{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T17:59:55Z","timestamp":1770832795262,"version":"3.50.1"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030036379","type":"print"},{"value":"9783030036386","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-03638-6_16","type":"book-chapter","created":{"date-parts":[[2018,11,1]],"date-time":"2018-11-01T03:12:53Z","timestamp":1541041973000},"page":"255-271","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Sarracenia: Enhancing the Performance and Stealthiness of SSH Honeypots Using Virtual Machine Introspection"],"prefix":"10.1007","author":[{"given":"Stewart","family":"Sentanoe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin","family":"Taubmann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hans P.","family":"Reiser","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,11,2]]},"reference":[{"key":"16_CR1","doi-asserted-by":"publisher","unstructured":"Bahram, S., et al.: DKSM: subverting virtual machine introspection for fun and profit. In: 2010 29th IEEE Symposium on Reliable Distributed Systems, pp. 82\u201391, October 2010. https:\/\/doi.org\/10.1109\/SRDS.2010.39","DOI":"10.1109\/SRDS.2010.39"},{"key":"16_CR2","doi-asserted-by":"publisher","first-page":"S66","DOI":"10.1016\/j.diin.2017.06.002","volume":"22","author":"F Block","year":"2017","unstructured":"Block, F., Dewald, A.: Linux memory forensics: dissecting the user space process heap. Digit. Investig. 22, S66\u2013S75 (2017)","journal-title":"Digit. Investig."},{"key":"16_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-642-23644-0_1","volume-title":"Recent Advances in Intrusion Detection","author":"E Bosman","year":"2011","unstructured":"Bosman, E., Slowinska, A., Bos, H.: Minemu: the world\u2019s fastest taint tracker. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol. 6961, pp. 1\u201320. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-23644-0_1"},{"issue":"5","key":"16_CR4","first-page":"395","volume":"4","author":"J Briffaut","year":"2009","unstructured":"Briffaut, J., Lalande, J.F., Toinard, C.: Security and results of a large-scale high-interaction honeypot. JCP 4(5), 395\u2013404 (2009)","journal-title":"JCP"},{"key":"16_CR5","unstructured":"Cohen, M.: Rekall memory forensics framework. DFIR Prague (2014). https:\/\/digital-forensics.sans.org\/summit-archives\/dfirprague14\/Rekall_Memory_Forensics_Michael_Cohen.pdf"},{"key":"16_CR6","unstructured":"Coret, J.A.: Kojoney - A Honeypot For The SSH Service (2006). http:\/\/kojoney.sourceforge.net\/ . Accessed 17 Feb 2018"},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 51\u201362. ACM (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"16_CR8","unstructured":"Dolan-Gavitt, B., Payne, B., Lee, W.: Leveraging forensic tools for virtual machine introspection. Technical report GT-CS-11-05, Georgia Institute of Technology (2011)"},{"key":"16_CR9","unstructured":"Enemy, K.Y.: Honeywall CDROM Roo 3rd Generation Technology. Honeynet Project & Research Alliance, vol. 17 (2005). https:\/\/projects.honeynet.org\/honeywall\/"},{"key":"16_CR10","unstructured":"Garfinkel, T., Rosenblum, M., et al.: A virtual machine introspection based architecture for intrusion detection. In: Network and Distributed Systems Security Symposium (NDSS), vol. 3, pp. 191\u2013206 (2003)"},{"key":"16_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-642-41284-4_2","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"M Graziano","year":"2013","unstructured":"Graziano, M., Lanzi, A., Balzarotti, D.: Hypervisor memory forensics. In: Stolfo, S.J., Stavrou, A., Wright, C.V. (eds.) RAID 2013. LNCS, vol. 8145, pp. 21\u201340. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-41284-4_2"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"Holz, T., Raynal, F.: Detecting honeypots and other suspicious environments. In: Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop, IAW 2005, pp. 29\u201336. IEEE (2005)","DOI":"10.1109\/IAW.2005.1495930"},{"key":"16_CR13","unstructured":"Hoopes, J.: Virtualization for security: including sandboxing, disaster recovery, high availability, forensic analysis, and honeypotting. Syngress (2009)"},{"key":"16_CR14","unstructured":"Intel: Intel$${\\textregistered }$$ 100 Series and Intel$${\\textregistered }$$ C230 Series Chipset Family Platform Controller Hub (PCH), May 2016"},{"key":"16_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/978-3-540-74320-0_11","volume-title":"Recent Advances in Intrusion Detection","author":"X Jiang","year":"2007","unstructured":"Jiang, X., Wang, X.: \u201cOut-of-the-Box\u201d monitoring of VM-based high-interaction honeypots. