{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T03:30:34Z","timestamp":1777433434565,"version":"3.51.4"},"publisher-location":"Cham","reference-count":20,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319736969","type":"print"},{"value":"9783319736976","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-73697-6_1","type":"book-chapter","created":{"date-parts":[[2018,1,5]],"date-time":"2018-01-05T02:53:43Z","timestamp":1515120823000},"page":"3-17","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud"],"prefix":"10.1007","author":[{"given":"Xiaoqi","family":"Jia","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guangzhe","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingjia","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weijuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Donghai","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,1,6]]},"reference":[{"key":"1_CR1","unstructured":"Symantec. \nhttps:\/\/www.symantec.com\/security-center\/threat-report"},{"key":"1_CR2","unstructured":"Kirat, D., Vigna, G., Kruegel, C.: Barecloud: bare-metal analysis-based evasive malware detection. In: Malware Detection (2014)"},{"key":"1_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1007\/978-3-642-23644-0_18","volume-title":"Recent Advances in Intrusion Detection","author":"M Lindorfer","year":"2011","unstructured":"Lindorfer, M., Kolbitsch, C., Milani Comparetti, P.: Detecting environment-sensitive malware. In: Sommer, R., Balzarotti, D., Maier, G. (eds.) RAID 2011. LNCS, vol. 6961, pp. 338\u2013357. Springer, Heidelberg (2011). \nhttps:\/\/doi.org\/10.1007\/978-3-642-23644-0_18"},{"key":"1_CR4","unstructured":"Linux Foundation: The Xen project. \nhttp:\/\/www.xenproject.org\/\n\n. Accessed 4 Mar 2017"},{"key":"1_CR5","unstructured":"Cuckoo Sandbox. \nhttp:\/\/www.cuckoosandbox.org"},{"key":"1_CR6","unstructured":"Bayer, U., Comparetti, P.M., Hlauschek, C., Krgel, C., Kirda, E.: Scalable, behavior-based malware clustering. In: Network and Distributed System Security Symposium, NDSS 2009, San Diego, California, USA, February 2009"},{"key":"1_CR7","first-page":"2229","volume":"2","author":"DMW Powers","year":"2011","unstructured":"Powers, D.M.W.: Evaluation: from precision, recall and f-factor to ROC, informedness, markedness and correlation. J. Mach. Learn. Technol. 2, 2229\u20133981 (2011)","journal-title":"J. Mach. Learn. Technol."},{"key":"1_CR8","unstructured":"VX Heaven Virus Collection: VX Heaven. \nhttp:\/\/vx.nextlux.org\n\n. Accessed 4 Mar 2017"},{"issue":"2","key":"1_CR9","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using CWSandbox. IEEE Secur. Priv. 5(2), 32\u201339 (2007)","journal-title":"IEEE Secur. Priv."},{"key":"1_CR10","unstructured":"Norman Sandbox. \nhttp:\/\/www.norman.com\/"},{"key":"1_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1007\/978-3-540-74320-0_11","volume-title":"Recent Advances in Intrusion Detection","author":"X Jiang","year":"2007","unstructured":"Jiang, X., Wang, X.: \u201cOut-of-the-Box\u201d monitoring of VM-based high-interaction honeypots. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 198\u2013218. Springer, Heidelberg (2007). \nhttps:\/\/doi.org\/10.1007\/978-3-540-74320-0_11"},{"key":"1_CR12","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: A Tool for Analyzing Malware (2006)"},{"key":"1_CR13","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: ACM Conference on Computer and Communications Security, CCS 2007, Alexandria, Virginia, USA, pp. 116\u2013127, October 2007","DOI":"10.1145\/1315245.1315261"},{"key":"1_CR14","unstructured":"Bellard, F.: QEMU, a fast and portable dynamic translator. In: Conference on USENIX Technical Conference, p. 41 (2005)"},{"key":"1_CR15","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: ACM Conference on Computer and Communications Security, CCS 2008, Alexandria, Virginia, USA, pp. 51\u201362, October 2008","DOI":"10.1145\/1455770.1455779"},{"key":"1_CR16","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through VMM-based \u201cOut-of-the-Box\u201d semantic view reconstruction. In: ACM Conference on Computer and Communications Security, CCS 2007, Alexandria, Virginia, USA, pp. 128\u2013138, October 2007","DOI":"10.1145\/1315245.1315262"},{"key":"1_CR17","doi-asserted-by":"crossref","unstructured":"Fattori, A., Paleari, R., Martignoni, L., Monga, M.: Dynamic and transparent analysis of commodity production systems. In: IEEE\/ACM International Conference on Automated Software Engineering, pp. 417\u2013426 (2010)","DOI":"10.1145\/1858996.1859085"},{"key":"1_CR18","doi-asserted-by":"crossref","unstructured":"Vasudevan, A., Yerraballi, R.: Cobra: fine-grained malware analysis using stealth localized-executions. In: IEEE Symposium on Security & Privacy, p. 15 pp. -279 (2006)","DOI":"10.1109\/SP.2006.9"},{"key":"1_CR19","unstructured":"Chen, X., Andersen, J., Mao, Z.M., Bailey, M.: Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware. In: IEEE International Conference on Dependable Systems and Networks with FTCS and DCC, pp. 177\u2013186 (2008)"},{"issue":"3","key":"1_CR20","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/s11416-008-0096-y","volume":"6","author":"B Lau","year":"2010","unstructured":"Lau, B., Svajcer, V.: Measuring virtual machine detection in malware using DSD tracer. J. Comput. Virol. Hacking Tech. 6(3), 181\u2013195 (2010)","journal-title":"J. Comput. Virol. Hacking Tech."}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-73697-6_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,1,5]],"date-time":"2018-01-05T02:53:57Z","timestamp":1515120837000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-73697-6_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319736969","9783319736976"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-73697-6_1","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}