%-2447-99."},{"key":"4_CR14","doi-asserted-by":"crossref","unstructured":"Patrice Godefroid, Nils Klarlund, and Koushik Sen. DART: Directed automated random testing. In Proc. of the 2005 Programming Language Design and Implementation Conference (PLDI), 2005.","DOI":"10.1145\/1065010.1065036"},{"key":"4_CR15","unstructured":"Kevin Ha. Keylogger.Stawin. http:\/\/www.symantec.com\/security_ response\/writeup.jsp?docid=2004-012915%-2315-99."},{"key":"4_CR16","unstructured":"Neal Hindocha. Win32.Netsky.D. http:\/\/www.symantec.com\/security_ response\/writeup.jsp?docid=2004-030110%-0232-99."},{"key":"4_CR17","first-page":"386","volume":"19","author":"King. James","year":"1976","unstructured":"James King. Symbolic execution and program testing. Communications of the ACM, 19:386\u2013394, 1976.","journal-title":"Communications of the ACM"},{"key":"4_CR18","unstructured":"McAfee. W97M\/Opey.C. ttp:\/\/vil.nai.com\/vil\/content\/v_10290.htm."},{"key":"4_CR19","doi-asserted-by":"crossref","unstructured":"Andreas Moser, Christopher Kruegel, and Engin Kirda. Exploring multiple execution paths for malware analysis. In IEEE Symposium on Security and Privacy. IEEE Press, 2007.","DOI":"10.1109\/SP.2007.17"},{"key":"4_CR20","doi-asserted-by":"crossref","unstructured":"James Newsome, David Brumley, Jason Franklin, and Dawn Song. Replayer: Automatic protocol replay by binary analysis. In Proceedings of the13$th$ACM Conference on Computer and and Communications Security (CCS), October 2006.","DOI":"10.1145\/1180405.1180444"},{"key":"4_CR21","unstructured":"Benjamin C Pierce. Types and Programming Languages. The MIT Press, 2002."},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Koushik Sen, Darko Marinov, and Gul Agha. CUTE: A concolic unit testing engine for c. In ACM SIGSOFT Sympsoium on the Foundations of Software Engineering, 2005.","DOI":"10.1145\/1081706.1081750"},{"key":"4_CR23","unstructured":"Symantec. Spyware.e2give. http:\/\/www.symantec.com\/security response\/ writeup.jsp?docid=2004-102614-1006-99."},{"key":"4_CR24","unstructured":"Symantec. Xeram.1664. http:\/\/www.symantec.com\/security_response\/ writeup.jsp?docid=2000-121913-2839-99."},{"key":"4_CR25","unstructured":"United States Department of Justice Press Release. Former computer network administrator at new jersey high-tech firm sentenced to 41 months for unleashing $10 million computer \u201ctime bomb\u201d. http:\/\/www.usdoj.gov\/criminal\/cybercrime\/lloydSent.htm."},{"key":"4_CR26","unstructured":"United States Department of Justice Press Release. Former lance, inc. employee sentenced to 24 months and ordered to pay $194,609 restitution in computer fraud case. http:\/\/www.usdoj.gov\/criminal\/cybercrime\/SullivanSent.htm."},{"key":"4_CR27","unstructured":"United States Department of Justice Press Release. Former technology manager sentenced to a year in prison for computer hacking offense. http:\/\/www.usdoj.gov\/criminal\/cybercrime\/sheaSent.htm."},{"key":"4_CR28","doi-asserted-by":"crossref","unstructured":"Yichen Xie and Alex Aiken. Context-and path-sensitive memory leak detection. ACM SIGSOFT Software Engineering Notes, 30, 2005.","DOI":"10.1145\/1095430.1081728"},{"key":"4_CR29","doi-asserted-by":"crossref","unstructured":"Junfeng Yang, Can Sar, Paul Twohey, Cristian Cadar, and Dawson Engler. Automatically generating malicious disks using symbolic execution. In IEEE Symposium on Security and Privacy, 2006.","DOI":"10.1109\/SP.2006.7"}],"container-title":["Advances in Information Security","Botnet Detection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-68768-1_4.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,29]],"date-time":"2021-04-29T04:04:34Z","timestamp":1619669074000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-0-387-68768-1_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9780387687667"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-68768-1_4","relation":{},"subject":[]}}