{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,26]],"date-time":"2026-08-26T03:25:49Z","timestamp":1787714749579,"version":"build-2784847793"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319263618","type":"print"},{"value":"9783319263625","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-26362-5_25","type":"book-chapter","created":{"date-parts":[[2015,10,26]],"date-time":"2015-10-26T10:10:45Z","timestamp":1445854245000},"page":"538-561","source":"Crossref","is-referenced-by-count":5,"title":["Towards Automatic Inference of Kernel Object Semantics from Binary Code"],"prefix":"10.1007","author":[{"given":"Junyuan","family":"Zeng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2015,12,12]]},"reference":[{"key":"25_CR1","unstructured":"Linux test project. \n                      https:\/\/github.com\/linux-test-project"},{"key":"25_CR2","unstructured":"QEMU: an open source processor emulator. \n                      http:\/\/www.qemu.org\/"},{"key":"25_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1007\/978-3-540-24723-4_2","volume-title":"Compiler Construction","author":"G Balakrishnan","year":"2004","unstructured":"Balakrishnan, G., Reps, T.: Analyzing memory accesses in x86 executables. In: Duesterwald, E. (ed.) CC 2004. LNCS, vol. 2985, pp. 5\u201323. Springer, Heidelberg (2004)"},{"key":"25_CR4","doi-asserted-by":"crossref","unstructured":"Caballero, J., Poosankam, P., Kreibich, C., Song, D.: Dispatcher: enabling active botnet infiltration using automatic protocol reverse-engineering. In: Proceedings of the 16th ACM Conference on Computer and and Communications Security (CCS 2009), pp. 621\u2013634, Chicago, Illinois, USA (2009)","DOI":"10.1145\/1653662.1653737"},{"key":"25_CR5","doi-asserted-by":"crossref","unstructured":"Caballero, J., Song, D.: Polyglot: automatic extraction of protocol format using dynamic binary analysis. In: Proceedings of the 14th ACM Conference on Computer and and Communications Security (CCS 2007), pp. 317\u2013329, Alexandria, Virginia, USA (2007)","DOI":"10.1145\/1315245.1315286"},{"key":"25_CR6","unstructured":"Cozzie, A., Stratton, F., Xue, H., King, S.T.: Digging for data structures. In: Proceeding of 8th Symposium on Operating System Design and Implementation (OSDI 2008), pp. 231\u2013244, San Diego, CA, December 2008"},{"key":"25_CR7","doi-asserted-by":"crossref","unstructured":"Cui, W., Peinado, M., Chen, K., Wang, H.J., Irun-Briz, L.: Tupni: automatic reverse engineering of input formats. In: Proceedings of the 15th ACM Conference on Computer and Communications Security (CCS 2008), pp. 391\u2013402, Alexandria, Virginia, USA, October 2008","DOI":"10.1145\/1455770.1455820"},{"key":"25_CR8","doi-asserted-by":"crossref","unstructured":"Damas, L., Milner, R.: Principal type-schemes for functional programs. In: Proceedings of the 9th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, pp. 207\u2013212, January 1982","DOI":"10.1145\/582153.582176"},{"key":"25_CR9","doi-asserted-by":"crossref","unstructured":"Deng, Z., Zhang, X., Xu, D.: Spider: stealthy binary program instrumentation and debugging via hardware virtualization. In: Proceedings of the 29th Annual Computer Security Applications Conference, ACSAC 2013, pp. 289\u2013298, New Orleans, Louisiana (2013)","DOI":"10.1145\/2523649.2523675"},{"key":"25_CR10","doi-asserted-by":"crossref","unstructured":"Fu, Y., Lin, Z.: Space traveling across VM: automatically bridging the semantic gap in virtual machine introspection via online kernel data redirection. In: Proceedings of 33rd IEEE Symposium on Security and Privacy, May 2012","DOI":"10.1109\/SP.2012.40"},{"key":"25_CR11","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: Proceedings Network and Distributed Systems Security Symposium (NDSS 2003), pp. 38\u201353, February 2003"},{"key":"25_CR12","doi-asserted-by":"crossref","unstructured":"Guo, P.J., Perkins, J.H., McCamant, S., Ernst, M.D.: Dynamic inference of abstract types. In: ISSTA, pp. 255\u2013265, July 2006","DOI":"10.1145\/1146238.1146268"},{"key":"25_CR13","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/1368506.1368517","volume":"42","author":"B Hay","year":"2008","unstructured":"Hay, B., Nance, K.: Forensics examination of volatile system data using virtual introspection. SIGOPS Oper. Syst. Rev. 42, 74\u201382 (2008)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"25_CR14","doi-asserted-by":"crossref","unstructured":"Johnson, N., Caballero, J., Chen, K., McCamant, S., Poosankam, P., Reynaud, D., Song, D.: Differential slicing: identifying causal execution differences for security applications. In: Proceedings of 32nd IEEE Symposium on Security and Privacy, pp. 347\u2013362, May 2011","DOI":"10.1109\/SP.2011.41"},{"key":"25_CR15","unstructured":"Jones, S.T., Arpaci-Dusseau, A.C., Arpaci-Dusseau, R.H.: Antfarm: tracking processes in a virtual machine environment. In: Proceedings of the Annual Conference on USENIX 2006 Annual Technical Conference. USENIX Association, Boston (2006)"},{"key":"25_CR16","unstructured":"Lee, J., Avgerinos, T., Brumley, D.: Tie: principled reverse engineering of types in binary programs. In: Proceedings of the 18th Annual Network and Distributed System Security Symposium (NDSS 2011), San Diego, CA, February 2011"},{"key":"25_CR17","unstructured":"Lin, Z., Jiang, X., Xu, D., Zhang, X.: Automatic protocol format reverse engineering through context-aware monitored execution. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, CA, February 2008"},{"key":"25_CR18","unstructured":"Lin, Z., Zhang, X., Xu, D.: Automatic reverse engineering of data structures from binary execution. In: Proceedings of the 17th Annual Network and Distributed System Security Symposium (NDSS 2010), San Diego, CA, February 2010"},{"key":"25_CR19","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Proceedings of the 14th Annual Network and Distributed System Security Symposium (NDSS 2005), San Diego, CA, February 2005"},{"key":"25_CR20","doi-asserted-by":"crossref","unstructured":"O\u2019Callahan, R., Jackson, D.: Lackwit: a program understanding tool based on type inference. In Proceedings of the 19th International Conference on Software Engineering, ICSE 1997, pp. 338\u2013348, Boston, Massachusetts, USA (1997)","DOI":"10.1145\/253228.253351"},{"key":"25_CR21","doi-asserted-by":"crossref","unstructured":"Ramalingam, G., Field, J., Tip, F.: Aggregate structure identification and its application to program analysis. In: Proceedings of the 26th ACM SIGPLAN-SIGACT Symposium on Principles of programming languages (POPL 1999), San Antonio, Texas, pp. 119\u2013132. ACM (1999)","DOI":"10.1145\/292540.292553"},{"key":"25_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1007\/978-3-540-78791-4_2","volume-title":"Compiler Construction","author":"T Reps","year":"2008","unstructured":"Reps, T., Balakrishnan, G.: Improved memory-access analysis for x86 executables. In: Hendren, L. (ed.) CC 2008. LNCS, vol. 4959, pp. 16\u201335. Springer, Heidelberg (2008)"},{"key":"25_CR23","unstructured":"Slowinska, A., Stancescu, T., Bos, H.: Howard: a dynamic excavator for reverse engineering data structures. In: Proceedings of the 18th Annual Network and Distributed System Security Symposium (NDSS 2011), San Diego, CA, February 2011"},{"key":"25_CR24","unstructured":"Walters, A.: The volatility framework: volatile memory artifact extraction utility framework. \n                      https:\/\/www.volatilesystems.com\/default\/volatility"},{"key":"25_CR25","unstructured":"Wondracek, G., Milani, P., Kruegel, C., Kirda, E.: Automatic network protocol analysis. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, CA, February 2008"},{"key":"25_CR26","doi-asserted-by":"crossref","unstructured":"Zeng, J., Fu, Y., Lin, Z.: Pemu: a pin highly compatible out-of-VM dynamic binary instrumentation framework. In: Proceedings of the 11th Annual International Conference on Virtual Execution Environments, pp. 147\u2013160, Istanbul, Turkey, March 2015","DOI":"10.1145\/2817817.2731201"},{"key":"25_CR27","unstructured":"Zhang, M., Prakash, A., Li, X., Liang, Z., Yin, H.: Identifying and analyzing pointer misuses for sophisticated memory-corruption exploit diagnosis. In: Proceedings of the 19th Annual Network and Distributed System Security Symposium (NDSS 2012), San Diego, CA, February 2012"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-26362-5_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,31]],"date-time":"2019-05-31T05:21:15Z","timestamp":1559280075000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-26362-5_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319263618","9783319263625"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-26362-5_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]}}}