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 198\u2013218. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74320-0_11"},{"issue":"2","key":"16_CR16","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1145\/1698750.1698752","volume":"13","author":"X Jiang","year":"2010","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection and monitoring through VMM-based \u201cout-of-the-box\u201d semantic view reconstruction. ACM Trans. Inf. Syst. Secur. (TISSEC) 13(2), 12 (2010)","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"16_CR17","doi-asserted-by":"crossref","DOI":"10.1201\/b10738","volume-title":"Honeypots: A New Paradigm to Information Security","author":"R Joshi","year":"2011","unstructured":"Joshi, R., Sardana, A.: Honeypots: A New Paradigm to Information Security. CRC Press, Boca Raton (2011)"},{"key":"16_CR18","unstructured":"Kittel, T.: Library to parse dwarf information and access\/use it in C\/C++ (2014). https:\/\/github.com\/kittel\/libdwarfparser . Accessed 17 Feb 2018"},{"issue":"1","key":"16_CR19","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1109\/MSECP.2004.1264861","volume":"2","author":"N Krawetz","year":"2004","unstructured":"Krawetz, N.: Anti-honeypot technology. IEEE Secur. Privacy 2(1), 76\u201379 (2004)","journal-title":"IEEE Secur. Privacy"},{"key":"16_CR20","unstructured":"Lengyel, T.K.: Stealthy monitoring with xen altp2m. https:\/\/blog.xenproject.org\/2016\/04\/13\/stealthy-monitoring-with-xen-altp2m\/ . Accessed 13 Feb 2018"},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Lengyel, T.K., Maresca, S., Payne, B.D., Webster, G.D., Vogl, S., Kiayias, A.: Scalability, fidelity and stealth in the drakvuf dynamic malware analysis system. In: Proceedings of the 30th Annual Computer Security Applications Conference (2014)","DOI":"10.1145\/2664243.2664252"},{"key":"16_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/978-3-642-38631-2_13","volume-title":"Network and System Security","author":"TK Lengyel","year":"2013","unstructured":"Lengyel, T.K., Neumann, J., Maresca, S., Kiayias, A.: Towards hybrid honeynets via virtual machine introspection and cloning. In: Lopez, J., Huang, X., Sandhu, R. (eds.) NSS 2013. LNCS, vol. 7873, pp. 164\u2013177. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38631-2_13"},{"key":"16_CR23","unstructured":"Oosterhof, M.: Cowrie SSH\/Telnet Honeypot (2014). https:\/\/github.com\/micheloosterhof\/cowrie . Accessed 17 Feb 2018"},{"key":"16_CR24","doi-asserted-by":"crossref","unstructured":"Payne, B.D.: Simplifying virtual machine introspection using LibVMI. Sandia report, pp. 43\u201344 (2012)","DOI":"10.2172\/1055635"},{"key":"16_CR25","doi-asserted-by":"publisher","unstructured":"Portokalidis, G., Bos, H.: Eudaemon: involuntary and on-demand emulation against zero-day exploits. In: Proceedings of the 3rd ACM SIGOPS\/EuroSys European Conference on Computer Systems, Eurosys 2008, pp. 287\u2013299. ACM, New York (2008). https:\/\/doi.org\/10.1145\/1352592.1352622","DOI":"10.1145\/1352592.1352622"},{"issue":"4","key":"16_CR26","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1218063.1217938","volume":"40","author":"G Portokalidis","year":"2006","unstructured":"Portokalidis, G., Slowinska, A., Bos, H.: Argos: an emulator for fingerprinting zero-day attacks for advertised honeypots with automatic signature generation. SIGOPS Oper. Syst. Rev. 40(4), 15\u201327 (2006). https:\/\/doi.org\/10.1145\/1218063.1217938","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"16_CR27","doi-asserted-by":"crossref","unstructured":"Sentanoe, S., Taubmann, B., Reiser, H.P.: Virtual machine introspection based SSH honeypot. In: Proceedings