{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T06:10:47Z","timestamp":1725516647227},"publisher-location":"Berlin, Heidelberg","reference-count":38,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540705413"},{"type":"electronic","value":"9783540705420"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-70542-0_4","type":"book-chapter","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T16:07:43Z","timestamp":1218557263000},"page":"64-87","source":"Crossref","is-referenced-by-count":14,"title":["Dynamic Binary Instrumentation-Based Framework for Malware Defense"],"prefix":"10.1007","author":[{"given":"Najwa","family":"Aaraj","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anand","family":"Raghunathan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niraj K.","family":"Jha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"Computer Security Institute, CSI Survey 2007 (2007), http:\/\/www.gocsi.com","key":"4_CR1"},{"unstructured":"Virus Bulletin (2007), http:\/\/www.virusbtn.com\/news\/2007","key":"4_CR2"},{"unstructured":"Symantec Security Response (2007), http:\/\/www.symantec.com","key":"4_CR3"},{"unstructured":"The difference between a virus, worm and trojan horse (2004), http:\/\/www.webopedia.com\/DidYouKnow\/Internet\/2004\/virus.asp","key":"4_CR4"},{"key":"4_CR5","volume-title":"The Art of Computer Virus Research and Defense","author":"P. Szor","year":"2005","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Addison-Wesley Professional, Reading (2005)"},{"unstructured":"Norman SandBox Pro-active virus protection (2004), http:\/\/lan-aces.com\/Norman_Sandbox.pdf","key":"4_CR6"},{"unstructured":"Gordon, S., Howard, F.: Antivirus software testing for the new millenium. In: Proc. National Information Systems Security Conf., pp. 125\u2013139 (October 2000)","key":"4_CR7"},{"unstructured":"Westcoast labs: Checkmark certification (2007), http:\/\/www.westcoastlabs.com\/checkmark","key":"4_CR8"},{"doi-asserted-by":"crossref","unstructured":"Zhou, Q.: A service-oriented solution framework for distributed virus detection and vulnerability remediation (VDVR) system. In: Proc. Int. Cryptology Conf. Services Computing, pp. 569\u2013573 (July 2007)","key":"4_CR9","DOI":"10.1109\/SCC.2007.18"},{"doi-asserted-by":"crossref","unstructured":"Shin-Jia, H., Kuang-Hsi, C.: A proxy automatic signature scheme using a compiler in distributed systems for unknown virus detection. In: Proc. Int. Conf. Advanced Information Networking and Applications, pp. 649\u2013654 (March 2005)","key":"4_CR10","DOI":"10.1109\/AINA.2005.53"},{"unstructured":"Yoo, I., Ultes-Nitsche, U.: Adaptive detection of worms\/viruses in firewalls. In: Proc. Int. Conf. Security Technology (October 2004)","key":"4_CR11"},{"doi-asserted-by":"crossref","unstructured":"Henchiri, O., Japkowicz, N.: A feature selection and evaluation scheme for computer virus detection. In: Proc. Int. Conf. Data Mining, pp. 891\u2013895 (December 2006)","key":"4_CR12","DOI":"10.1109\/ICDM.2006.4"},{"doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D., Egele, M., Kruegel, C., Kirda, E.: Panorama: Capturing system-wide information flow for malware detection and analysis. In: Proc. ACM Conf. Computer and Communication Security, pp. 116\u2013127 (October 2007)","key":"4_CR13","DOI":"10.1145\/1315245.1315261"},{"doi-asserted-by":"crossref","unstructured":"Rozinov, K.: Reverse code engineering: An in-depth analysis of the Bagle virus. In: Proc. Wkshp. Information Assurance and Security, pp. 380\u2013387 (June 2005)","key":"4_CR14","DOI":"10.1109\/IAW.2005.1495977"},{"doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S.A., Song, D., Bryant, R.E.: Semantics-aware malware detection. In: Proc. IEEE Symp. Security and Privacy, pp. 32\u201346 (May 2005)","key":"4_CR15","DOI":"10.1109\/SP.2005.20"},{"doi-asserted-by":"crossref","unstructured":"Preda, M.D., Christodorescu, M., Jha, S., Debray, S.: A semantics-based approach to malware detection. In: Proc. Conf. Principles of Programming Languages, pp. 377\u2013388 (January 2007)","key":"4_CR16","DOI":"10.1145\/1190216.1190270"},{"doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Exploring multiple execution paths for malware analysis. In: Proc. IEEE Symp. Security and Privacy, pp. 231\u2013245 (May 2007)","key":"4_CR17","DOI":"10.1109\/SP.2007.17"},{"unstructured":"Goldberg, I., Wagner, D., Thomas, R., Brewer, E.A.: A secure environment for untrusted helper applications confining the wily hacker. In: Proc. Conf. USENIX Security Symp., pp. 1\u201313 (July 1996)","key":"4_CR18"},{"unstructured":"Peterson, D.S., Bishop, M., Pandey, R.: A flexible containment mechanism for executing untrusted code. In: Proc. Conf. USENIX Security Symp., pp. 207\u2013225 (August 2002)","key":"4_CR19"},{"unstructured":"Lam, L.