{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,25]],"date-time":"2026-04-25T17:31:15Z","timestamp":1777138275919,"version":"3.51.4"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030004699","type":"print"},{"value":"9783030004705","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-00470-5_31","type":"book-chapter","created":{"date-parts":[[2018,9,6]],"date-time":"2018-09-06T06:43:19Z","timestamp":1536216199000},"page":"670-690","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["ShadowMonitor: An Effective In-VM Monitoring Framework with Hardware-Enforced Isolation"],"prefix":"10.1007","author":[{"given":"Bin","family":"Shi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xudong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyu","family":"Hao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haiying","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,7]]},"reference":[{"key":"31_CR1","unstructured":"AMD64 architecture programmers manual"},{"key":"31_CR2","unstructured":"Intel 64 and IA-32 architectures software developers manual"},{"key":"31_CR3","unstructured":"Ltrace. \nhttps:\/\/en.wikipedia.org\/wiki\/Ltrace"},{"key":"31_CR4","unstructured":"Qemu-kvm. \nhttp:\/\/www.qemu-project.org"},{"key":"31_CR5","unstructured":"Strace. \nhttps:\/\/en.wikipedia.org\/wiki\/Strace"},{"key":"31_CR6","doi-asserted-by":"crossref","unstructured":"Xiang, G., Jin, H., Zou, D., Zhang, X., Wen, S., Zhao, F.: Vmdriver: a driver-based monitoring mechanism for virtualization. In: 29th IEEE Symposium on Reliable Distributed Systems (SRDS 2010) (2010)","DOI":"10.1109\/SRDS.2010.38"},{"key":"31_CR7","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: The Network and Distributed System Security Symposium, NDSS 2003 (2003)"},{"key":"31_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/978-3-642-33338-5_2","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"M Carbone","year":"2012","unstructured":"Carbone, M., Conover, M., Montague, B., Lee, W.: Secure and robust monitoring of virtual machines through guest-assisted introspection. In: Balzarotti, D., Stolfo, S.J., Cova, M. (eds.) RAID 2012. LNCS, vol. 7462, pp. 22\u201341. Springer, Heidelberg (2012). \nhttps:\/\/doi.org\/10.1007\/978-3-642-33338-5_2"},{"key":"31_CR9","doi-asserted-by":"crossref","unstructured":"Criswell, J., et al.: Kcofi: complete control-flow integrity for commodity operating system kernels. In: 2014 IEEE Symposium on Security and Privacy, SP 2014 (2014)","DOI":"10.1109\/SP.2014.26"},{"key":"31_CR10","doi-asserted-by":"publisher","unstructured":"Criswell, J., et al.: Virtual ghost: protecting applications from hostile operating systems. In: Proceedings of ASPLOS 2014, pp. 81\u201396. ACM (2014). \nhttps:\/\/doi.org\/10.1145\/2541940.2541986","DOI":"10.1145\/2541940.2541986"},{"key":"31_CR11","unstructured":"Dolan, B., et al.: Tappan zee (north) bridge: mining memory accesses for introspection. In: Conference on Computer and Communications Security, CCS 2013 (2013)"},{"key":"31_CR12","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., et al.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: 32nd IEEE Symposium on Security and Privacy, S&P 2011 (2011)","DOI":"10.1109\/SP.2011.11"},{"key":"31_CR13","doi-asserted-by":"crossref","unstructured":"Fu, Y., Lin, Z.: Space traveling across VM: automatically bridging the semantic gap in virtual machine introspection via online kernel data redirection. In: IEEE Symposium on Security and Privacy, SP 2012 (2012)","DOI":"10.1109\/SP.2012.40"},{"key":"31_CR14","doi-asserted-by":"crossref","unstructured":"Gu, Z., et al.: Process implanting: a new active introspection framework for virtualization. In: IEEE Symposium on Reliable Distributed Systems (SRDS 2011) (2011)","DOI":"10.1109\/SRDS.2011.26"},{"key":"31_CR15","doi-asserted-by":"crossref","unstructured":"Jain, B., et al.: Sok: introspections on trust and the semantic gap. In: IEEE Symposium on Security and Privacy, SP 2014, Berkeley, CA, USA (2014)","DOI":"10.1109\/SP.2014.45"},{"key":"31_CR16","doi-asserted-by":"crossref","unstructured":"Jang, D., et al.: Atra: address translation redirection attack against hardware-based external monitors. In: Proceedings of CCS 2014 (2014)","DOI":"10.1145\/2660267.2660303"},{"issue":"2","key":"31_CR17","doi-asserted-by":"publisher","first-page":"12:1","DOI":"10.1145\/1698750.1698752","volume":"13","author":"X Jiang","year":"2010","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection and monitoring through VMM-based \u201cout-of-the-box\u201d semantic view reconstruction. ACM Trans. Inf. Syst. Secur. 