{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T05:32:07Z","timestamp":1769923927410,"version":"3.49.0"},"publisher-location":"Berlin, Heidelberg","reference-count":28,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642155116","type":"print"},{"value":"9783642155123","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-15512-3_16","type":"book-chapter","created":{"date-parts":[[2010,8,31]],"date-time":"2010-08-31T12:27:39Z","timestamp":1283257659000},"page":"297-316","source":"Crossref","is-referenced-by-count":22,"title":["Live and Trustworthy Forensic Analysis of Commodity Production Systems"],"prefix":"10.1007","author":[{"given":"Lorenzo","family":"Martignoni","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aristide","family":"Fattori","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roberto","family":"Paleari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"Cavallaro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"16_CR1","volume-title":"Rootkits: Subverting the Windows Kernel","author":"G. Hoglund","year":"2005","unstructured":"Hoglund, G., Butler, J.: Rootkits: Subverting the Windows Kernel. Addison-Wesley Professional, Reading (2005)"},{"key":"16_CR2","unstructured":"Sparks, S., Butler, J.: Shadow Walker. Raising The Bar For Windows Rootkit Detection. Phrack Magazine\u00a011(63) (2005)"},{"key":"16_CR3","unstructured":"AMD, Inc.: AMD Virtualization, www.amd.com\/virtualization"},{"key":"16_CR4","unstructured":"Intel Corporation: Intel Virtualization Technology, http:\/\/www.intel.com\/technology\/virtualization\/"},{"key":"16_CR5","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: Malware Analysis via Hardware Virtualization Extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"16_CR6","volume-title":"Proceedings of the Network and Distributed Systems Security Symposium","author":"T. Garfinkel","year":"2003","unstructured":"Garfinkel, T., Rosenblum, M.: A Virtual Machine Introspection Based Architecture for Intrusion Detection. In: Proceedings of the Network and Distributed Systems Security Symposium. The Internet Society, San Diego (2003)"},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: An Architecture for Secure Active Monitoring Using Virtualization. In: Proceedings of the IEEE Symposium on Security and Privacy (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"16_CR8","doi-asserted-by":"crossref","unstructured":"Riley, R., Jiang, X., Xu, D.: Guest-Transparent Prevention of Kernel Rootkits with VMM-Based Memory Shadowing. In: Proceedings of the 11th International Symposium on Recent Advances in Intrusion Detection (2008)","DOI":"10.1007\/978-3-540-87403-4_1"},{"key":"16_CR9","volume-title":"Proccedings of the ACM Symposium on Operating Systems Principles","author":"A. Seshadri","year":"2007","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: SecVisor: A Tiny Hypervisor to Provide Lifetime Kernel Code Integrity for Commodity OSes. In: Proccedings of the ACM Symposium on Operating Systems Principles. ACM, New York (2007)"},{"key":"16_CR10","unstructured":"Rutkowska, J.: Subverting Vista Kernel For Fun And Profit. Black Hat USA (2006)"},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"McCune, J.M., Parno, B., Perrig, A., Reiter, M.K., Isozaki, H.: Flicker: An execution infrastructure for tcb minimization. In: Proceedings of the ACM European Conference in Computer Systems (2008)","DOI":"10.1145\/1352592.1352625"},{"key":"16_CR12","doi-asserted-by":"crossref","unstructured":"Seshadri, A., Luk, M., Shi, E., Perrig, A., van Doorn, L., Khosla, P.: Pioneer: Verifying integrity and guaranteeing execution of code on legacy platforms. In: Proceedings of ACM Symposium on Operating Systems Principles (2005)","DOI":"10.1145\/1095810.1095812"},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Seshadri, A., Perrig, A., van Doorn, L., Khosla, P.: Swatt: Software-based attestation for embedded devices. In: Proceedings of the IEEE Symposium on Security and Privacy (2004)","DOI":"10.1109\/SECPRI.2004.1301329"},{"key":"16_CR14","series-title":"Lecture Notes in Computer Science","volume-title":"Proceedings of