{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,1]],"date-time":"2025-06-01T21:40:49Z","timestamp":1748814049485},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319308395"},{"type":"electronic","value":"9783319308401"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-30840-1_17","type":"book-chapter","created":{"date-parts":[[2016,3,9]],"date-time":"2016-03-09T09:15:22Z","timestamp":1457514922000},"page":"262-277","source":"Crossref","is-referenced-by-count":1,"title":["Uncloaking Rootkits on Mobile Devices with a Hypervisor-Based Detector"],"prefix":"10.1007","author":[{"given":"Julian","family":"Vetter","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Junker-Petschick","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jan","family":"Nordholz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Peter","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Janis","family":"Danisevskis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,3,10]]},"reference":[{"key":"17_CR1","unstructured":"Antutu Hong Kong: Antutu benchmark. \n                      http:\/\/www.antutu.com\/en\/Ranking.shtml\n                      \n                    . Accessed 12 May 2015"},{"key":"17_CR2","unstructured":"Ltd, ARM: mbed TLS. \n                      https:\/\/tls.mbed.org\/\n                      \n                    . Accessed 26 May 2015"},{"issue":"4","key":"17_CR3","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1145\/1899928.1899945","volume":"44","author":"K Barr","year":"2010","unstructured":"Barr, K., Bungale, P., Deasy, S., Gyuris, V., Hung, P., Newell, C., Tuch, H., Zoppis, B.: The VMware mobile virtualization platform: is that a hypervisor in your pocket? ACM SIGOPS Oper. Syst. Rev. 44(4), 124\u2013135 (2010)","journal-title":"ACM SIGOPS Oper. Syst. Rev."},{"issue":"4","key":"17_CR4","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1145\/2775054.2694380","volume":"50","author":"Patrick Colp","year":"2015","unstructured":"Colp, P., Zhang, J., Gleeson, J., Suneja, S., de Lara, E., Raj, H., Saroiu, S., Wolman, A.: Protecting data on smartphones and tablets from memory attacks. In: Proceedings of the Twentieth International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2015, pp. 177\u2013189. ACM, New York (2015). \n                      http:\/\/acm.org\/10.1145\/2694344.2694380","journal-title":"ACM SIGPLAN Notices"},{"key":"17_CR5","unstructured":"Cui, W., Peinado, M., Xu, Z., Chan, E.: Tracking rootkit footprints with a practical memory analysis system. In: USENIX Security Symposium, pp. 601\u2013615 (2012)"},{"key":"17_CR6","unstructured":"Danisevskis, J., Peter, M., Nordholz, J., Petschick, M., Vetter, J.: Graphical user interface for virtualized mobile handsets (2015)"},{"key":"17_CR7","doi-asserted-by":"crossref","unstructured":"David, F.M., Chan, E.M., Carlyle, J.C., Campbell, R.H.: Cloaker: hardware supported rootkit concealment. In: 2008 IEEE Symposium on Security and Privacy, SP 2008, pp. 296\u2013310. IEEE (2008)","DOI":"10.1109\/SP.2008.8"},{"key":"17_CR8","unstructured":"Dharmdasani, H.: Android-rootkit (2015) \n                      https:\/\/github.com\/hiteshd\/Android-Rootkit\n                      \n                    . Accessed 13 April 2015"},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., Lee, W.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: 2011 IEEE Symposium on Security and Privacy (SP), pp. 297\u2013312. IEEE (2011)","DOI":"10.1109\/SP.2011.11"},{"key":"17_CR10","unstructured":"F-Secure Labs: Mobile threat report q1 2014, April 2014. \n                      https:\/\/www.f-secure.com\/documents\/996508\/1030743\/Mobile_Threat_Report_Q1_2014.pdf\n                      \n                    . Accessed 11 April 2015"},{"key":"17_CR11","first-page":"191","volume":"3","author":"T Garfinkel","year":"2003","unstructured":"Garfinkel, T., Rosenblum, M., et al.: A virtual machine introspection based architecture for intrusion detection. NDSS 3, 191\u2013206 (2003)","journal-title":"NDSS"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Gotzfried, J., Muller, T.: Armored: CPU-bound encryption for android-driven arm devices. In: 2013 Eighth International Conference on Availability, Reliability and Security (ARES), pp. 161\u2013168, September 2013","DOI":"10.1109\/ARES.2013.23"},{"key":"17_CR13","unstructured":"Guerrero, S.: Getting sys_call_table on android, March 2013. \n                      https:\/\/www.nowsecure.com\/blog\/2013\/03\/13\/syscalltable-android-playing-rootkits\/\n                      \n                    . Accessed 29 April 2015"},{"issue":"3","key":"17_CR14","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1145\/1368506.1368517","volume":"42","author":"B Hay","year":"2008","unstructured":"Hay, B., Nance, K.: Forensics examination of volatile system data using virtual introspection. SIGOPS Oper. Syst. Rev. 42(3), 74\u201382 (2008)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"17_CR15","unstructured":"Hofmann, O.S., Dunn, A.M., Kim, S., Roy, I., Witchel, E.: Ensuring operating system kernel integrity with OSck. In: Proceedings of the Sixteenth International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS XVI, pp. 279\u2013290. ACM, New York (2011). \n                      http:\/\/acm.org\/10.1145\/1950365.1950398"},{"key":"17_CR16","volume-title":"Rootkits: Subverting the Windows Kernel","author":"G Hoglund","year":"2005","unstructured":"Hoglund, G., Butler, J.: Rootkits: Subverting the Windows Kernel. Addison-Wesley Professional, Reading (2005)"},{"key":"17_CR17","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through VMM-based out-of-the-box semantic view reconstruction. