{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,4]],"date-time":"2025-05-04T06:40:09Z","timestamp":1746340809528,"version":"3.40.4"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319112114"},{"type":"electronic","value":"9783319112121"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-11212-1_27","type":"book-chapter","created":{"date-parts":[[2014,8,14]],"date-time":"2014-08-14T20:36:45Z","timestamp":1408048605000},"page":"475-493","source":"Crossref","is-referenced-by-count":8,"title":["RootkitDet: Practical End-to-End Defense against Kernel Rootkits in a Cloud Environment"],"prefix":"10.1007","author":[{"given":"Lingchen","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sachin","family":"Shetty","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiwu","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"27_CR1","unstructured":"McAfee: Rootkits, Part 1 of 3: A Growing Threat. white paper (April 2006)"},{"key":"27_CR2","unstructured":"McAfee: 2010 Threat Predictions. white paper, McAfee AVERT Labs (December 2009)"},{"issue":"5","key":"27_CR3","doi-asserted-by":"publisher","first-page":"670","DOI":"10.1109\/TDSC.2010.38","volume":"8","author":"A. Baliga","year":"2011","unstructured":"Baliga, A., Ganapathy, V., Iftode, L.: Detecting kernel-level rootkits using data structure invariants. IEEE Transactions on Dependable and Secure Computing\u00a08(5), 670\u2013684 (2011)","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"27_CR4","unstructured":"Petroni Jr., N.L., Fraser, T., Walters, A., Arbaugh, W.A.: An architecture for specification-based detection of semantic integrity violations in kernel dynamic data. In: Proceedings of the 15th USENIX Security Symposium, pp. 289\u2013304 (2006)"},{"key":"27_CR5","doi-asserted-by":"crossref","unstructured":"Petroni Jr., N.L., Hicks, M.: Automated detection of persistent kernel control-flow attacks. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 103\u2013115. ACM (2007)","DOI":"10.1145\/1315245.1315260"},{"key":"27_CR6","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X., Cui, W., Ning, P.: Countering kernel rootkits with lightweight hook protection. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 545\u2013554. ACM (2009)","DOI":"10.1145\/1653662.1653728"},{"key":"27_CR7","doi-asserted-by":"crossref","unstructured":"Kruegel, C., Robertson, W., Vigna, G.: Detecting kernel-level rootkits through binary analysis. In: 20th Annual Computer Security Applications Conference 2004, pp. 91\u2013100. IEEE (2004)","DOI":"10.1109\/CSAC.2004.19"},{"key":"27_CR8","doi-asserted-by":"crossref","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: Secvisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity oses. In: ACM SIGOPS Operating Systems Review, vol.\u00a041, pp. 335\u2013350. ACM (2007)","DOI":"10.1145\/1323293.1294294"},{"key":"27_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-87403-4_1","volume-title":"Recent Advances in Intrusion Detection","author":"R. Riley","year":"2008","unstructured":"Riley, R., Jiang, X., Xu, D.: Guest-transparent prevention of kernel rootkits with vmm-based memory shadowing. In: Lippmann, R., Kirda, E., Trachtenberg, A. (eds.) RAID 2008. LNCS, vol.\u00a05230, pp. 1\u201320. Springer, Heidelberg (2008)"},{"key":"27_CR10","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: An architecture for secure active monitoring using virtualization. In: IEEE Symposium on Security and Privacy, SP 2008, pp. 233\u2013247. IEEE (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"27_CR11","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through vmm-based out-of-the-box semantic view reconstruction. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 128\u2013138. ACM (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"27_CR12","doi-asserted-by":"crossref","unstructured":"Fraser, T., Evenson, M.R., Arbaugh, W.A.: Vici-virtual machine introspection for cognitive immunity. In: Annual Computer Security Applications Conference, ACSAC 2008, pp. 87\u201396. IEEE (2008)","DOI":"10.1109\/ACSAC.2008.33"},{"key":"27_CR13","unstructured":"Kemerlis, V.P., Portokalidis, G., Keromytis, A.D.: kguard: lightweight kernel protection against return-to-user attacks. In: USENIX Security Symposium (2012)"},{"key":"27_CR14","unstructured":"Linux-KVM: Linux-KVM, http:\/\/www.linux-kvm.org\/page\/Main_Page"},{"key":"27_CR15","unstructured":"Litty, L., Lagar-Cavilla, H.A., Lie, D.: Hypervisor support for identifying covertly executing binaries. In: Proceedings of the 17th Conference on Security Symposium, pp. 243\u2013258 (2008)"},{"key":"27_CR16","doi-asserted-by":"crossref","unstructured":"Wagner, D., Dean, D.: Intrusion detection via static analysis. In: Proceedings of the 2001 IEEE Symposium on Security and Privacy, S&P 2001, pp. 156\u2013168. IEEE (2001)","DOI":"10.1109\/SECPRI.2001.924296"},{"key":"27_CR17","doi-asserted-by":"crossref","unstructured":"Baliga, A., Kamat, P., Iftode, L.: Lurking in the shadows: Identifying systemic threats to kernel data. In: IEEE Symposium on Security and Privacy, SP 2007, pp. 246\u2013251. IEEE (2007)","DOI":"10.1109\/SP.2007.25"},{"key":"27_CR18","unstructured":"Stealth: Announcing full functional adore-ng rootkit for 2.6 kernel, http:\/\/lwn.net\/Articles\/75991\/"},{"key":"27_CR19","unstructured":"eNYe Sec: eNYeLKM v1.1, http:\/\/www.enye-sec.org\/en\/tags\/enye-lkm\/"},{"key":"27_CR20","unstructured":"Halflife: Abuse of the Linux-kernel for Fun and Profit. Phrack Magazine 5(50) (April 1997)"},{"key":"27_CR21","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: Proc. Network and Distributed Systems Security Symposium (2003)"},{"key":"27_CR22","unstructured":"Hund, R., Holz, T., Freiling, F.C.: Return-oriented rootkits: Bypassing kernel code integrity protection mechanisms. In: Proceedings of the 18th USENIX Security Symposium, pp. 383\u2013398 (2009)"}],"container-title":["Lecture Notes in Computer Science","Computer Security - ESORICS 2014"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-11212-1_27","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,4]],"date-time":"2025-05-04T06:07:15Z","timestamp":1746338835000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-11212-1_27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319112114","9783319112121"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-11212-1_27","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}