the Conference on Detection of Intrusions and Malware and Vulnerability Assessment","author":"L. Martignoni","year":"2010","unstructured":"Martignoni, L., Paleari, R., Bruschi, D.: Conqueror: tamper-proof code execution on legacy systems. In: Proceedings of the Conference on Detection of Intrusions and Malware and Vulnerability Assessment. LNCS. Springer, Heidelberg (2010)"},{"key":"16_CR15","volume-title":"Dynamics of a Trusted Platform: A Building Block Approach","author":"D. Grawrock","year":"2009","unstructured":"Grawrock, D.: Dynamics of a Trusted Platform: A Building Block Approach. Intel Press, Hillsboro (2009)"},{"key":"16_CR16","doi-asserted-by":"crossref","unstructured":"Carbone, M., Zamboni, D., Lee, W.: Taming virtualization. IEEE Security and Privacy\u00a06(1) (2008)","DOI":"10.1109\/MSP.2008.24"},{"key":"16_CR17","volume-title":"Virtual Machines: Versatile Platforms for Systems and Processes","author":"J.E. Smith","year":"2005","unstructured":"Smith, J.E., Nair, R.: Virtual Machines: Versatile Platforms for Systems and Processes. Morgan Kaufmann, San Francisco (2005)"},{"key":"16_CR18","unstructured":"Volatile Systems LLC: Volatility, http:\/\/www.volatilesystems.com\/"},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Forrest, S., Hofmeyr, S.R., Somayaji, A., Longstaff, T.A.: A Sense of Self for Unix Processes. In: Proceedings of the IEEE Symposium on Security and Privacy (1996)","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"16_CR20","unstructured":"Butler, J., Silberman, P.: RAIDE: Rookit analysis identification elimination. In: Black Hat USA (2006)"},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Franklin, J., Seshadri, A., Qu, N., Datta, A., Chaki, S.: Attacking, Repairing, and Verifying SecVisor: A Retrospective on the Security of a Hypervisor. Technical Report, Carnegie Mellon University (2008)","DOI":"10.1145\/1294261.1294294"},{"key":"16_CR22","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X.: \u201cout-of-the-box\u201d monitoring of VM-based high-interaction honeypots. In: Proceedings of the International Symposium on Recent Advances in Intrusion Detection (2007)","DOI":"10.1007\/978-3-540-74320-0_11"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Sharif, M., Lee, W., Cui, W., Lanzi, A.: Secure In-VM Monitoring Using Hardware Virtualization. In: Proceedings of the ACM Conference on Computer and Communications Security (2009)","DOI":"10.1145\/1653662.1653720"},{"key":"16_CR24","doi-asserted-by":"crossref","unstructured":"Chen, X., Garfinkel, T., Lewis, E.C., Subrahmanyam, P., Waldspurger, C.A., Boneh, D., Dwoskin, J., Ports, D.R.K.: Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems. Operating Systems Review\u00a042(2) (2008)","DOI":"10.1145\/1353535.1346284"},{"key":"16_CR25","unstructured":"Perrig, A., Gligor, V., Vasudevan, A.: XTREC: secure real-time execution trace recording and analysis on commodity platforms. Technical Report, Carnegie Mellon University (2010)"},{"key":"16_CR26","unstructured":"Sahita, R., Warrier, U., Dewan, P.: Dynamic software application protection. Technical Report, Intel Corporation (2009)"},{"key":"16_CR27","unstructured":"Fattori, A., Paleari, R., Martignoni, L., Monga, M.: HyperDbg: a fully transparent kernel-level debugger, http:\/\/code.google.com\/p\/hyperdbg\/"},{"key":"16_CR28","doi-asserted-by":"crossref","unstructured":"King, S.T., Chen, P.M., Wang, Y.M., Verbowski, C., Wang, H.J., Lorch, J.R.: SubVirt: Implementing malware with virtual machines. In: Proceedings of IEEE Symposium on Security and Privacy (2006)","DOI":"10.1109\/SP.2006.38"}],"container-title":["Lecture Notes in Computer Science","Recent Advances in Intrusion Detection"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-15512-3_16.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,24]],"date-time":"2020-11-24T03:09:18Z","timestamp":1606187358000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-15512-3_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642155116","9783642155123"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-15512-3_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}