{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:38:12Z","timestamp":1759091892733,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319228457"},{"type":"electronic","value":"9783319228464"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-22846-4_15","type":"book-chapter","created":{"date-parts":[[2015,8,13]],"date-time":"2015-08-13T13:50:58Z","timestamp":1439473858000},"page":"249-267","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Proposed Processor Extensions for Significant Speedup of Hypervisor Memory Introspection"],"prefix":"10.1007","author":[{"given":"Andrei","family":"Lu\u0163a\u015f","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S\u00e1ndor","family":"Luk\u00e1cs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrian","family":"Cole\u015fa","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Lu\u0163a\u015f","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,8,14]]},"reference":[{"key":"15_CR1","unstructured":"ARM: ARM Architecture Reference Manual ARMv7-A and ARMv7-R (2014)"},{"key":"15_CR2","unstructured":"BOCHS: The cross-platform IA-32 emulator. http:\/\/bochs.sourceforge.net\/. Accessed on 24\u201311\u20132014"},{"key":"15_CR3","unstructured":"BROMIUM: Bromium vSentry and LAVA products (2014\u201311-24). http:\/\/www.bromium.com\/products.html. Accessed on 24\u201311\u20132014"},{"issue":"4","key":"15_CR4","doi-asserted-by":"publisher","first-page":"12:1","DOI":"10.1145\/2382553.2382554","volume":"30","author":"E Bugnion","year":"2012","unstructured":"Bugnion, E., Devine, S., Rosenblum, M., Sugerman, J., Wang, E.Y.: Bringing virtualization to the x86 architecture with the original vmware workstation. ACM Trans. Comput. Syst 30(4), 12:1\u201312:51 (2012)","journal-title":"ACM Trans. Comput. Syst"},{"key":"15_CR5","doi-asserted-by":"crossref","unstructured":"Chang, C.J., Wu, J.J., Hsu, W.C., Liu, P., Yew, P.C.: Efficient memory virtualization for cross-ISA system mode emulation. In: Proceedings of the 10th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments (VEE 2014), pp. 117\u2013128. ACM, New York (2014)","DOI":"10.1145\/2576195.2576201"},{"key":"15_CR6","unstructured":"Chen, P.M., Noble, B.D.: When virtual is better than real. In: Proceedings of the Eighth Workshop on Hot Topics in Operating Systems (HOTOS 2001), IEEE Computer Society, Washington, DC (2001)"},{"key":"15_CR7","unstructured":"Chennupaty, S., Jiang, H., Sreenivas, A.: Technology Insight: Intel\u2019s Next Generation 14nm Microarchitecture for Client and Server (2014)"},{"key":"15_CR8","unstructured":"Citrix: XenClient XT. The ultimate in multi-level secure local virtual desktops. http:\/\/www.citrix.com\/products\/xenclient\/features\/editions\/xt.html. Accessed on 24\u201311\u20132014"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: Malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS 2008), pp. 51\u201362. ACM, New York (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., Lee, W.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: IEEE Symposium on Security and Privacy (SP), pp. 297\u2013312. IEEE (2011)","DOI":"10.1109\/SP.2011.11"},{"key":"15_CR11","unstructured":"Dontu, M., Sahita, R.: Zero-Footprint Guest Memory Introspection from Xen. In: XenProject Developer Summit (2014)"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Durham, D.: Mitigating exploits, rootkits and advanced persistent threats. In: Proceedings of the 2014 Symposium on High Performance Chips (Hot Chips 2014), IEEE Technical Committee on Microprocessors and Microcomputers in Cooperation with ACM SIGARCH (2014)","DOI":"10.1109\/HOTCHIPS.2014.7478798"},{"key":"15_CR13","unstructured":"FireEye: Advantage FireEye. Debunking the Myth of Sandbox Security (2013)"},{"key":"15_CR14","unstructured":"Garfinkel, T., Rosenblum, M.: A Virtual Machine Introspection Based Architecture for Intrusion Detection. In: Proceedings of Network and Distributed Systems Security Symposium, pp. 191\u2013206 (2003)"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Hammarlund, P.: 4th Generation Intel Core Processor, codenamed Haswell. In: HotChips (2013)","DOI":"10.1109\/HOTCHIPS.2013.7478321"},{"key":"15_CR16","unstructured":"Intel Corporation: intel$$^{\\textregistered }$$ 64 and IA-32 Architectures Software Developer\u2019s Manual (2015). Accessed on 02 Feb 2015"},{"key":"15_CR17","doi-asserted-by":"crossref","unstructured":"Jain, B., Baig, M.B., Zhang, D., Porter, D.E., Sion, R.: SoK: Introspections on trust and the semantic gap. In: Proceedings of the 2014 IEEE Symposium on Security and Privacy (SP 2014), pp. 605\u2013620. IEEE Computer Society, Washington, DC (2014)","DOI":"10.1109\/SP.2014.45"},{"key":"15_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/978-3-540-74320-0_11","volume-title":"Recent Advances in Intrusion Detection","author":"X Jiang","year":"2007","unstructured":"Jiang, X., Wang, X.: \u201cOut-of-the-box\u201d monitoring of VM-based high-interaction honeypots. