{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T08:04:48Z","timestamp":1771661088916,"version":"3.50.1"},"publisher-location":"Cham","reference-count":54,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030801281","type":"print"},{"value":"9783030801298","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-80129-8_66","type":"book-chapter","created":{"date-parts":[[2021,7,5]],"date-time":"2021-07-05T09:04:22Z","timestamp":1625475862000},"page":"1003-1019","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Beware of Unknown Areas to Notify Adversaries: Detecting Dynamic Binary Instrumentation Runtimes with Low-Level Memory Scanning"],"prefix":"10.1007","author":[{"given":"Federico","family":"Palmaro","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luisa","family":"Franchina","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"66_CR1","doi-asserted-by":"crossref","unstructured":"Angelini, M., et al.: ROPMate: visually assisting the creation of ROP-based exploits. In: 2018 IEEE Symposium on Visualization for Cyber Security, VizSec 2018, pp. 1\u20138 (Oct 2018)","DOI":"10.1109\/VIZSEC.2018.8709204"},{"issue":"2","key":"66_CR2","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1109\/JPROC.2004.840305","volume":"93","author":"M Arnold","year":"2005","unstructured":"Arnold, M., Fink, S.J., Grove, D., Hind, M., Sweeney, P.F.: A survey of adaptive optimization in virtual machines. Proc. IEEE 93(2), 449\u2013466 (2005)","journal-title":"Proc. IEEE"},{"issue":"2","key":"66_CR3","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1145\/857076.857077","volume":"35","author":"J Aycock","year":"2003","unstructured":"Aycock, J.: A brief history of just-in-time. ACM Comput. Surv. 35(2), 97\u2013113 (2003)","journal-title":"ACM Comput. Surv."},{"key":"66_CR4","doi-asserted-by":"crossref","unstructured":"Bebenita, M., et al.: SPUR: a trace-based JIT compiler for CIL. In: Proceedings of the ACM International Conference on Object Oriented Programming Systems Languages and Applications, OOPSLA 2010, pp. 708\u2013725. ACM (2010)","DOI":"10.1145\/1869459.1869517"},{"key":"66_CR5","doi-asserted-by":"crossref","unstructured":"Bernat, A.R., Miller, B.P.: Anywhere, any-time binary instrumentation. In: PASTE 2011 (2011)","DOI":"10.1145\/2024569.2024572"},{"key":"66_CR6","doi-asserted-by":"crossref","unstructured":"Biondo, A., Conti, M., Lain, D.: Back to the epilogue: evading control flow guard via unaligned targets. In: 25th Annual Network and Distributed System Security Symposium, NDSS 2018 (2018)","DOI":"10.14722\/ndss.2018.23318"},{"key":"66_CR7","unstructured":"Blackthorne, J., Bulazel, A., Fasano, A., Biernat, P., Yener, B.: Avleak: fingerprinting antivirus emulators through black-box testing. In: 10th USENIX Workshop on Offensive Technologies, WOOT 2016, (2016)"},{"key":"66_CR8","doi-asserted-by":"crossref","unstructured":"Borrello, P., Coppa, E., D\u2019Elia, D.C., Demetrescu, C.: The ROP needle: hiding trigger-based injection vectors via code reuse. In: Proceedings of the 34th ACM\/SIGAPP Symposium on Applied Computing, SAC 2019, pp. 1962\u20131970, New York, NY, USA. Association for Computing Machinery (2019)","DOI":"10.1145\/3297280.3297472"},{"key":"66_CR9","doi-asserted-by":"crossref","unstructured":"Bruening, D., Amarasinghe, S.: Maintaining consistency and bounding capacity of software code caches. In: International Symposium on Code Generation and Optimization, pp. 74\u201385 (2005)","DOI":"10.1109\/CGO.2005.19"},{"key":"66_CR10","doi-asserted-by":"crossref","unstructured":"Bruening, D., Garnett, T., Amarasinghe, S.: An infrastructure for adaptive dynamic optimization. In: International Symposium on Code Generation and Optimization, 2003. CGO 2003, pp. 265\u2013275 (2003)","DOI":"10.1109\/CGO.2003.1191551"},{"key":"66_CR11","unstructured":"Bruening, D.: Efficient, transparent, and comprehensive runtime code manipulation (2004)"},{"key":"66_CR12","doi-asserted-by":"crossref","unstructured":"Bruening, D., Zhao, Q., Amarasinghe, S.: Transparent dynamic instrumentation. In: VEE 2012. ACM (2012)","DOI":"10.1145\/2151024.2151043"},{"key":"66_CR13","doi-asserted-by":"publisher","unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., Yin, H.: Automatically identifying trigger-based behavior in malware. In: Lee, W., Wang, C., Dagon, D. (eds.) Botnet Detection: Countering the Largest Security Threat, pp. 65\u201388. Springer, Boston (2008). https:\/\/doi.org\/10.1007\/978-0-387-68768-1_4","DOI":"10.1007\/978-0-387-68768-1_4"},{"issue":"4","key":"66_CR14","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1177\/109434200001400404","volume":"14","author":"B Buck","year":"2000","unstructured":"Buck, B., Hollingsworth, J.K.: An API for runtime code patching. Int. J. High Perform. Comput. Appl. 14(4), 317\u2013329 (2000)","journal-title":"Int. J. High Perform. Comput. Appl."},{"key":"66_CR15","doi-asserted-by":"crossref","unstructured":"Bulazel, A., Yener, B.: A survey on automated dynamic malware analysis evasion and counter-evasion: PC, mobile, and web. In: Proceedings of the 1st Reversing and Offensive-Oriented Trends Symposium, ROOTS, pp. 2:1\u20132:21. ACM (2017)","DOI":"10.1145\/3150376.3150378"},{"key":"66_CR16","doi-asserted-by":"crossref","unstructured":"Conti, M., et al.: Losing control: on the effectiveness of control-flow integrity under stack attacks. In: Proceedings of the 22nd ACM Conference on Computer and Communications Security, CCS 2015, pp. 952\u2013963 (2015)","DOI":"10.1145\/2810103.2813671"},{"key":"66_CR17","doi-asserted-by":"crossref","unstructured":"Dang, T.H.Y., Maniatis, P., Wagner, D.: The performance cost of shadow stacks and stack canaries. In: Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, ASIA CCS 2015, pp. 555\u2013566. ACM (2015)","DOI":"10.1145\/2714576.2714635"},{"key":"66_CR18","doi-asserted-by":"crossref","unstructured":"Dasgupta, S., Park, D., Kasampalis, T., Adve, V.S., Ro\u015fu, G.: A complete formal semantics of x86-64 user-level instruction set architecture. In: Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2019, pp. 1133\u20131148. Association for Computing Machinery (2019)","DOI":"10.1145\/3314221.3314601"},{"key":"66_CR19","unstructured":"Degenbaev, U.: Formal specification of the x86 instruction set architecture. PhD thesis (2012)"},{"key":"66_CR20","doi-asserted-by":"crossref","unstructured":"D\u2019Elia, D.C., Coppa, E., Nicchi, S., Palmaro, F., Cavallaro, L.: SoK: using dynamic binary instrumentation for security (and how you may get caught red handed). In: Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security, Asia CCS 2019, pp. 15\u201327. ACM (2019)","DOI":"10.1145\/3321705.3329819"},{"key":"66_CR21","doi-asserted-by":"publisher","first-page":"2750","DOI":"10.1109\/TIFS.2020.2976559","volume":"15","author":"DC D\u2019Elia","year":"2020","unstructured":"D\u2019Elia, D.C., Coppa, E., Palmaro, F., Cavallaro, L.: On the dissection of evasive malware. IEEE Trans. Inf. Forensics Secur. 