{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T16:10:05Z","timestamp":1746202205245,"version":"3.40.4"},"publisher-location":"Cham","reference-count":18,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319063195"},{"type":"electronic","value":"9783319063201"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-06320-1_10","type":"book-chapter","created":{"date-parts":[[2014,4,28]],"date-time":"2014-04-28T00:59:27Z","timestamp":1398646767000},"page":"119-128","source":"Crossref","is-referenced-by-count":0,"title":["A Methodology for Hook-Based Kernel Level Rootkits"],"prefix":"10.1007","author":[{"given":"Chien-Ming","family":"Chen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mu-En","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bing-Zhe","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinying","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chieh","family":"Hsing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hung-Min","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"8","key":"10_CR1","doi-asserted-by":"publisher","first-page":"1318","DOI":"10.1109\/TIFS.2013.2270106","volume":"8","author":"C.-M. Chen","year":"2013","unstructured":"Chen, C.-M., Wang, K.-H., Wu, T.-Y., Pan, J.-S., Sun, H.-M.: A scalable transitive human-verifiable authentication protocol for mobile devices. IEEE Transactions on Information Forensics and Security\u00a08(8), 1318\u20131330 (2013)","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10_CR2","unstructured":"DiabloNova. Rootkit Unhooker v3.8 (2007), http:\/\/www.rootkit.com\/newsread.php?newsid=902"},{"issue":"5","key":"10_CR3","doi-asserted-by":"publisher","first-page":"2345","DOI":"10.1016\/j.eswa.2013.09.032","volume":"41","author":"B.-Z. He","year":"2014","unstructured":"He, B.-Z., Chen, C.-M., Su, Y.-P., Sun, H.-M.: A defence scheme against identity theft attack based on multiple social networks. Expert Systems with Applications\u00a041(5), 2345\u20132352 (2014)","journal-title":"Expert Systems with Applications"},{"key":"10_CR4","unstructured":"Hoglund, G., Butler, J.: HideProcessHookMDL (2004), http:\/\/www.rootkit.com\/"},{"key":"10_CR5","unstructured":"Hoglund, G., Butler, J.: Rootkits-Subverting the Windows Kernel. Addison-Wesley (2004)"},{"key":"10_CR6","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy Malware Detection through VMM-Based \u201cOut-of-the-Box\u201d SemanticView Reconstruction. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 128\u2013138 (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"10_CR7","unstructured":"Joanna, R.: Thoughts about Cross-View Based Rootkit Detection (2005), http:\/\/invisiblethings.org"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"King, S.T., Chen, P.M., Wang, Y.-M., Verbowski, C., Wang, H.J., Lorch, J.R.: SubVirt: Implementing Malware with Virtual Machines. In: 2006 IEEE Symposium on Security and Privacy, pp. 314\u2013327 (2006)","DOI":"10.1109\/SP.2006.38"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Robertson, W., Vigna, G.: Detecting Kernel-Level Rootkits through Binary Analysis. In: Proceedings of the 20th Annual Computer Security Applications Conference, pp. 91\u2013100. IEEE Computer Society (2004)","DOI":"10.1109\/CSAC.2004.19"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Levine, J., Grizzard, J., Owen, H.: A Methodology to Detect and Characterize Kernel Level Rootkit Exploits Involving Redirection of the System Call Table. In: Proceedings of the Second IEEE International Information Assurance Workshop, pp. 107\u2013125. IEEE (2004)","DOI":"10.1109\/IWIA.2004.1288042"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Levine, J., Grizzard, J., Phillip, H., Owen, H.: A Methodology to Characterize Kernel Level Rootkit Exploits that Overwrite the System Call Table. In: Proceedings of the IEEE SoutheastCon, pp. 25\u201331. IEEE (2004)","DOI":"10.1109\/SECON.2004.1287894"},{"issue":"4","key":"10_CR12","first-page":"201","volume":"4","author":"C.-W. Lin","year":"2013","unstructured":"Lin, C.-W., Hong, T.-P., Chang, C.-C., Wang, S.-L.: A greedy-based approach for hiding sensitive itemsets by transaction insertion. Journal of Information Hiding and Multimedia Signal Processing\u00a04(4), 201\u2013227 (2013)","journal-title":"Journal of Information Hiding and Multimedia Signal Processing"},{"key":"10_CR13","unstructured":"R. S. Projects. RootKit Hook Analyzer (2007), http:\/\/www.resplendence.com\/hookanalyzer"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Quynh, N.A., Takefuji, Y.: Towards a Tamper-Resistant Kernel Rootkit Detector. In: Proceedings of the 2007 ACM Symposium on Applied Computing, pp. 276\u2013283. ACM (2007)","DOI":"10.1145\/1244002.1244070"},{"issue":"6","key":"10_CR15","doi-asserted-by":"publisher","first-page":"1109","DOI":"10.1109\/TMM.2008.2001381","volume":"10","author":"H.-M. Sun","year":"2008","unstructured":"Sun, H.-M., Chen, C.-M., Shieh, C.-Z.: Flexible-pay-per-channel: A new model for content access control in pay-tv broadcasting systems. IEEE Transactions on Multimedia\u00a010(6), 1109\u20131120 (2008)","journal-title":"IEEE Transactions on Multimedia"},{"issue":"6","key":"10_CR16","doi-asserted-by":"publisher","first-page":"813","DOI":"10.1109\/TC.2011.46","volume":"60","author":"H.-M. Sun","year":"2011","unstructured":"Sun, H.-M., Wang, H., Wang, K.-H., Chen, C.-M.: A native apis protection mechanism in the kernel mode against malicious code. IEEE Transactions on Computers\u00a060(6), 813\u2013823 (2011)","journal-title":"IEEE Transactions on Computers"},{"key":"10_CR17","unstructured":"Tan, C.K.: Defeating Kernel Native API Hookers by Direct Service Dispatch Table Restoration (2004), http:\/\/www.security.org.sg"},{"key":"10_CR18","unstructured":"Wang, Y.-M., Beck, D.: Fast User-Mode Rootkit Scanner for the Enterprise. In: Proceedings of the 19th Conference on Large Installation System Administration Conference, pp. 23\u201330. USENIX (2005)"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-06320-1_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,2]],"date-time":"2025-05-02T15:35:21Z","timestamp":1746200121000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-06320-1_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319063195","9783319063201"],"references-count":18,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-06320-1_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}