of the 4th Workshop on Security in Highly Connected IT Systems, pp. 13\u201318. ACM (2017)","DOI":"10.1145\/3099012.3099016"},{"key":"16_CR28","unstructured":"Spitzner, L.: Know your enemy: Genii honeynets. The Honeynet Alliance (2005)"},{"key":"16_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1007\/978-3-540-87403-4_3","volume-title":"Recent Advances in Intrusion Detection","author":"A Srivastava","year":"2008","unstructured":"Srivastava, A., Giffin, J.: Tamper-resistant, application-aware blocking of malicious network connections. In: Lippmann, R., Kirda, E., Trachtenberg, A. (eds.) RAID 2008. LNCS, vol. 5230, pp. 39\u201358. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-87403-4_3"},{"key":"16_CR30","unstructured":"Stuart: High-interaction MitM SSH honeypot (2016). https:\/\/github.com\/magisterquis\/sshhipot . Accessed 17 Feb 2018"},{"key":"16_CR31","unstructured":"Tamminen, U.: Kippo - SSH Honeypot (2009). https:\/\/github.com\/desaster\/kippo . Accessed 17 Feb 2018"},{"key":"16_CR32","doi-asserted-by":"publisher","first-page":"S114","DOI":"10.1016\/j.diin.2016.01.014","volume":"16","author":"B Taubmann","year":"2016","unstructured":"Taubmann, B., Fr\u00e4drich, C., Dusold, D., Reiser, H.P.: Tlskex: harnessing virtual machine introspection for decrypting tls communication. Digit. Investig. 16, S114\u2013S123 (2016)","journal-title":"Digit. Investig."},{"key":"16_CR33","doi-asserted-by":"crossref","unstructured":"Taubmann, B., Rakotondravony, N., Reiser, H.P.: Cloudphylactor: harnessing mandatory access control for virtual machine introspection in cloud data centers. In: 2016 IEEE Trustcom\/BigDataSE\/I SPA, pp. 957\u2013964. IEEE (2016)","DOI":"10.1109\/TrustCom.2016.0162"},{"key":"16_CR34","unstructured":"Taubmann, B., Rakotondravony, N., Reiser, H.P.: Libvmtrace: tracing virtual machines (2016)"},{"key":"16_CR35","unstructured":"Testa, J.: SSH man-in-the-middle tool (2017). https:\/\/github.com\/jtesta\/ssh-mitm . Accessed 17 Feb 2018"},{"key":"16_CR36","doi-asserted-by":"publisher","first-page":"S98","DOI":"10.1016\/j.diin.2018.04.015","volume":"26","author":"T Tuzel","year":"2018","unstructured":"Tuzel, T., Bridgman, M., Zepf, J., Lengyel, T.K., Temkin, K.: Who watches the watcher? Detecting hypervisor introspection from unprivileged guests. Digit. Investig. 26, S98\u2013S106 (2018)","journal-title":"Digit. Investig."},{"key":"16_CR37","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"125","DOI":"10.1007\/978-3-319-56538-5_13","volume-title":"Recent Advances in Information Systems and Technologies","author":"J Uitto","year":"2017","unstructured":"Uitto, J., Rauti, S., Laur\u00e9n, S., Lepp\u00e4nen, V.: A survey on anti-honeypot and anti-introspection methods. In: Rocha, \u00c1., Correia, A.M., Adeli, H., Reis, L.P., Costanzo, S. (eds.) WorldCIST 2017. AISC, vol. 570, pp. 125\u2013134. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56538-5_13"},{"issue":"1","key":"16_CR38","first-page":"30","volume":"4","author":"P Wang","year":"2010","unstructured":"Wang, P., Wu, L., Cunningham, R., Zou, C.C.: Honeypot detection in advanced botnet attacks. Int. J. Inf. Comput. Secur. 4(1), 30\u201351 (2010)","journal-title":"Int. J. Inf. Comput. Secur."}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-03638-6_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,30]],"date-time":"2019-10-30T06:16:13Z","timestamp":1572416173000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-03638-6_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030036379","9783030036386"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-03638-6_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Oslo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Norway","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 November 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 November 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/securitylab.no\/nordsec18\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"81","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"29","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"36% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}