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 198\u2013218. Springer, Heidelberg (2007)"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Joshi, A., King, S.T., Dunlap, G.W., Chen, P.M.: Detecting past and present intrusions through vulnerability-specific predicates. In: Proceedings of the Twentieth ACM Symposium on Operating Systems Principles (SOSP 2005), pp. 91\u2013104. ACM, New York (2005)","DOI":"10.1145\/1095809.1095820"},{"key":"15_CR20","unstructured":"Lampson, B.: Accountability and freedom (2005)"},{"issue":"11","key":"15_CR21","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1145\/1592761.1592773","volume":"52","author":"B Lampson","year":"2009","unstructured":"Lampson, B.: Privacy and security: usable security: how to get it. Commun. ACM 52(11), 25\u201327 (2009)","journal-title":"Commun. ACM"},{"key":"15_CR22","unstructured":"Lengyel, T., Kittel, T., Webster, G., Torrey, J.: Pitfalls of virtual machine introspection on modern hardware. In: 1st Workshop on Malware Memory Forensics (MMF) (2014)"},{"key":"15_CR23","unstructured":"Lengyel, T.K., Neumann, J., Maresca, S.: Virtual machine introspection in a hybrid honeypot architecture. In: Presented as part of the 5th Workshop on Cyber Security Experimentation and Test. USENIX, Berkeley (2012)"},{"key":"15_CR24","unstructured":"LibVMI: Virtual machine introspection tools. http:\/\/libvmi.com\/. Accessed on 20\u201306-2015"},{"key":"15_CR25","volume-title":"The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory","author":"MH Ligh","year":"2014","unstructured":"Ligh, M.H., Case, A., Levy, J., Walters, A.: The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory, 1st edn. Wiley, New York (2014)","edition":"1"},{"issue":"1","key":"15_CR26","first-page":"1","volume":"9","author":"A Lu\u0163a\u015f","year":"2015","unstructured":"Lu\u0163a\u015f, A., Luk\u00e1cs, S., Lu\u0163a\u015f, D., Cole\u015fa, A.: U-HIPE: hypervisor-based protection of user-mode processes in windows. J. Comput. Virol. Hacking Tech. 9(1), 1\u201314 (2015)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"15_CR27","unstructured":"McAfee: A New Paradigm Shift: Comprehensive Security Beyond the Operating System (2012)"},{"key":"15_CR28","unstructured":"McAfee: McAfee DeepSAFE and Deep Defender (2013)"},{"key":"15_CR29","unstructured":"Mohandas, R., Sahita, R.: Detecting Evasive Malware in Sandbox. In: Focus Security Conference (2014)"},{"key":"15_CR30","unstructured":"Rutkowska, J., Wojtczuk, R.: Qubes OS. http:\/\/www.qubes-os.org\/. Accessed on 24\u201311\u20132014"},{"key":"15_CR31","doi-asserted-by":"crossref","unstructured":"Sharif, M.I., Lee, W., Cui, W., Lanzi, A.: Secure in-VM monitoring using hardware virtualization. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009), pp. 477\u2013487. ACM (2009)","DOI":"10.1145\/1653662.1653720"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Srinivasan, D., Wang, Z., Jiang, X., Xu, D.: Process out-grafting: an efficient \u201cout-of-VM\u201d approach for fine-grained process execution monitoring. In: Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS 2011), pp. 363\u2013374. ACM, New York (2011)","DOI":"10.1145\/2046707.2046751"},{"key":"15_CR33","doi-asserted-by":"crossref","unstructured":"Vasudevan, A., Chaki, S., Jia, L., McCune, J., Newsome, J., Datta, A.: Design, implementation and verification of an eXtensible and modular hypervisor framework. In: Proceedings of the 2013 IEEE Symposium on Security and Privacy (SP 2013), pp. 430\u2013444. IEEE Computer Society, Washington, DC (2013)","DOI":"10.1109\/SP.2013.36"},{"key":"15_CR34","doi-asserted-by":"crossref","unstructured":"Vasudevan, A., McCune, J., Newsome, J., Perrig, A., van Doorn, L.: CARMA: a hardware tamper-resistant isolated execution environment on commodity x86 platforms. In: Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security (ASIACCS 2012), pp. 48\u201349. ACM, New York (2012)","DOI":"10.1145\/2414456.2414484"},{"key":"15_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/978-3-642-13869-0_10","volume-title":"Trust and Trustworthy Computing","author":"A Vasudevan","year":"2010","unstructured":"Vasudevan, A., McCune, J.M., Qu, N., van Doorn, L., Perrig, A.: Requirements for an integrity-protected hypervisor on the x86 hardware virtualized architecture. In: Acquisti, A., Smith, S.W., Sadeghi, A.-R. (eds.) TRUST 2010. LNCS, vol. 6101, pp. 141\u2013165. Springer, Heidelberg (2010)"},{"key":"15_CR36","doi-asserted-by":"crossref","unstructured":"Zhang, F., Chen, J., Chen, H., Zang, B.: CloudVisor: retrofitting protection of virtual machines in multi-tenant cloud with nested virtualization. In: Proceedings of the Twenty-Third ACM Symposium on Operating Systems Principles (SOSP 2011), pp. 203\u2013216. ACM, New York (2011)","DOI":"10.1145\/2043556.2043576"}],"container-title":["Lecture Notes in Computer Science","Trust and Trustworthy Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-22846-4_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,21]],"date-time":"2023-02-21T06:31:48Z","timestamp":1676961108000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-22846-4_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319228457","9783319228464"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-22846-4_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"14 August 2015","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}