{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,21]],"date-time":"2026-03-21T17:56:23Z","timestamp":1774115783719,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":34,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540754954","type":"print"},{"value":"9783540754961","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-75496-1_1","type":"book-chapter","created":{"date-parts":[[2007,9,18]],"date-time":"2007-09-18T07:29:35Z","timestamp":1190100575000},"page":"1-18","source":"Crossref","is-referenced-by-count":70,"title":["Detecting System Emulators"],"prefix":"10.1007","author":[{"given":"Thomas","family":"Raffetseder","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"1_CR1","unstructured":"VMware Inc. (2006), http:\/\/www.vmware.com\/"},{"key":"1_CR2","unstructured":"Robin, J.S., Irvine, C.E.: Analysis of the Intel Pentium\u2019s Ability to Support a Secure Virtual Machine Monitor. In: Proceedings of the 9th USENIX Security Symposium, Denver, Colorado, USA (August 14\u201317, 2000)"},{"key":"1_CR3","unstructured":"Rutkowska, J.: Red Pill... or how to detect VMM using (almost) one CPU instruction (2004), http:\/\/invisiblethings.org\/papers\/redpill.html"},{"key":"1_CR4","doi-asserted-by":"crossref","unstructured":"Classified by Symantec Corporation: W32.Toxbot.C (2007), http:\/\/www.symantec.com\/security_response\/writeup.jsp?docid=2005-063015-3130-99&tabid=2","DOI":"10.1016\/S1353-4858(05)70263-4"},{"key":"1_CR5","volume-title":"IEEE Symposium on Security and Privacy","author":"A. Vasudevan","year":"2006","unstructured":"Vasudevan, A., Yerraballi, R.: Cobra: Fine-grained Malware Analysis using Stealth Localized-Executions. In: IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Los Alamitos (2006)"},{"key":"1_CR6","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: A Tool for Analyzing Malware. In: EICAR. 15th Annual Conference of the European Institute for Computer Antivirus Research (2006)"},{"key":"1_CR7","unstructured":"Qemu - open source processor emulator (2006), http:\/\/fabrice.bellard.free.fr\/qemu\/"},{"issue":"7","key":"1_CR8","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1145\/361011.361073","volume":"17","author":"G.J. Popek","year":"1974","unstructured":"Popek, G.J., Goldberg, R.P.: Formal requirements for virtualizable third generation architectures. Communications of the ACM\u00a017(7), 412\u2013421 (1974)","journal-title":"Communications of the ACM"},{"key":"1_CR9","unstructured":"Intel Corporation: Intel 64 and IA-32 Architectures Software Developer\u2019s Manual vol. 3A: System Programming Guide, Part 1 (2006)"},{"key":"1_CR10","doi-asserted-by":"crossref","unstructured":"May, C.: Mimic: a fast system\/370 simulator. In: Conference on Programming Language Design and Implementation - Papers of the Symposium on Interpreters and interpretive techniques (1987)","DOI":"10.1145\/29650.29651"},{"key":"1_CR11","unstructured":"Bellard, F.: Qemu, a Fast and Portable Dynamic Translator. In: USENIX 2005 Annual Technical Conference, FREENIX (2005)"},{"key":"1_CR12","unstructured":"Bellard, F.: Qemu Accelerator Module (2006), http:\/\/fabrice.bellard.free.fr\/qemu\/qemu-accel.html"},{"key":"1_CR13","unstructured":"Intel Corporation: Intel 64 and IA-32 Architectures Software Developer\u2019s Manual vol. 1: Basic Architecture (2006)"},{"key":"1_CR14","unstructured":"Intel Corporation: Intel 64 and IA-32 Architectures Software Developer\u2019s Manual vol. 2B: Instruction Set Reference, N-Z (2006)"},{"key":"1_CR15","unstructured":"Intel Corporation: Intel 64 and IA-32 Architectures Software Developer\u2019s Manual vol. 3B: System Programming Guide, Part 2 (2006)"},{"key":"1_CR16","unstructured":"Lang, J.: Personal Correspondence (2006)"},{"key":"1_CR17","unstructured":"Intel Corporation: Intel Pentium 4 Processor - Specification Update (2006)"},{"key":"1_CR18","unstructured":"Intel Corporation: Intel 64 and IA-32 Architectures Software Developer\u2019s Manual vol. 2A: Instruction Set Reference, A-M (2006)"},{"key":"1_CR19","unstructured":"VirtualPC 2004 (build 528) detection (?) (2006), http:\/\/www.securityfocus.com\/archive\/1\/445189"},{"key":"1_CR20","unstructured":"Intel Corporation: Using the RDTSC Instruction for Performance Monitoring (1997)"},{"key":"1_CR21","unstructured":"Intel Corporation: Intel Virtualization Technology Specification for the IA-32 Intel Architecture (2005)"},{"key":"1_CR22","unstructured":"Advanced Micro Devices, Inc.: AMD64 Architecture Programmer\u2019s Manual vol. 2: System Programming (2006)"},{"key":"1_CR23","unstructured":"Advanced Micro Devices, Inc.: AMD I\/O Virtualization Technology (IOMMU) Specification (2006)"},{"key":"1_CR24","unstructured":"Rutkowska, J.: Introducing Blue Pill (2006), http:\/\/theinvisiblethings.blogspot.com\/2006\/06\/introducing-blue-pill.html"},{"key":"1_CR25","unstructured":"Zovi, D.D.: Hardware Virtualization Rootkits. In: BlackHat Briefings, USA (2006)"},{"key":"1_CR26","volume-title":"IEEE Symposium on Security and Privacy","author":"S.T. King","year":"2006","unstructured":"King, S.T., Chen, P.M., Wang, Y.M., Verbowski, C., Wang, H.J., Lorch, J.R.: SubVirt: Implementing malware with virtual machines. In: IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Los Alamitos (2006)"},{"key":"1_CR27","unstructured":"KVM: Kernel-based Virtual Machine (2007), http:\/\/kvm.sourceforge.net\/"},{"key":"1_CR28","unstructured":"Christodorescu, M., Jha, S.: Static Analysis of Executables to Detect Malicious Patterns. In: Usenix Security Symposium (2003)"},{"key":"1_CR29","volume-title":"IEEE Symposium on Security and Privacy","author":"M. Christodorescu","year":"2005","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.: Semantics-aware Malware Detection. In: IEEE Symposium on Security and Privacy, IEEE Computer Society Press, Los Alamitos (2005)"},{"key":"1_CR30","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Computer Systems Architecture","author":"C. Kruegel","year":"2004","unstructured":"Kruegel, C., Robertson, W., Vigna, G.: Detecting Kernel-Level Rootkits Through Binary Analysis. In: Yew, P.-C., Xue, J. (eds.) ACSAC 2004. LNCS, vol.\u00a03189, Springer, Heidelberg (2004)"},{"key":"1_CR31","unstructured":"Klein, T.: Scooby Doo - VMware Fingerprint Suite (2006), http:\/\/www.trapkit.de\/research\/vmm\/scoopydoo\/index.html"},{"key":"1_CR32","unstructured":"Garfinkel, T., Adams, K., Warfield, A., Franklin, J.: Compatibility is Not Transparency: VMM Detection Myths and Realities. In: Proceedings of the 11th Workshop on Hot Topics in Operating Systems (HotOS-XI) (May 2007)"},{"key":"1_CR33","doi-asserted-by":"crossref","unstructured":"Franklin, J., Luk, M., McCune, J.M., Seshadri, A., Perrig, A., van Doorn, L.: Remote Detection of Virtual Machine Monitors with Fuzzy Benchmarking. Carnegie Mellon CyLab (2007)","DOI":"10.1145\/1368506.1368518"},{"key":"1_CR34","unstructured":"Ferrie, P.: Attacks on Virtual Machine Emulators. In: AVAR Conference, Auckland, Symantec Advanced Threat Research (2006)"}],"container-title":["Lecture Notes in Computer Science","Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-75496-1_1.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T10:21:58Z","timestamp":1619518918000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-75496-1_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540754954","9783540754961"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-75496-1_1","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[]}}