-C., Yu, Y., Chiueh, T.-C.: Secure mobile code execution service. In: Proc. Conf. Large Installation System Administration, pp. 53\u201362 (December 2006)","key":"4_CR20"},{"unstructured":"VMWare\u00a0Inc., Palo\u00a0Alto, VMWare browser appliance (2006), http:\/\/www.vmware.com\/appliances\/directory\/browserapp.html","key":"4_CR21"},{"key":"4_CR22","volume-title":"Virtual Honeypots: From Botnet Tracking to Intrusion Detection","author":"N. Provos","year":"2007","unstructured":"Provos, N., Holz, T.: Virtual Honeypots: From Botnet Tracking to Intrusion Detection. Addison-Wesley, Reading (2007)"},{"unstructured":"Intel vPro Processor Technology (2007), http:\/\/www.intel.com\/business\/vpro","key":"4_CR23"},{"unstructured":"Aaraj, N., Raghunathan, A., Jha, N.K.: Virtualization-assisted framework for prevention of software vulnerability based security attacks. Tech. Rep. CE-J07-001, Dept. of Electrical Engineering, Princeton University (December 2007)","key":"4_CR24"},{"doi-asserted-by":"crossref","unstructured":"Luk, C.-K., Cohn, R., Muth, R., Patil, H., Klauser, A., Lowney, G., Wallace, S., Reddi, V.J., Hazelwood, K.: Pin: Building customized program analysis tools with dynamic instrumentation. In: Proc. Programming Language Design and Implementation Forum, pp. 190\u2013200 (June 2005)","key":"4_CR25","DOI":"10.1145\/1065010.1065034"},{"doi-asserted-by":"crossref","unstructured":"Hangal, S., Lam, M.S.: Tracking down software bugs using automatic anomaly detection. In: Proc. Int. Conf. Software Engineering, pp. 291\u2013301 (May 2002)","key":"4_CR26","DOI":"10.1145\/581376.581377"},{"doi-asserted-by":"crossref","unstructured":"Ernst, M.D., Cockrell, J., Griswold, W.G., Notkin, D.: Dynamically discovering likely program invariants to support program evolution. In: Proc. Int. Conf. Software Engineering, pp. 213\u2013224 (May 1999)","key":"4_CR27","DOI":"10.1145\/302405.302467"},{"unstructured":"Symantec\u00a0corporation, Cupertino, The digital immune system (2007), http:\/\/www.symantec.com\/avcenter\/reference\/dis.tech.brief.pdf","key":"4_CR28"},{"unstructured":"STP: A decision procedure for bitvectors and arrays (2007), http:\/\/theory.stanford.edu\/~vganesh\/stp.html","key":"4_CR29"},{"doi-asserted-by":"crossref","unstructured":"Cadar, C., Ganesh, V., Pawlowski, P.M., Dill, D.L., Engler, D.R.: EXE: Automatically generating inputs of death. In: Proc. ACM Conf. Computer and Communications Security, pp. 322\u2013335 (November 2006)","key":"4_CR30","DOI":"10.1145\/1180405.1180445"},{"unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., Yin, H.: Automatically identifying trigger-based behavior in malware (2007), http:\/\/bitblaze.cs.berkeley.edu\/papers\/botnet_book-2007.pdf","key":"4_CR31"},{"unstructured":"XenSource: Delivering the Power of Xen (2007), http:\/\/www.xensource.com","key":"4_CR32"},{"unstructured":"VMWare\u00a0Inc., Palo\u00a0Alto, Virtual Appliance Marketplace (2007), http:\/\/www.vmware.com\/appliances","key":"4_CR33"},{"unstructured":"VX Heavens (2007), http:\/\/vx.netlux.org","key":"4_CR34"},{"unstructured":"Computer Virus Codes (2007), http:\/\/virus-codes.blogspot.com","key":"4_CR35"},{"unstructured":"ELFCrypt (2005), http:\/\/www.infogreg.com\/source-code\/public-domain\/elfcrypt-v1.0.html","key":"4_CR36"},{"unstructured":"UPX: the Ultimate Packer for eXecutables (2007), http:\/\/upx.sourceforge.net","key":"4_CR37"},{"unstructured":"Obfuscator download (2006), http:\/\/www.soft32.com\/download_186322.html","key":"4_CR38"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-70542-0_4.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,19]],"date-time":"2020-11-19T05:07:33Z","timestamp":1605762453000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-70542-0_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540705413","9783540705420"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-70542-0_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[]}}