{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,8]],"date-time":"2025-02-08T20:40:02Z","timestamp":1739047202378,"version":"3.37.0"},"publisher-location":"Berlin, Heidelberg","reference-count":22,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642008429"},{"type":"electronic","value":"9783642008436"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-00843-6_7","type":"book-chapter","created":{"date-parts":[[2009,4,1]],"date-time":"2009-04-01T14:42:08Z","timestamp":1238596928000},"page":"71-82","source":"Crossref","is-referenced-by-count":1,"title":["Reconstructing a Packed DLL Binary for Static Analysis"],"prefix":"10.1007","author":[{"given":"Xianggen","family":"Wang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dengguo","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Purui","family":"Su","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"7_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"250","DOI":"10.1007\/978-3-540-31985-6_19","volume-title":"Compiler Construction","author":"G. Balakrishnan","year":"2005","unstructured":"Balakrishnan, G., Gruian, R., Reps, T., Teitelbaum, T.: CodeSurfer\/x86\u2014A platform for analyzing x86 executables. In: Bodik, R. (ed.) CC 2005. LNCS, vol.\u00a03443, pp. 250\u2013254. Springer, Heidelberg (2005)"},{"key":"7_CR2","unstructured":"Christodorescu, M., Jha, S.: Static Analysis of Executables to Detect Malicious Patterns. In: Usenix Security Symposium (2003)"},{"key":"7_CR3","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Jha, S., Seshia, S., Song, D., Bryant, R.: Semantics-aware Malware Detection. In: IEEE Symposium on Security and Privacy (2005)","DOI":"10.1109\/SP.2005.20"},{"key":"7_CR4","unstructured":"PEiD, http:\/\/www.secretashell.com\/codomain\/peid\/"},{"key":"7_CR5","unstructured":"Themida, http:\/\/www.oreans.com\/"},{"key":"7_CR6","unstructured":"Yoda Protector, http:\/\/sourceforge.net\/projects\/yodap\/"},{"key":"7_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/10958513_1","volume-title":"Information Security","author":"P.C. Oorschot van","year":"2003","unstructured":"van Oorschot, P.C.: Revisiting software protection. In: Boyd, C., Mao, W. (eds.) ISC 2003. LNCS, vol.\u00a02851, pp. 1\u201313. Springer, Heidelberg (2003)"},{"key":"7_CR8","unstructured":"Wang, P.: Tamper Resistance for Software Protection, Master Thesis, Information and Communications University, Korea (2005)"},{"key":"7_CR9","doi-asserted-by":"crossref","unstructured":"Kanzaki, Y., Monden, A., Nakamura, M., Matsumoto, K.: Exploiting self-modification mechanism for program protection. In: Proc. of the 27th Annual International Computer Software and Applications Conference, pp. 170\u2013181 (2003)","DOI":"10.1109\/CMPSAC.2003.1245338"},{"key":"7_CR10","doi-asserted-by":"crossref","unstructured":"Giffin, J.T., Christodorescu, M., Kruger, L.: Strengthening Software Self-Checksumming via Self-Modifying Code. In: 21st Annual Computer Security Applications Conference, pp. 23\u201332 (2005)","DOI":"10.1109\/CSAC.2005.53"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Albert, D.J., Morse, S.P.: Combating Software Piracy by Encryption and Key Management. Computer (1984)","DOI":"10.1109\/MC.1984.1659112"},{"key":"7_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"608","DOI":"10.1007\/978-3-540-30501-9_117","volume-title":"Parallel and Distributed Computing: Applications and Technologies","author":"J.-W. Lee","year":"2004","unstructured":"Lee, J.-W., Kim, H., Yoon, H.: Tamper resistant software by integrity-based encryption. In: Liew, K.-M., Shen, H., See, S., Cai, W. (eds.) PDCAT 2004. LNCS, vol.\u00a03320, pp. 608\u2013612. Springer, Heidelberg (2004)"},{"key":"7_CR13","doi-asserted-by":"crossref","unstructured":"Huang, Y.L., Ho, F.S., Tsai, H.Y., Kao, H.M.: A control flow obfuscation method to discourage malicious tampering of software codes. In: ASIACCS 2006, computer and communications security, New York, NY, USA, p. 362 (2006)","DOI":"10.1145\/1128817.1128878"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Linn, C., Debray, S.: Obfuscation of executable code to improve resistance to static disassembly. In: CCS 2003, New York, NY, USA, pp. 290\u2013299 (2003)","DOI":"10.1145\/948109.948149"},{"key":"7_CR15","unstructured":"Wroblewski, G.: General method of program code obfuscation. In: Proc. Int. Conf. on Software Engineering Research and Practice (SERP) (2002)"},{"key":"7_CR16","unstructured":"Christodorescu, M., Kinder, J., Jha, S., Katzenbeisser, S., Veith, H.: Malware normalization. Technical Report 1539, University of Wisconsin, USA (2005)"},{"key":"7_CR17","unstructured":"DataRescue SA. IDA Pro disassembler: Multi-processor, Windows hosted disassembler and debugger, http:\/\/www.datarescue.com\/idabase\/"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Royal, P., Halpin, M., Dagon, D., Edmonds, R., Lee, W.: PolyUnpack: Automating the hidden-code extraction of unpack-executing malware. In: ACSAC 2006, USA, pp. 289\u2013300 (2006)","DOI":"10.1109\/ACSAC.2006.38"},{"key":"7_CR19","doi-asserted-by":"crossref","unstructured":"Nanda, S., Li, W., Lam, L., Chiueh, T.: BIRD: Binary interpretation using runtime disassembly. In: CGO 2006, USA, pp. 358\u2013370 (2006)","DOI":"10.1109\/CGO.2006.6"},{"key":"7_CR20","doi-asserted-by":"crossref","unstructured":"Kang, M.G., Poosankam, P., Yin, H.: Renovo: A Hidden Code Extractor for Packed Executables. In: The 5th ACM Workshop on Recurring Malcode (WORM) (2007)","DOI":"10.1145\/1314389.1314399"},{"key":"7_CR21","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Exploring Multiple Execution Paths for Malware Analysis. In: SP 2007, pp. 231\u2013245 (2007)","DOI":"10.1109\/SP.2007.17"},{"key":"7_CR22","unstructured":"Bellard, F.: QEMU, a Fast and Portable Dynamic Translator. In: FREENIX Track: 2005 USENIX Annual Technical Conference (2005)"}],"container-title":["Lecture Notes in Computer Science","Information Security Practice and Experience"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-00843-6_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,8]],"date-time":"2025-02-08T20:06:08Z","timestamp":1739045168000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-00843-6_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642008429","9783642008436"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-00843-6_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2009]]}}}