{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T21:29:43Z","timestamp":1743110983854,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":31,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642193477"},{"type":"electronic","value":"9783642193484"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-19348-4_18","type":"book-chapter","created":{"date-parts":[[2011,2,11]],"date-time":"2011-02-11T10:50:20Z","timestamp":1297421420000},"page":"244-258","source":"Crossref","is-referenced-by-count":5,"title":["Some Ideas on Virtualized System Security, and Monitors"],"prefix":"10.1007","author":[{"given":"Hedi","family":"Benzina","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean","family":"Goubault-Larrecq","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"18_CR1","unstructured":"Briffaut, J.: Formalisation et garantie de propri\u00e9t\u00e9s de s\u00e9curit\u00e9 syst\u00e8me: Application \u00e0 la d\u00e9tection dintrusions. PhD thesis, LIFO Universit\u00e9 d\u2019Orl\u00e9ans, ENSI Bourges (December 2007)"},{"key":"18_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/978-3-540-79104-1_17","volume-title":"Information Security Practice and Experience","author":"A. Brown","year":"2008","unstructured":"Brown, A., Ryan, M.: Synthesising monitors from high-level policies for the safe execution of untrusted software. In: Chen, L., Mu, Y., Susilo, W. (eds.) ISPEC 2008. LNCS, vol.\u00a04991, pp. 233\u2013247. Springer, Heidelberg (2008)"},{"key":"18_CR3","unstructured":"Dias, H.: Linux kernel \u2019net\/atm\/proc.c\u2019 local denial of service vulnerability. BugTraq Id 32676, CVE-2008-5079 (December 2008)"},{"key":"18_CR4","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1016\/0022-0000(79)90046-1","volume":"18","author":"M.J. Fischer","year":"1979","unstructured":"Fischer, M.J., Ladner, R.E.: Propositional dynamic logic of regular programs. Journal of Computer and System Sciences\u00a018, 194\u2013211 (1979)","journal-title":"Journal of Computer and System Sciences"},{"key":"18_CR5","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: Proceedings of the 10th Annual Network and Distributed Systems Security Symposium, San Diego, CA (February 2003)"},{"key":"18_CR6","unstructured":"Goldberg, I., Wagner, D., Thomas, R., Brewer, E.A.: A secure environment for untrusted helper applications (confining the wily hacker). In: Proceedings of the 6th USENIX Security Symposium, San Jose, CA (July 1996)"},{"key":"18_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-89247-2_1","volume-title":"Runtime Verification","author":"J. Goubault-Larrecq","year":"2008","unstructured":"Goubault-Larrecq, J., Olivain, J.: A smell of orchids. In: Leucker, M. (ed.) RV 2008. LNCS, vol.\u00a05289, pp. 1\u201320. Springer, Heidelberg (2008)"},{"key":"18_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1007\/978-3-540-45248-5_6","volume-title":"Recent Advances in Intrusion Detection","author":"B. Morin","year":"2003","unstructured":"Morin, B., Debar, H.: Correlation of intrusion symptoms: an application of chronicles. In: Vigna, G., Kr\u00fcgel, C., Jonsson, E. (eds.) RAID 2003. LNCS, vol.\u00a02820, pp. 94\u2013112. Springer, Heidelberg (2003)"},{"key":"18_CR9","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1145\/248155.238781","volume":"30","author":"G.C. Necula","year":"1996","unstructured":"Necula, G.C., Lee, P.: Safe kernel extensions without run-time checking. SIGOPS Operating Systems Review\u00a030, 229\u2013243 (1996)","journal-title":"SIGOPS Operating Systems Review"},{"key":"18_CR10","unstructured":"NetTop (2004), http:\/\/www.nsa.gov\/research\/tech_transfer\/fact_sheets\/nettop.shtml"},{"key":"18_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"286","DOI":"10.1007\/11513988_28","volume-title":"Computer Aided Verification","author":"J. Olivain","year":"2005","unstructured":"Olivain, J., Goubault-Larrecq, J.: The orchids intrusion detection tool. In: Etessami, K., Rajamani, S.K. (eds.) CAV 2005. LNCS, vol.\u00a03576, pp. 286\u2013290. Springer, Heidelberg (2005)"},{"key":"18_CR12","doi-asserted-by":"crossref","unstructured":"Onoue, K., Oyama, Y., Yonezawa, A.: Control of system calls from outside of virtual machines. In: Wainwright, R.L., Haddad, H. (eds.) SAC, pp. 2116\u20131221. ACM, New York (2008)","DOI":"10.1145\/1363686.1364196"},{"key":"18_CR13","unstructured":"Provos, N.: Improving host security with system call policies. In: Proceedings of the 12th USENIX Security Symposium, Washington, DC (August 2003)"},{"key":"18_CR14","unstructured":"Purczy\u0144ski, W., qaaz: Linux kernel prior to 2.6.24.2 \u2018vmsplice_to_pipe()\u2019 local privilege escalation vulnerability (February 