{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T05:37:13Z","timestamp":1769924233967,"version":"3.49.0"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319788128","type":"print"},{"value":"9783319788135","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78813-5_42","type":"book-chapter","created":{"date-parts":[[2018,4,10]],"date-time":"2018-04-10T06:03:21Z","timestamp":1523340201000},"page":"778-792","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["A Hypervisor Level Provenance System to Reconstruct Attack Story Caused by\u00a0Kernel Malware"],"prefix":"10.1007","author":[{"given":"Chonghua","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shiqing","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Junghwan","family":"Rhee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaochun","family":"Yun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyu","family":"Hao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,4,11]]},"reference":[{"key":"42_CR1","unstructured":"Unmasking kernel exploits. https:\/\/www.lastline.com\/labsblog\/unmasking-kernel-exploits\/"},{"key":"42_CR2","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1016\/j.cose.2015.03.007","volume":"52","author":"F Aristide","year":"2015","unstructured":"Aristide, F., Andrea, L., Davide, B., Engin, K.: Hypervisor-based malware protection with AccessMiner. Comput. Secur. 52, 33\u201350 (2015)","journal-title":"Comput. Secur."},{"key":"42_CR3","doi-asserted-by":"crossref","unstructured":"Bahram, S., Jiang, X., Wang, Z., Grace, M., Li, J., Srinivasan, D., Rhee, J., Xu, D.: DKSM: subverting virtual machine introspection for fun and profit. In: SRDS, pp. 82\u201391 (2010)","DOI":"10.1109\/SRDS.2010.39"},{"key":"42_CR4","unstructured":"Bates, A., Tian, D., Butler, K., Moyer, T.: Trustworthy whole-system provenance for the Linux kernel. In: USENIX Security, pp. 319\u2013334 (2015)"},{"key":"42_CR5","doi-asserted-by":"crossref","unstructured":"Carbone, M., Cui, W., Lu, L., Lee, W., Peinado, M., Jiang, X.: Mapping kernel objects to enable systematic integrity checking. In: CCS, pp. 555\u2013565 (2009)","DOI":"10.1145\/1653662.1653729"},{"key":"42_CR6","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Hodosh, J., Hulin, P., Leek, T., Whelan, R.: Repeatable reverse engineering with panda. In: Proceedings of 5th Program Protection and Reverse Engineering Workshop, pp. 4:1\u20134:11 (2015)","DOI":"10.1145\/2843859.2843867"},{"key":"42_CR7","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Hodosh, J., Lee, W.: Tappan zee (north) bridge: mining memory accesses for introspection. In: CCS, pp. 839\u2013850 (2013)","DOI":"10.1145\/2508859.2516697"},{"key":"42_CR8","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: NDSS, pp. 191\u2013206 (2003)"},{"key":"42_CR9","doi-asserted-by":"crossref","unstructured":"Jain, B., Baig, M.B., Zhang, D., Porter, D.E., Sion, R.: SoK: introspections on trust and the semantic gap. In: Proceedings of 35th IEEE S&P, pp. 605\u2013620 (2014)","DOI":"10.1109\/SP.2014.45"},{"key":"42_CR10","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection through VMM-based out-of-the-box semantic view reconstruction. In: CCS, pp. 128\u2013138 (2007)","DOI":"10.1145\/1315245.1315262"},{"key":"42_CR11","unstructured":"Lanzi, A., Sharif, M., Lee, W.: K-tracer: a system for extracting kernel malware behavior. In: NDSS (2009)"},{"key":"42_CR12","unstructured":"Lee, K., Zhang, X., Xu, D.: High accuracy attack provenance via binary-based execution partition. In: NDSS (2013)"},{"key":"42_CR13","doi-asserted-by":"crossref","unstructured":"Lee, K., Zhang, X., Xu, D.: LogGC: garbage collecting audit log. In: CCS, pp. 1005\u20131016 (2013)","DOI":"10.1145\/2508859.2516731"},{"key":"42_CR14","doi-asserted-by":"crossref","unstructured":"Li, J., Wang, Z., Jiang, X., Grace, M., Bahram, S.: Defeating return-oriented rootkits with \u201creturn-less\u201d kernels. In: EuroSys, pp. 195\u2013208 (2010)","DOI":"10.1145\/1755913.1755934"},{"key":"42_CR15","unstructured":"Liangnd, Z., Yin, H., Song, D.: HookFinder: identifying and understanding malware hooking behaviors. In: NDSS, pp. 41\u201357 (2008)"},{"key":"42_CR16","doi-asserted-by":"crossref","unstructured":"Ma, S., Zhang, X., Xu, D.: ProTracer: towards practical provenance tracing by alternating between logging and tainting. In: NDSS (2016)","DOI":"10.14722\/ndss.2016.23350"},{"key":"42_CR17","doi-asserted-by":"crossref","unstructured":"Pei, K., Gu, Z., Saltaformaggio, B., Ma, S., Wang, F., Zhang, Z., Si, L., Zhang, X., Xu, D.: HERCULE: attack story reconstruction via community discovery on correlated log graph. In: ACSAC, pp. 583\u2013595 (2016)","DOI":"10.1145\/2991079.2991122"},{"key":"42_CR18","doi-asserted-by":"crossref","unstructured":"Pohly, D., McLaughlin, S., McDaniel, P., Butler, K.: Hi-Fi: collecting high-fidelity whole-system provenance. In: ACSAC, pp. 259\u2013268 (2012)","DOI":"10.1145\/2420950.2420989"},{"key":"42_CR19","first-page":"178","volume-title":"Lecture Notes in Computer Science","author":"Junghwan Rhee","year":"2010","unstructured":"Rhee, J., Xu, D., Riley, R., Jiang, X.: Kernel malware analysis with un-tampered and temporal views of dynamic kernel memory. In: RAID, pp. 178\u2013197 (2010)"},{"key":"42_CR20","doi-asserted-by":"crossref","unstructured":"Rhee, J., Riley, R., Xu, D., Jiang, X.: Defeating dynamic data kernel rootkit attacks via VMM-based guest-transparent monitoring. In: 2009 International Conference on Availability, Reliability and Security, pp. 74\u201381 (2009)","DOI":"10.1109\/ARES.2009.116"},{"key":"42_CR21","doi-asserted-by":"crossref","unstructured":"Riley, R., Jiang, X., Xu, D.: Guest-transparent prevention of kernel rootkits with VMM-based memory shadowing. In: RAID, pp. 1\u201320 (2008)","DOI":"10.1007\/978-3-540-87403-4_1"},{"key":"42_CR22","doi-asserted-by":"crossref","unstructured":"Riley, R., Jiang, X., Xu, D.: Multi-aspect profiling of kernel rootkit behavior. In: EuroSys, pp. 47\u201360 (2009)","DOI":"10.1145\/1519065.1519072"},{"issue":"99","key":"42_CR23","first-page":"1","volume":"PP","author":"E Rudd","year":"2016","unstructured":"Rudd, E., Rozsa, A., Gunther, M., Boult, T.: A survey of stealth malware: attacks, mitigation measures, and steps toward autonomous open world solutions. IEEE Commun. Surv. Tutor. PP(99), 1\u201328 (2016)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"42_CR24","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X., Cui, W., Wang, X.: Countering persistent kernel rootkits through systematic hook discovery. In: RAID, pp. 21\u201338 (2008)","DOI":"10.1007\/978-3-540-87403-4_2"},{"key":"42_CR25","doi-asserted-by":"crossref","unstructured":"Xu, Z., Wu, Z., Li, Z., Jee, K., Rhee, J., Xiao, X., Xu, F., Wang, H., Jiang, G.: High fidelity data reduction for big data security dependency analyses. In: CCS, pp. 504\u2013516 (2016)","DOI":"10.1145\/2976749.2978378"},{"key":"42_CR26","first-page":"304","volume-title":"Lecture Notes in Computer Science","author":"Chaoting Xuan","year":"2009","unstructured":"Xuan, C., Copeland, J., Beyah, R.: Toward revealing kernel malware behavior in virtual execution environments. In: RAID, pp. 304\u2013325 (2009)"},{"key":"42_CR27","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1007\/978-3-319-45719-2_3","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"Junyuan Zeng","year":"2016","unstructured":"Zeng, J., Fu, Y., Lin, Z.: Automatic uncovering of tap points from kernel executions. In: RAID, pp. 49\u201370 (2016)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78813-5_42","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,14]],"date-time":"2019-10-14T17:57:53Z","timestamp":1571075873000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-78813-5_42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319788128","9783319788135"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78813-5_42","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}