{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T15:53:18Z","timestamp":1742917998403,"version":"3.40.3"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319120867"},{"type":"electronic","value":"9783319120874"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-12087-4_7","type":"book-chapter","created":{"date-parts":[[2014,10,24]],"date-time":"2014-10-24T19:32:54Z","timestamp":1414179174000},"page":"101-117","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Automatic Detection and Analysis of Encrypted Messages in Malware"],"prefix":"10.1007","author":[{"given":"Ruoxu","family":"Zhao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dawu","family":"Gu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juanru","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuanyuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,10,25]]},"reference":[{"key":"7_CR1","unstructured":"PIN - a dynamic binary instrumentation tool. http:\/\/software.intel.com\/en-us\/articles\/pin-a-dynamic-binary-instrumentation-tool"},{"key":"7_CR2","unstructured":"QEMU open source processor emulator. http:\/\/wiki.qemu.org\/Main_Page"},{"key":"7_CR3","doi-asserted-by":"crossref","unstructured":"Caballero, J., Poosankam, P., Kreibich, C., Song, D.: Dispatcher: enabling active botnet infiltration using automatic protocol reverse-engineering. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, pp. 621\u2013634. ACM (2009)","DOI":"10.1145\/1653662.1653737"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Caballero, J., Yin, H., Liang, Z., Song, D.: Polyglot: automatic extraction of protocol message format using dynamic binary analysis. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 317\u2013329. ACM (2007)","DOI":"10.1145\/1315245.1315286"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Calvet, J., Fernandez, J.M., Marion, J.Y.: Aligot: cryptographic function identification in obfuscated binary programs. In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, pp. 169\u2013182. ACM (2012)","DOI":"10.1145\/2382196.2382217"},{"key":"7_CR6","doi-asserted-by":"crossref","unstructured":"Cho, C.Y., Shin, E.C.R., Song, D., et al.: Inference and analysis of formal models of botnet command and control protocols. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, pp. 426\u2013439. ACM (2010)","DOI":"10.1145\/1866307.1866355"},{"key":"7_CR7","doi-asserted-by":"crossref","unstructured":"Comparetti, P.M., Wondracek, G., Kruegel, C., Kirda, E.: Prospex: protocol specification extraction. In: 2009 30th IEEE Symposium on Security and Privacy, pp. 110\u2013125. IEEE (2009)","DOI":"10.1109\/SP.2009.14"},{"key":"7_CR8","unstructured":"Cui, W., Kannan, J., Wang, H.J.: Discoverer: automatic protocol reverse engineering from network traces. In: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, pp. 1\u201314 (2007)"},{"key":"7_CR9","doi-asserted-by":"crossref","unstructured":"Cui, W., Peinado, M., Chen, K., Wang, H.J., Irun-Briz, L.: Tupni: automatic reverse engineering of input formats. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 391\u2013402. ACM (2008)","DOI":"10.1145\/1455770.1455820"},{"key":"7_CR10","unstructured":"Elisan, C.: The XOR bypass (2012). https:\/\/blog.damballa.com\/archives\/tag\/malware-dropper"},{"key":"7_CR11","unstructured":"Gr\u00f6bert, F.: Automatic identification of cryptographic primitives in software. Diploma thesis, Ruhr-University Bochum, Germany (2010)"},{"key":"7_CR12","unstructured":"Lee, C.P.: Framework for botnet emulation and analysis. ProQuest (2009)"},{"key":"7_CR13","unstructured":"Li, X., Wang, X., Chang, W.: CipherXRay: exposing cryptographic operations and transient secrets from monitored binary execution (2012)"},{"key":"7_CR14","unstructured":"Lin, Z., Jiang, X., Xu, D., Zhang, X.: Automatic protocol format reverse engineering through context-aware monitored execution. In: NDSS, vol. 8, pp. 1\u201315 (2008)"},{"key":"7_CR15","unstructured":"Lutz, N.: Towards revealing attackers intent by automatically decrypting network traffic. Master\u2019s thesis, ETH, Z\u00fcrich, Switzerland, July 2008"},{"key":"7_CR16","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: NDSS (2005)"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Rossow, C., Dietrich, C.J.: ProVeX: detecting botnets with encrypted command and control channels. In: DIMVA (2013)","DOI":"10.1007\/978-3-642-39235-1_2"},{"key":"7_CR18","series-title":"Lecture Notes in Computer Science","first-page":"1","volume-title":"Applied Cryptography and Network Security","author":"Y Wang","year":"2011","unstructured":"Wang, Y., Zhang, Z., Yao, D.D., Qu, B., Guo, L.: Inferring protocol state machine from network traces: a probabilistic approach. In: Lopez, J., Tsudik, G. (eds.) ACNS 2011. LNCS, vol. 6715, pp. 1\u201318. Springer, Heidelberg (2011)"},{"key":"7_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"200","DOI":"10.1007\/978-3-642-04444-1_13","volume-title":"Computer Security \u2013 ESORICS 2009","author":"Z Wang","year":"2009","unstructured":"Wang, Z., Jiang, X., Cui, W., Wang, X., Grace, M.: ReFormat: automatic reverse engineering of encrypted messages. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 200\u2013215. Springer, Heidelberg (2009)"},{"key":"7_CR20","unstructured":"Wondracek, G., Comparetti, P.M., Kruegel, C., Kirda, E., Anna, S.S.S.: Automatic network protocol analysis. In: NDSS, vol. 8, pp. 1\u201314 (2008)"},{"key":"7_CR21","unstructured":"Zhao, R.: Lochsemu process emulator for windows x86. https:\/\/github.com\/zhaoruoxu\/lochsemu"},{"key":"7_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1007\/978-3-642-34129-8_22","volume-title":"Information and Communications Security","author":"R Zhao","year":"2012","unstructured":"Zhao, R., Gu, D., Li, J., Liu, H.: Detecting encryption functions via process emulation and IL-based program analysis. In: Chim, T.W., Yuen, T.H. (eds.) ICICS 2012. LNCS, vol. 7618, pp. 252\u2013263. Springer, Heidelberg (2012)"},{"key":"7_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1007\/978-3-642-24861-0_13","volume-title":"Information Security","author":"R Zhao","year":"2011","unstructured":"Zhao, R., Gu, D., Li, J., Yu, R.: Detection and analysis of cryptographic data inside software. In: Lai, X., Zhou, J., Li, H. (eds.) ISC 2011. LNCS, vol. 7001, pp. 182\u2013196. Springer, Heidelberg (2011)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-12087-4_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,19]],"date-time":"2023-01-19T23:54:23Z","timestamp":1674172463000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-12087-4_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319120867","9783319120874"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-12087-4_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"25 October 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}