13(2), 12:1\u201312:28 (2010). \nhttps:\/\/doi.org\/10.1145\/1698750.1698752","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"31_CR18","doi-asserted-by":"publisher","unstructured":"Kelem, N.L., Feiertag, R.J.: A separation model for virtual machine monitors. In: IEEE Symposium on Security and Privacy, pp. 78\u201386 (1991). \nhttps:\/\/doi.org\/10.1109\/RISP.1991.130776","DOI":"10.1109\/RISP.1991.130776"},{"key":"31_CR19","doi-asserted-by":"publisher","unstructured":"Kwon, Y., et al.: Sego: pervasive trusted metadata for efficiently verified untrusted system services. In: Proceedings of ASPLOS 2016, pp. 277\u2013290. ACM (2016). \nhttps:\/\/doi.org\/10.1145\/2872362.2872372","DOI":"10.1145\/2872362.2872372"},{"key":"31_CR20","unstructured":"Lee, H., et al.: KI-Mon: a hardware-assisted event-triggered monitoring platform for mutable kernel object. In: The 22th USENIX Security Symposium (2013)"},{"key":"31_CR21","doi-asserted-by":"crossref","unstructured":"Lengyel, T.K., et al.: Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. In: Proceedings of ACSAC 2014 (2014)","DOI":"10.1145\/2664243.2664252"},{"key":"31_CR22","doi-asserted-by":"crossref","unstructured":"Liu, Y., et al.: Thwarting memory disclosure with efficient hypervisor-enforced intra-domain isolation. In: Proceedings CCS 2015, 12\u201316 October 2015","DOI":"10.1145\/2810103.2813690"},{"key":"31_CR23","doi-asserted-by":"crossref","unstructured":"Liu, Z., et al.: CPU transparent protection of OS kernel and hypervisor integrity with programmable DRAM. In: Proceedings of ISCA 2013, 23\u201327 June 2013","DOI":"10.1145\/2485922.2485956"},{"key":"31_CR24","doi-asserted-by":"publisher","unstructured":"Madnick, S.E., Donovan, J.J.: Application and analysis of the virtual machine approach to information system security and isolation. In: Proceedings of the Workshop on Virtual Computer Systems. ACM, New York (1973). \nhttps:\/\/doi.org\/10.1145\/800122.803961","DOI":"10.1145\/800122.803961"},{"key":"31_CR25","doi-asserted-by":"publisher","unstructured":"McKeen, F., et al.: Innovative instructions and software model for isolated execution. In: Proceedings of HASP 2013, p. 10. ACM (2013). \nhttps:\/\/doi.org\/10.1145\/2487726.2488368","DOI":"10.1145\/2487726.2488368"},{"key":"31_CR26","doi-asserted-by":"crossref","unstructured":"Moon, H., et al.: Vigilare: toward snoop-based kernel integrity monitor. In: The ACM Conference on Computer and Communications Security, CCS 2012 (2012)","DOI":"10.1145\/2382196.2382202"},{"key":"31_CR27","doi-asserted-by":"publisher","unstructured":"Payne, B.D.: Simplifying virtual machine introspection using LibVMI. \nhttps:\/\/doi.org\/10.2172\/1055635","DOI":"10.2172\/1055635"},{"key":"31_CR28","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Lee, W.: Secure and flexible monitoring of virtual machines. In: 23rd Annual Computer Security Applications Conference (ACSAC 2007), 10\u201314 December 2007, Miami Beach, Florida, USA (2007)","DOI":"10.1109\/ACSAC.2007.10"},{"key":"31_CR29","doi-asserted-by":"crossref","unstructured":"Payne, B.D., et al.: Lares: an architecture for secure active monitoring using virtualization. In: 2008 IEEE Symposium on Security and Privacy (S&P 2008) (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"31_CR30","doi-asserted-by":"crossref","unstructured":"Sharif, M.I., et al.: Secure in-VM monitoring using hardware virtualization. In: The Conference on Computer and Communications Security, CCS 2009 (2009)","DOI":"10.1145\/1653662.1653720"},{"key":"31_CR31","doi-asserted-by":"crossref","unstructured":"Srinivasan, D., et al.: Process out-grafting: an efficient \u201cout-of-VM\" approach for fine-grained process execution monitoring. In: Proceedings of CCS 2011 (2011)","DOI":"10.1145\/2046707.2046751"},{"key":"31_CR32","unstructured":"Walters, A.: The volatility framework: volatile memory artifact extraction utility framework (2007)"},{"key":"31_CR33","doi-asserted-by":"crossref","unstructured":"Wu, R., et al.: System call redirection: a practical approach to meeting real-world virtual machine introspection needs. In: 44th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, DSN 2014 (2014)","DOI":"10.1109\/DSN.2014.59"},{"key":"31_CR34","unstructured":"Zhao, S., et al.: Seeing through the same lens: introspecting guest address space at native speed. In: 26th USENIX Security Symposium, USENIX Security 2017 (2017)"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00470-5_31","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,9,6]],"date-time":"2018-09-06T07:12:23Z","timestamp":1536217943000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00470-5_31"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030004699","9783030004705"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00470-5_31","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}