2008), http:\/\/www.securityfocus.com\/bid\/27801"},{"key":"18_CR15","unstructured":"Qemu (2010), http:\/\/www.qemu.org\/"},{"key":"18_CR16","unstructured":"Small number of video iPods shipped with Windows virus (2010), http:\/\/www.apple.com\/support\/windowsvirus\/"},{"key":"18_CR17","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1109\/CSFW.2001.930148","volume-title":"14th IEEE Computer Security Foundations Workshop (CSFW 2001)","author":"M. Roger","year":"2001","unstructured":"Roger, M., Goubault-Larrecq, J.: Log auditing through model checking. In: 14th IEEE Computer Security Foundations Workshop (CSFW 2001), pp. 220\u2013236. IEEE Comp. Soc. Press, Los Alamitos (2001)"},{"key":"18_CR18","unstructured":"Sailer, R., Jaeger, T., Valdez, E., Caceres, R., Perez, R., Berger, S., Griffin, J., Doorn, L.: Building a MAC-based security architecture for the Xen opensource hypervisor. In: Proceedings of the 21st Annual Computer Security Applications Conference, Tucson, AZ (December 2005)"},{"key":"18_CR19","unstructured":"Sekar, R., Bendre, M., Bollineni, P., Dhurjati, D.: A fast automaton-based\u00a0method for detecting anomalous program behaviors. In: IEEE Symposium on Security and Privacy, Oakland, CA (May 2001)"},{"key":"18_CR20","volume-title":"Proceedings of the New Security Paradigms Workshop (NSPW 2001)","author":"R. Sekar","year":"2001","unstructured":"Sekar, R., Ramakrishnan, C., Ramakrishnan, I., Smolka, S.: Model-carrying code (MCC): A new paradigm for mobile-code security. In: Proceedings of the New Security Paradigms Workshop (NSPW 2001). ACM Press, Cloudcroft (September 2001)"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Sekar, R., Uppuluri, P.: Synthesizing fast intrusion prevention\/detection systems from high-level specifications. In: Proceedings of the 8th Conference on USENIX Security Symposium, SSYM 1999, Berkeley, CA (1999)","DOI":"10.1145\/319709.319712"},{"key":"18_CR22","unstructured":"Smalley, S., Vance, C., Salamon, W.: Implementing SELinux as a Linux security module. Technical report, NSA (2001)"},{"key":"18_CR23","unstructured":"Starzetz, P.: Linux kernel 2.4.22 do_brk() privilege escalation vulnerability. K-Otik ID 0446, CVE CAN-2003-0961 (December 2003), http:\/\/www.k-otik.net\/bugtraq\/12.02.kernel.2422.php"},{"key":"18_CR24","unstructured":"Virtualbox (2010), http:\/\/www.virtualbox.org\/"},{"key":"18_CR25","unstructured":"Vmware (2010), http:\/\/www.vmware.com\/"},{"key":"18_CR26","unstructured":"Wojtczuk, R.: Subverting the Xen hypervisor. In: Black Hat 2008, Las Vegas, NV (2008)"},{"key":"18_CR27","unstructured":"[ms-wusp]: Windows update services: Client-server protocol specification (2007-2010), http:\/\/msdn.microsoft.com\/en-us\/library\/cc251937PROT.13.aspx"},{"key":"18_CR28","unstructured":"Xen (2005-2010), http:\/\/www.xen.org\/"},{"key":"18_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/3-540-36084-0_16","volume-title":"Recent Advances in Intrusion Detection","author":"J. Zimmermann","year":"2002","unstructured":"Zimmermann, J., M\u00e9, L., Bidan, C.: Introducing reference flow control for detecting intrusion symptoms at the OS level. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, pp. 292\u2013306. Springer, Heidelberg (2002)"},{"key":"18_CR30","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1109\/CSAC.2003.1254341","volume-title":"ACSAC 2003: Proceedings of the 19th Annual Computer Security Applications Conference","author":"J. Zimmerman","year":"2003","unstructured":"Zimmerman, J., M\u00e9, L., Bidan, C.: Experimenting with a policy-based hids based on an information flow control model. In: ACSAC 2003: Proceedings of the 19th Annual Computer Security Applications Conference, Washington, DC, USA, p. 364. IEEE Computer Society, Los Alamitos (2003)"},{"key":"18_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"291","DOI":"10.1007\/978-3-540-39650-5_17","volume-title":"Computer Security \u2013 ESORICS 2003","author":"J. Zimmermann","year":"2003","unstructured":"Zimmermann, J., M\u00e9, L., Bidan, C.: An improved reference flow control model for policy-based intrusion detection. In: Snekkenes, E., Gollmann, D. (eds.) ESORICS 2003. LNCS, vol.\u00a02808, pp. 291\u2013308. Springer, Heidelberg (2003)"}],"container-title":["Lecture Notes in Computer Science","Data Privacy Management and Autonomous Spontaneous Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-19348-4_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T15:26:22Z","timestamp":1740929182000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-19348-4_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642193477","9783642193484"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-19348-4_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}