15, 2750\u20132765 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"66_CR22","doi-asserted-by":"crossref","unstructured":"D\u2019Elia, D.C., Coppa, E., Salvati, A., Demetrescu, C.: Static analysis of ROP code. In: Proceedings of the 12th European Workshop on Systems Security, EuroSec 2019. Association for Computing Machinery (2019)","DOI":"10.1145\/3301417.3312494"},{"key":"66_CR23","doi-asserted-by":"crossref","unstructured":"D\u2019Elia, D.C., Demetrescu, C.: Flexible on-stack replacement in LLVM. In: Proceedings of the 2016 International Symposium on Code Generation and Optimization, CGO 2016, pp. 250\u2013260. Association for Computing Machinery (2016)","DOI":"10.1145\/2854038.2854061"},{"key":"66_CR24","doi-asserted-by":"crossref","unstructured":"D\u2019Elia, D.C., Demetrescu, C.: On-stack replacement, distilled. In: Proceedings of the 39th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2018, pp. 166\u2013180, New York, NY, USA. Association for Computing Machinery (2018)","DOI":"10.1145\/3192366.3192396"},{"key":"66_CR25","doi-asserted-by":"publisher","first-page":"1131","DOI":"10.1002\/spe.2348","volume":"46","author":"DC D\u2019Elia","year":"2016","unstructured":"D\u2019Elia, D.C., Demetrescu, C., Finocchi, I.: Mining hot calling contexts in small space. Softw. Pract. Exp. 46, 1131\u20131152 (2016)","journal-title":"Softw. Pract. Exp."},{"key":"66_CR26","unstructured":"D\u2019Elia, D.C., Nicchi, S., Mariani, M., Marini, M., Palmaro, F.: Design robust API monitoring solutions (2020). https:\/\/arxiv.org\/abs\/2005.00323"},{"key":"66_CR27","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS 2008, pp. 51\u201362. ACM (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"66_CR28","doi-asserted-by":"crossref","unstructured":"Egele, M., Scholte, T., Kirda, E., Kruegel, C.: A survey on automated dynamic malware-analysis techniques and tools. ACM Comput. Surv. 44(2), 6:1\u20136:42 (2008)","DOI":"10.1145\/2089125.2089126"},{"key":"66_CR29","doi-asserted-by":"publisher","unstructured":"Filho, A.S., Rodr\u00edguez, R.J., Feitosa, E.L.: Reducing the attack surface of dynamic binary instrumentation frameworks. In: Rocha, \u00c1, Pereira, R.P. (eds.) Developments and Advances in Defense and Security, vol. 152, pp. 3\u201313. Springer, Singapore (2020). https:\/\/doi.org\/10.1007\/978-981-13-9155-2_1","DOI":"10.1007\/978-981-13-9155-2_1"},{"key":"66_CR30","doi-asserted-by":"crossref","unstructured":"Fioraldi, A., D\u2019Elia, D.C., Querzoni, L.: Fuzzing binaries for memory safety errors with QASan. In: 2020 IEEE Secure Development Conference (SecDev) (2020)","DOI":"10.1109\/SecDev45635.2020.00019"},{"key":"66_CR31","unstructured":"Fioraldi, A., Maier, D., Ei\u00dffeldt, H., Heuse, M.: AFL++: combining incremental steps of fuzzing research. In: 14th USENIX Workshop on Offensive Technologies (WOOT 20). USENIX Association (Aug 2020)"},{"key":"66_CR32","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: NDSS 2003 (2003)"},{"key":"66_CR33","unstructured":"Jung, J., Hu, H., Solodukhin, D., Pagan, D., Lee, K.H., Kim, T.: Fuzzification: anti-fuzzing techniques. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 1913\u20131930, Santa Clara, CA. USENIX Association (Aug 2019)"},{"key":"66_CR34","doi-asserted-by":"crossref","unstructured":"Lengyel, T.K., Maresca, S., Payne, B.D., Webster, G.D., Vogl, S., Kiayias, A.: Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. In: Proceedings of the 30th Annual Computer Security Applications Conference, ACSAC 2014, pp. 386\u2013395. ACM (2014)","DOI":"10.1145\/2664243.2664252"},{"key":"66_CR35","doi-asserted-by":"crossref","unstructured":"Lueck, G., Patil, H., Pereira, C.: PinADX: an interface for customizable debugging with dynamic instrumentation. In: Proceedings of the Tenth International Symposium on Code Generation and Optimization, CGO 2012, pp. 114\u2013123. ACM (2012)","DOI":"10.1145\/2259016.2259032"},{"key":"66_CR36","doi-asserted-by":"crossref","unstructured":"Luk, C.K., et al.: Pin: building customized program analysis tools with dynamic instrumentation. In: Proceedings of the 2005 ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2005, pp. 190\u2013200. ACM (2005)","DOI":"10.1145\/1065010.1065034"},{"key":"66_CR37","doi-asserted-by":"crossref","unstructured":"Miramirkhani, N., Appini, M.P., Nikiforakis, N., Polychronakis, M.: Spotless sandboxes: evading malware analysis systems using wear-and-tear artifacts. In: 2017 IEEE Symposium on Security and Privacy (SP) (2017)","DOI":"10.1109\/SP.2017.42"},{"key":"66_CR38","doi-asserted-by":"crossref","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation. In: PLDI 2007. ACM (2007)","DOI":"10.1145\/1250734.1250746"},{"issue":"6","key":"66_CR39","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1049\/iet-ifs.2018.5386","volume":"13","author":"C Ntantogian","year":"2019","unstructured":"Ntantogian, C., Poulios, G., Karopoulos, G., Xenakis, C.: Transforming malicious code to ROP gadgets for antivirus evasion. IET Inf. Secur. 13(6), 570\u2013578 (2019)","journal-title":"IET Inf. Secur."},{"key":"66_CR40","doi-asserted-by":"publisher","unstructured":"Oyama, Y.: How does malware use RDTSC? a study on operations executed by malware with CPU cycle measurement. In: Detection of Intrusions and Malware, and Vulnerability Assessment, pp. 197\u2013218, Springer International Publishing, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-22038-9_10","DOI":"10.1007\/978-3-030-22038-9_10"},{"key":"66_CR41","doi-asserted-by":"crossref","unstructured":"Patil, H., Pereira, C., Stallcup, M., Lueck, G., Cownie, J.: Pinplay: a framework for deterministic replay and reproducible analysis of parallel programs. In: Proceedings of the 8th Annual IEEE\/ACM International Symposium on Code Generation and Optimization, CGO 2010, pap. 2\u201311. ACM (2010)","DOI":"10.1145\/1772954.1772958"},{"key":"66_CR42","unstructured":"Polino, M.: Hiding pin\u2019s artifacts to defeat evasive malware. In: BlackHat Europe (2017). https:\/\/www.blackhat.com\/eu-17\/briefings.html#hiding-pins-artifacts-to-defeat-evasive-malware"},{"key":"66_CR43","doi-asserted-by":"crossref","unstructured":"Shacham, H.: The geometry of innocent flesh on the bone: return-into-libc without function calls (on the x86). In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS 2007, pp. 552\u2013561, New York, NY, USA. Association for Computing Machinery (2007)","DOI":"10.1145\/1315245.1315313"},{"key":"66_CR44","doi-asserted-by":"crossref","unstructured":"Song, C., Zhang, C., Wang, T., Lee, W., Melski, D.: Exploiting and protecting dynamic code generation. In: NDSS 2015 (2003)","DOI":"10.14722\/ndss.2015.23233"},{"key":"66_CR45","doi-asserted-by":"crossref","unstructured":"Song, Y.W., Lee, Y.: Efficient data race detection for C\/C++ programs using dynamic granularity. In: 2014 IEEE 28th International Parallel and Distributed Processing Symposium, pp. 679\u2013688 (2014)","DOI":"10.1109\/IPDPS.2014.76"},{"key":"66_CR46","doi-asserted-by":"crossref","unstructured":"Sullivan, G.T., Bruening, D.L., Baron, I., Garnett, T., Amarasinghe, S.: Dynamic native optimization of interpreters. In: Proceedings of the 2003 Workshop on Interpreters, Virtual Machines and Emulators, IVME 2003, pp. 50\u201357. Association for Computing Machinery (2003)","DOI":"10.1145\/858570.858576"},{"key":"66_CR47","doi-asserted-by":"crossref","unstructured":"Ugarte-Pedrero, X., Balzarotti, D., Santos, I., Bringas, P.G.: Sok: deep packer inspection: a longitudinal study of the complexity of run-time packers. In: 2015 IEEE Symposium on Security and Privacy, pp. 659\u2013673 (May 2015)","DOI":"10.1109\/SP.2015.46"},{"key":"66_CR48","doi-asserted-by":"crossref","unstructured":"van\u00a0der Veen, V., Andriesse, D., Stamatogiannakis, M., Chen, X., Bos, H., Giuffrida, C.: The dynamics of innocent flesh on the bone: code reuse ten years later. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, pp. 1675\u20131689 (2017)","DOI":"10.1145\/3133956.3134026"},{"key":"66_CR49","unstructured":"Wang, T., Lu, K., Lu, L., Chung, S., Lee, W.: Jekyll on iOS: when benign apps become evil. In: Proceedings of the 22Nd USENIX Conference on Security, SEC2013, pp. 559\u2013572 (2013)"},{"key":"66_CR50","doi-asserted-by":"crossref","unstructured":"Wang, Y., Patil, H., Pereira, C., Lueck, G., Gupta, R., Neamtiu, I.: Drdebug: deterministic replay based cyclic debugging with dynamic slicing. In: Proceedings of Annual IEEE\/ACM International Symposium on Code Generation and Optimization, CGO 2014, pp. 98\u2013108. Association for Computing Machinery (2014)","DOI":"10.1145\/2544137.2544152"},{"issue":"2","key":"66_CR51","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using CWSandbox. IEEE Secur. Priv. 5(2), 32\u201339 (2007)","journal-title":"IEEE Secur. Priv."},{"key":"66_CR52","doi-asserted-by":"publisher","unstructured":"Xu, Z., Zhang, J., Gu, G., Lin, Z.: GoldenEye: efficiently and effectively unveiling malware\u2019s targeted environment. In: Proceedings of the 17th International Conference on Research in Attacks, Intrusions and Defenses, RAID2014, pp. 22\u201345. Springer International Publishing, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11379-1_2","DOI":"10.1007\/978-3-319-11379-1_2"},{"key":"66_CR53","doi-asserted-by":"crossref","unstructured":"Zhao, Q., Bruening, D., Amarasinghe, S.: Umbra: efficient and scalable memory shadowing. In: Proceedings of the 8th Annual IEEE\/ACM International Symposium on Code Generation and Optimization, CGO 2010, pp. 22\u201331. Association for Computing Machinery (2010)","DOI":"10.1145\/1772954.1772960"},{"issue":"5","key":"66_CR54","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1145\/1127577.1127584","volume":"33","author":"Q Zhao","year":"2005","unstructured":"Zhao, Q., Rabbah, R., Wong, W.-F.: Dynamic memory optimization using pool allocation and prefetching. SIGARCH Comput. Archit. News 33(5), 27\u201332 (2005)","journal-title":"SIGARCH Comput. Archit. News"}],"container-title":["Lecture Notes in Networks and Systems","Intelligent Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-80129-8_66","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T07:14:24Z","timestamp":1771658064000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-80129-8_66"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030801281","9783030801298"],"references-count":54,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-80129-8_66","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"6 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}