{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T05:35:45Z","timestamp":1769924145239,"version":"3.49.0"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030215675","type":"print"},{"value":"9783030215682","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-21568-2_8","type":"book-chapter","created":{"date-parts":[[2019,5,28]],"date-time":"2019-05-28T22:13:31Z","timestamp":1559081611000},"page":"155-174","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["DynOpVm: VM-Based Software Obfuscation with Dynamic Opcode Mapping"],"prefix":"10.1007","author":[{"given":"Xiaoyang","family":"Cheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Debin","family":"Gao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chunfu","family":"Jia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,5,29]]},"reference":[{"issue":"2","key":"8_CR1","doi-asserted-by":"publisher","first-page":"152","DOI":"10.1145\/68182.68197","volume":"17","author":"TL Adams","year":"1989","unstructured":"Adams, T.L., Zimmerman, R.E.: An analysis of 8086 instruction set usage in MS DOS programs. ACM SIGARCH Comput. Archit. News 17(2), 152\u2013160 (1989)","journal-title":"ACM SIGARCH Comput. Archit. News"},{"issue":"6","key":"8_CR2","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt, S., et al.: FlowDroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. ACM SIGPLAN Not. 49(6), 259\u2013269 (2014)","journal-title":"ACM SIGPLAN Not."},{"key":"8_CR3","doi-asserted-by":"crossref","unstructured":"Averbuch, A., Kiperberg, M., Zaidenberg, N.J.: An efficient VM-based software protection. In: Proceedings of the 5th International Conference on Network and System Security (NSS), pp. 121\u2013128. IEEE (2011)","DOI":"10.1109\/ICNSS.2011.6059968"},{"key":"8_CR4","doi-asserted-by":"crossref","unstructured":"Banescu, S., Lucaci, C., Kr\u00e4mer, B., Pretschner, A.: VOT4CS: a virtualization obfuscation tool for C. In: Proceedings of the 2016 ACM Workshop on Software Protection, pp. 39\u201349. ACM (2016)","DOI":"10.1145\/2995306.2995312"},{"key":"8_CR5","unstructured":"Bao, T., Burket, J., Woo, M., Turner, R., Brumley, D.: BYTEWEIGHT: learning to recognize functions in binary code. In: Proceedings of the 23rd USENIX Security Symposium, pp. 845\u2013860 (2014)"},{"key":"8_CR6","doi-asserted-by":"crossref","unstructured":"Barrantes, E.G., Ackley, D.H., Palmer, T.S., Stefanovic, D., Zovi, D.D.: Randomized instruction set emulation to disrupt binary code injection attacks. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 281\u2013289. ACM (2003)","DOI":"10.1145\/948109.948147"},{"key":"8_CR7","volume-title":"Cryptography, Information Theory, and Error-Correction: A Handbook for the 21st Century","author":"AA Bruen","year":"2011","unstructured":"Bruen, A.A., Forcinito, M.A.: Cryptography, Information Theory, and Error-Correction: A Handbook for the 21st Century, vol. 68. Wiley, Hoboken (2011)"},{"key":"8_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1007\/978-3-642-22110-1_37","volume-title":"Computer Aided Verification","author":"D Brumley","year":"2011","unstructured":"Brumley, D., Jager, I., Avgerinos, T., Schwartz, E.J.: BAP: a binary analysis platform. In: Gopalakrishnan, G., Qadeer, S. (eds.) CAV 2011. LNCS, vol. 6806, pp. 463\u2013469. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22110-1_37"},{"key":"8_CR9","doi-asserted-by":"crossref","unstructured":"Clause, J., Li, W., Orso, A.: Dytan: a generic dynamic taint analysis framework. In: Proceedings of the 2007 International Symposium on Software Testing and Analysis, pp. 196\u2013206. ACM (2007)","DOI":"10.1145\/1273463.1273490"},{"key":"8_CR10","doi-asserted-by":"crossref","unstructured":"Coogan, K., Debray, S.: Equational reasoning on x86 assembly code. In: Proceedings of the 11th IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM), pp. 75\u201384. IEEE (2011)","DOI":"10.1109\/SCAM.2011.15"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"Coogan, K., Lu, G., Debray, S.: Deobfuscation of virtualization-obfuscated software: a semantics-based approach. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, pp. 275\u2013284. ACM (2011)","DOI":"10.1145\/2046707.2046739"},{"key":"8_CR12","doi-asserted-by":"crossref","unstructured":"De Clercq, R., et al.: SOFIA: software and control flow integrity architecture. In: Proceedings of the 2016 Design, Automation & Test in Europe Conference & Exhibition (DATE), pp. 1172\u20131177. IEEE (2016)","DOI":"10.3850\/9783981537079_1001"},{"key":"8_CR13","unstructured":"Egele, M., Kruegel, C., Kirda, E., Vigna, G.: PiOS: detecting privacy leaks in iOS applications. In: Proceedings of the 2011 Network and Distributed System Security Symposium (NDSS), pp. 177\u2013183 (2011)"},{"key":"8_CR14","doi-asserted-by":"crossref","unstructured":"Fang, H., et al.: VMGuard: an integrity monitoring system for management virtual machines. In: Proceedings of the 16th International Conference on Parallel and Distributed Systems (ICPADS), pp. 67\u201374. IEEE (2010)","DOI":"10.1109\/ICPADS.2010.44"},{"key":"8_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1007\/978-3-642-24861-0_12","volume-title":"Information Security","author":"H Fang","year":"2011","unstructured":"Fang, H., Wu, Y., Wang, S., Huang, Y.: Multi-stage binary code obfuscation using improved virtual machine. In: Lai, X., Zhou, J., Li, H. (eds.) ISC 2011. LNCS, vol. 7001, pp. 168\u2013181. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-24861-0_12"},{"issue":"3","key":"8_CR16","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1007\/s11416-009-0126-4","volume":"6","author":"Y Guillot","year":"2010","unstructured":"Guillot, Y., Gazet, A.: Automatic binary deobfuscation. J. Comput. Virol. 6(3), 261\u2013276 (2010)","journal-title":"J. Comput. Virol."},{"issue":"6","key":"8_CR17","first-page":"929","volume":"85","author":"J Huang","year":"2002","unstructured":"Huang, J., Peng, T.C.: Analysis of x86 instruction set usage for dos\/windows applications and its implication on superscalar design. IEICE Trans. Inf. Syst. 85(6), 929\u2013939 (2002)","journal-title":"IEICE Trans. Inf. Syst."},{"key":"8_CR18","doi-asserted-by":"crossref","unstructured":"Ibrahim, A.H., Abdelhalim, M., Hussein, H., Fahmy, A.: Analysis of x86 instruction set usage for Windows 7 applications. In: Proceedings of the 2nd International Conference on Computer Technology and Development (ICCTD), pp. 511\u2013516. IEEE (2010)","DOI":"10.1109\/ICCTD.2010.5645851"},{"key":"8_CR19","doi-asserted-by":"crossref","unstructured":"Kalysch, A., G\u00f6tzfried, J., M\u00fcller, T.: VMAttack: deobfuscating virtualization-based packed binaries. In: Proceedings of the 12th International Conference on Availability, Reliability and Security, p. 2. ACM (2017)","DOI":"10.1145\/3098954.3098995"},{"key":"8_CR20","unstructured":"Kang, M.G., McCamant, S., Poosankam, P., Song, D.: DTA++: dynamic taint analysis with targeted control-flow propagation. In: Proceedings of the 2011 Network and Distributed System Security Symposium (NDSS) (2011)"},{"key":"8_CR21","doi-asserted-by":"crossref","unstructured":"Kc, G.S., Keromytis, A.D., Prevelakis, V.: Countering code-injection attacks with instruction-set randomization. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, pp. 272\u2013280. ACM (2003)","DOI":"10.1145\/948109.948146"},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Kuang, K., et al.: Exploit dynamic data flows to protect software against semantic attacks (2017)","DOI":"10.1109\/UIC-ATC.2017.8397540"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"Lin, Y., Gao, D., Cheng, X.: Control-flow carrying code. In: Proceedings of the 14th ACM Asia Conference on Information, Computer and Communications Security (AsiaCCS) (2019)","DOI":"10.1145\/3321705.3329815"},{"issue":"9","key":"8_CR24","doi-asserted-by":"publisher","first-page":"950","DOI":"10.1145\/358234.358271","volume":"27","author":"T Maude","year":"1984","unstructured":"Maude, T., Maude, D.: Hardware protection against software piracy. Commun. ACM 27(9), 950\u2013959 (1984)","journal-title":"Commun. ACM"},{"key":"8_CR25","unstructured":"Ming, J., Xu, D., Jiang, Y., Wu, D.: BinSim: trace-based semantic binary diffing via system call sliced segment equivalence checking. In: Proceedings of the 26th USENIX Security Symposium (2017)"},{"key":"8_CR26","doi-asserted-by":"crossref","unstructured":"Portokalidis, G., Keromytis, A.D.: Fast and practical instruction-set randomization for commodity systems. In: Proceedings of the 26th Annual Computer Security Applications Conference, pp. 41\u201348. ACM (2010)","DOI":"10.1145\/1920261.1920268"},{"key":"8_CR27","unstructured":"Quynh, N.A.: Capstone: next-gen disassembly framework. Black Hat USA (2014)"},{"key":"8_CR28","unstructured":"Rico, R.: Proposal of test-bench for the x86 instruction set (16 bits subset). Technical report TR-UAH-AUT-GAP-2005-21-en (2005). http:\/\/atc2.aut.uah.es\/~gap\/"},{"issue":"1","key":"8_CR29","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1016\/j.sysarc.2004.07.002","volume":"51","author":"R Rico","year":"2005","unstructured":"Rico, R., P\u00e9rez, J.I., Frutos, J.A.: The impact of x86 instruction set architecture on superscalar processing. J. Syst. Archit. 51(1), 63\u201377 (2005)","journal-title":"J. Syst. Archit."},{"key":"8_CR30","unstructured":"Rolles, R.: Unpacking virtualization obfuscators. In: Proceedings of the 3rd USENIX Workshop on Offensive Technologies (WOOT) (2009)"},{"issue":"4","key":"8_CR31","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1145\/71317.71323","volume":"17","author":"RJ Schwartz","year":"1989","unstructured":"Schwartz, R.J.: The design and development of a dynamic program behavior measurement tool for the Intel 8086\/88. ACM SIGARCH Comput. Archit. News 17(4), 82\u201394 (1989)","journal-title":"ACM SIGARCH Comput. Archit. News"},{"issue":"11","key":"8_CR32","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1145\/359168.359176","volume":"22","author":"A Shamir","year":"1979","unstructured":"Shamir, A.: How to share a secret. Commun. ACM 22(11), 612\u2013613 (1979)","journal-title":"Commun. ACM"},{"key":"8_CR33","doi-asserted-by":"crossref","unstructured":"Sharif, M., Lanzi, A., Giffin, J., Lee, W.: Automatic reverse engineering of malware emulators. In: Proceedings of the 30th IEEE Symposium on Security and Privacy (SP), pp. 94\u2013109. IEEE (2009)","DOI":"10.1109\/SP.2009.27"},{"key":"8_CR34","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., Wang, R., Hauser, C., Kruegel, C., Vigna, G.: Firmalice-automatic detection of authentication bypass vulnerabilities in binary firmware. In: Proceedings of the 2015 Network and Distributed System Security Symposium (NDSS) (2015)","DOI":"10.14722\/ndss.2015.23294"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., et al.: SOK: (state of) the art of war: offensive techniques in binary analysis. In: Proceedings of the 37th IEEE Symposium on Security and Privacy (SP), pp. 138\u2013157. IEEE (2016)","DOI":"10.1109\/SP.2016.17"},{"key":"8_CR36","doi-asserted-by":"crossref","unstructured":"Sinha, K., Kemerlis, V.P., Sethumadhavan, S.: Reviving instruction set randomization. In: Proceedings of the 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 21\u201328. IEEE (2017)","DOI":"10.1109\/HST.2017.7951732"},{"key":"8_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-89862-7_1","volume-title":"Information Systems Security","author":"D Song","year":"2008","unstructured":"Song, D., et al.: BitBlaze: a new approach to computer security via binary analysis. In: Sekar, R., Pujari, A.K. (eds.) ICISS 2008. LNCS, vol. 5352, pp. 1\u201325. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-89862-7_1"},{"key":"8_CR38","unstructured":"Sullivan, D., Arias, O., Gens, D., Davi, L., Sadeghi, A.R., Jin, Y.: Execution integrity with in-place encryption. arXiv preprint arXiv:1703.02698 (2017)"},{"key":"8_CR39","doi-asserted-by":"crossref","unstructured":"Tang, Z., et al.: SEEAD: a semantic-based approach for automatic binary code de-obfuscation. In: Proceedings of the 2017 Trustcom\/BigDataSE\/ICESS, pp. 261\u2013268. IEEE (2017)","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.246"},{"key":"8_CR40","unstructured":"Toemeh, R., Arumugam, S.: Applying genetic algorithms for searching key-space of polyalphabetic substitution ciphers. Int. Arab J. Inf. Technol. (IAJIT) 5(1) (2008)"},{"key":"8_CR41","doi-asserted-by":"crossref","unstructured":"van der Veen, V., et al.: A tough call: mitigating advanced code-reuse attacks at the binary level. In: Proceedings of the 37th IEEE Symposium on Security and Privacy (SP), pp. 934\u2013953. IEEE (2016)","DOI":"10.1109\/SP.2016.60"},{"key":"8_CR42","doi-asserted-by":"crossref","unstructured":"Wang, H., Fang, D., Li, G., Yin, X., Zhang, B., Gu, Y.: NISLVMP: improved virtual machine-based software protection. In: Proceedings of the 9th International Conference on Computational Intelligence and Security (CIS), pp. 479\u2013483. IEEE (2013)","DOI":"10.1109\/CIS.2013.107"},{"key":"8_CR43","unstructured":"Weiser, M.: Program slicing. In: Proceedings of the 5th International Conference on Software Engineering, pp. 439\u2013449. IEEE Press (1981)"},{"key":"8_CR44","doi-asserted-by":"crossref","unstructured":"Xu, D., Ming, J., Fu, Y., Wu, D.: VMHunt: a verifiable approach to partially-virtualized binary code simplification. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 442\u2013458. ACM (2018)","DOI":"10.1145\/3243734.3243827"},{"key":"8_CR45","doi-asserted-by":"crossref","unstructured":"Yadegari, B., Johannesmeyer, B., Whitely, B., Debray, S.: A generic approach to automatic deobfuscation of executable code. In: Proceedings of the 36th IEEE Symposium on Security and Privacy (SP), pp. 674\u2013691. IEEE (2015)","DOI":"10.1109\/SP.2015.47"},{"issue":"2","key":"8_CR46","first-page":"237","volume":"32","author":"M Yang","year":"2011","unstructured":"Yang, M., Huang, L.: Software protection scheme via nested virtual machine. J. Chin. Comput. Syst. 32(2), 237\u2013241 (2011)","journal-title":"J. Chin. Comput. Syst."}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-21568-2_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,29]],"date-time":"2024-05-29T00:03:48Z","timestamp":1716941028000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-21568-2_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030215675","9783030215682"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-21568-2_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"29 May 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bogota","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Colombia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"5 June 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 June 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.acns19.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"111","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"From the ACNS 2019 associated workshops, 10 out of 30 submitted papers were accepted for publication","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}