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 128\u2013138. ACM (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"17_CR18","unstructured":"Kapoor, A., Mathur, R.: Predicting the future of stealth attacks (2011). \n                      http:\/\/www.mcafee.com\/de\/resources\/reports\/rp-predicting-stealth-attacks.pdf"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Klein, G., Elphinstone, K., Heiser, G., Andronick, J., Cock, D., Derrin, P., Elkaduwe, D., Engelhardt, K., Kolanski, R., Norrish, M., et al.: sel4: formal verification of an OS kernel. In: Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, pp. 207\u2013220. ACM (2009)","DOI":"10.1145\/1629575.1629596"},{"key":"17_CR20","unstructured":"mncoppola: An lkm rootkit targeting linux 2.6\/3.x on x\n                      \n                        \n                      \n                      $$86(\\_64)$$\n                      \n                        \n                          \n                            86\n                            (\n                            _\n                            64\n                            )\n                          \n                        \n                      \n                    , and arm, September 2014. \n                      https:\/\/github.com\/mncoppola\/suterusu\n                      \n                    . Accessed 13 April 2015"},{"key":"17_CR21","unstructured":"National Vulnerability Database: CVE-2015-3456, January 2015. \n                      https:\/\/web.nvd.nist.gov\/view\/vuln\/detail?vulnId=CVE-2015-7835\n                      \n                    . Accessed 01 November 2015"},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"Nordholz, J., Vetter, J., Peter, M., Junker-Petschick, M., Danisevskis, J.: Xnpro: low-impact hypervisor-based execution prevention on arm. In: Proceedings of the 5th International Workshop on Trustworthy Embedded Devices, pp. 55\u201364. ACM (2015)","DOI":"10.1145\/2808414.2808415"},{"key":"17_CR23","unstructured":"Petroni Jr., N.L., Fraser, T., Molina, J., Arbaugh, W.A.: Copilot - a coprocessor-based kernel runtime integrity monitor. In: Proceedings of the 13th Conference on USENIX Security Symposium, SSYM 2004, vol. 13. p. 13. USENIX Association, Berkeley (2004). \n                      http:\/\/dl.acm.org\/citation.cfm?id=1251375.1251388"},{"key":"17_CR24","unstructured":"Richer, T.J., Neale, G., Osborne, G.: On the effectiveness of virtualisation assisted view comparison for rootkit detection. In: Proceedings of the 13th Australasian Information Security Conference (AISC 2015), vol. 27, p. 30 (2015)"},{"key":"17_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-87403-4_1","volume-title":"Recent Advances in Intrusion Detection","author":"R Riley","year":"2008","unstructured":"Riley, R., Jiang, X., Xu, D.: Guest-transparent prevention of kernel rootkits with VMM-based memory shadowing. In: Lippmann, R., Kirda, E., Trachtenberg, A. (eds.) RAID 2008. LNCS, vol. 5230, pp. 1\u201320. Springer, Heidelberg (2008)"},{"key":"17_CR26","unstructured":"Studer, N., VanVossen, R.: Xen and the art of certification. Xen Developer Summit 2014 (2014)"},{"key":"17_CR27","unstructured":"trimpsyw: adore-ng - linux rootkit adapted for 2.6 and 3.x, October 2014. \n                      https:\/\/github.com\/trimpsyw\/adore-ng\n                      \n                    . Accessed 13 April 2015\u201304-13"},{"key":"17_CR28","unstructured":"unixfreaxjp: Mmd-0028-2014 - fuzzy reversing a new china elf \u201clinux\/xor.ddos\u201d, September 2014. \n                      http:\/\/blog.malwaremustdie.org\/2014\/09\/mmd-0028-2014-fuzzy-reversing-new-china.html\n                      \n                    . Accessed 16 April 2015"},{"key":"17_CR29","doi-asserted-by":"crossref","unstructured":"Vogl, S., Pfoh, J., Kittel, T., Eckert, C.: Persistent data-only malware: function hooks without code. In: Symposium on Network and Distributed System Security (NDSS) (2014)","DOI":"10.14722\/ndss.2014.23019"},{"key":"17_CR30","unstructured":"Yan, L.K., Yin, H.: Droidscope: seamlessly reconstructing the OS and Dalvik semantic views for dynamic android malware analysis. In: USENIX Security Symposium, pp. 569\u2013584 (2012)"},{"key":"17_CR31","doi-asserted-by":"crossref","unstructured":"You, D.-H.: Android platform based Linux kernel rootkit. Phrack 68, April 2011","DOI":"10.1109\/MALWARE.2011.6112330"},{"key":"17_CR32","unstructured":"Zeng, J., Fu, Y., Lin, Z.: Pemu: a pin highly compatible out-of-VM dynamic binary instrumentation framework. In: Proceedings of the 11th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE 2015, pp. 147\u2013160. ACM, New York (2015). \n                      http:\/\/acm.org\/10.1145\/2731186.2731201"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology - ICISC 2015"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-30840-1_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,1]],"date-time":"2019-06-01T13:53:06Z","timestamp":1559397186000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-30840-1_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319308395","9783319308401"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-30840-1_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}