{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:14:04Z","timestamp":1763468044879,"version":"3.40.3"},"publisher-location":"Berlin, Heidelberg","reference-count":47,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642224232"},{"type":"electronic","value":"9783642224249"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-22424-9_8","type":"book-chapter","created":{"date-parts":[[2011,6,20]],"date-time":"2011-06-20T06:37:35Z","timestamp":1308551855000},"page":"124-143","source":"Crossref","is-referenced-by-count":18,"title":["Escape from Monkey Island: Evading High-Interaction Honeyclients"],"prefix":"10.1007","author":[{"given":"Alexandros","family":"Kapravelos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Marco","family":"Cova","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"8_CR1","unstructured":"Anubis: Analyzing Unknown Binaries, http:\/\/anubis.seclab.tuwien.ac.at"},{"key":"8_CR2","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: TTAnalyze: A Tool for Analyzing Malware. In: Proceedings of the European Institute for Computer Antivirus Research Annual Conference, EICAR (2006)"},{"key":"8_CR3","unstructured":"Boscovich, R. et\u00a0al.: Microsoft Security Intelligence Report. Technical Report, vol. 7, Microsoft, Inc. (2009)"},{"key":"8_CR4","unstructured":"Broersma, M.: Web attacks slip under the radar (2007), http:\/\/news.techworld.com\/security\/10620\/web-attacks-slip-under-the-radar\/"},{"key":"8_CR5","doi-asserted-by":"crossref","unstructured":"Cova, M., Kruegel, C., Vigna, G.: Detection and Analysis of Drive-by-Download Attacks and Malicious JavaScript Code. In: Proceedings of the International World Wide Web Conference, WWW (2010)","DOI":"10.1145\/1772690.1772720"},{"key":"8_CR6","unstructured":"CVE. Windows ANI LoadAniIcon() Chunk Size Stack Overflow (HTTP), http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2007-0038 ."},{"key":"8_CR7","unstructured":"CWSandbox (2009), http:\/\/www.cwsandbox.org\/"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: Malware analysis via hardware virtualization extensions. In: Proceedings of the ACM Conference on Computer and Communications Security, CCS (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"8_CR9","unstructured":"Ferrie, P.: Attacks on Virtual Machines. In: Proceedings of the Association of Anti-Virus Asia Researchers Conference (2007)"},{"key":"8_CR10","unstructured":"Fewer, S.: Reflective DLL injection, http:\/\/www.harmonysecurity.com\/files\/HS-P005_ReflectiveDllInjection.pdf"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"Fogla, P., Lee, W.: Evading Network Anomaly Detection Systems: Formal Reasoning and Practical Techniques. In: Proceedings of the ACM Conference on Computer and Communications Security CCS (2006)","DOI":"10.1145\/1180405.1180414"},{"key":"8_CR12","unstructured":"Frei, S., D\u00fcbendorfer, T., Ollman, G., May, M.: Understanding the Web browser threat: Examination of vulnerable online Web browser populations and the insecurity iceberg. In: Proceedings of DefCon, vol.\u00a016 (2008)"},{"key":"8_CR13","unstructured":"Garfinkel, T., Adams, K., Warfield, A., Franklin, J.: Compatibility is Not Transparency: VMM Detection Myths and Realities. In: Proceedings of the USENIX Workshop on Hot Topics in Operating Systems (2007)"},{"key":"8_CR14","unstructured":"Google. Safe Browsing API, http:\/\/code.google.com\/apis\/safebrowsing\/"},{"key":"8_CR15","unstructured":"Holz, T.: AV Tracker (2009), http:\/\/honeyblog.org\/archives\/37-AV-Tracker.html"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"Jaeger, T.: Reference Monitor Concept. Encyclopedia of Cryptography and Security (2010)","DOI":"10.1007\/978-1-4419-5906-5_646"},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy Malware Detection and Monitoring through VMM-Based Out-of-the-Box Semantic View Reconstruction. ACM Transactions on Information and System Security (TISSEC)\u00a013(2) (February 2010)","DOI":"10.1145\/1698750.1698752"},{"key":"8_CR18","unstructured":"Joebox: A Secure Sandbox Application for Windows (2009), http:\/\/www.joebox.org\/"},{"key":"8_CR19","unstructured":"Klein, T.: ScoopyNG - The VMware detection tool, http:\/\/www.trapkit.de\/research\/vmm\/scoopyng\/index.html"},{"key":"8_CR20","unstructured":"Krebs, B.: Former anti-virus researcher turns tables on industry (October 27, 2009), http:\/\/voices.washingtonpost.com\/securityfix\/2009\/10\/former_anti-virus_researcher_t.html"},{"key":"8_CR21","unstructured":"Liston, T., Skoudis, E.: On the Cutting Edge: Thwarting Virtual Machine Detection (2006), http:\/\/handlers.sans.org\/tliston\/ThwartingVMDetection_Liston_Skoudis.pdf"},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Martignoni, L., Paleari, R., Roglia, G.F., Bruschi, D.: Testing CPU Emulators. In: Proceedings of the International Symposium on Software Testing and Analysis, ISSTA (2009)","DOI":"10.1145\/1572272.1572303"},{"key":"8_CR23","unstructured":"Microsoft. What is SmartScreen Filter?, http:\/\/www.microsoft.com\/security\/filters\/smartscreen.aspx"},{"key":"8_CR24","unstructured":"MITRE. HoneyClient, http:\/\/www.honeyclient.org\/"},{"key":"8_CR25","unstructured":"Moshchuk, A., Bragin, T., Deville, D., Gribble, S., Levy, H.: SpyProxy: Execution-based Detection of Malicious Web Content. In: Proceedings of the USENIX Security Symposium (2007)"},{"key":"8_CR26","unstructured":"Moshchuk, A., Bragin, T., Gribble, S., Levy, H.: A Crawler-based Study of Spyware in the Web. In: Proceedings of the Symposium on Network and Distributed System Security, NDSS (2006)"},{"key":"8_CR27","unstructured":"M\u00fcller, T., Mack, B., Arziman, M.: Web Exploit Finder, http:\/\/www.xnos.org\/security\/web-exploit-finder.html"},{"key":"8_CR28","doi-asserted-by":"crossref","unstructured":"Nguyen, A., Schear, N., Jung, H., Godiyal, A., King, S., Nguyen, H.: MAVMM: Lightweight and Purpose Built VMM for Malware Analysis. In: Proceedings of the Annual Computer Security Applications Conference, ACSAC (2009)","DOI":"10.1109\/ACSAC.2009.48"},{"key":"8_CR29","unstructured":"Norman Sandbox (2009), http:\/\/www.norman.com\/about_norman\/technology\/norman_sandbox\/"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Paleari, R., Martignoni, L., Roglia, G.F., Bruschi, D.: A Fistful of Red-Pills: How to Automatically Generate Procedures to Detect CPU Emulators. In: Proceedings of the USENIX Workshop on Offensive Technologies, WOOT (2009)","DOI":"10.1145\/1572272.1572303"},{"key":"8_CR31","unstructured":"Polychronakis, M., Mavrommatis, P., Provos, N.: Ghost Turns Zombie: Exploring the Life Cycle of Web-based Malware. In: Proceedings of the USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET (2008)"},{"key":"8_CR32","unstructured":"Provos, N., Mavrommatis, P., Rajab, M., Monrose, F.: All Your iFRAMEs Point to Us. In: Proceedings of the USENIX Security Symposium (2008)"},{"key":"8_CR33","unstructured":"Provos, N., McNamee, D., Mavrommatis, P., Wang, K., Modadugu, N.: The Ghost in the Browser: Analysis of Web-based Malware. In: Proceedings of the USENIX Workshop on Hot Topics in Understanding Botnet (2007)"},{"key":"8_CR34","unstructured":"Ptacek, T., Newsham, T.: Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection. Technical report, Secure Networks, Inc. (1998)"},{"key":"8_CR35","unstructured":"Quist, D., Smith, V., Computing, O.: Detecting the Presence of Virtual Machines Using the Local Data Table, http:\/\/www.offensivecomputing.net\/files\/active\/0\/vm.pdf"},{"key":"8_CR36","doi-asserted-by":"crossref","unstructured":"Raffetseder, T., Kruegel, C., Kirda, E.: Detecting System Emulators. In: Proceedings of the Information Security Conference (2007)","DOI":"10.1007\/978-3-540-75496-1_1"},{"key":"8_CR37","unstructured":"Rocaspana, J.: SHELIA: A Client HoneyPot For Client-Side Attack Detection (2009), http:\/\/www.cs.vu.nl\/~herbertb\/misc\/shelia\/"},{"key":"8_CR38","unstructured":"Rutkowska, J.: Red Pill. or how to detect VMM using (almost) one CPU instruction (2004), http:\/\/www.invisiblethings.org\/papers\/redpill.html"},{"key":"8_CR39","doi-asserted-by":"crossref","unstructured":"Sharif, M., Lee, W., Cui, W., Lanzi, A.: Secure In-VM Monitoring Using Hardware Virtualization. In: Proceedings of the ACM Conference on Computer and Communications Security, CCS (2009)","DOI":"10.1145\/1653662.1653720"},{"key":"8_CR40","unstructured":"The Honeynet Project. Capture-HPC, https:\/\/projects.honeynet.org\/capture-hpc"},{"key":"8_CR41","unstructured":"ThreatExpert (2009), http:\/\/www.threatexpert.com\/"},{"key":"8_CR42","doi-asserted-by":"crossref","unstructured":"Tsaur, W., Chen, Y., Tsai, B.: A New Windows Driver-Hidden Rootkit Based on Direct Kernel Object Manipulation. In: Proceedings of the Algorithms and Architectures for Parallel Processing Conference (2009)","DOI":"10.1007\/978-3-642-03095-6_21"},{"key":"8_CR43","doi-asserted-by":"crossref","unstructured":"Van Gundy, M., Chen, H., Su, Z., Vigna, G.: Feature Omission Vulnerabilities: Thwarting Signature Generation for Polymorphic Worms. In: Proceedings of the Annual Computer Security Applications Conference, ACSAC (2007)","DOI":"10.1109\/ACSAC.2007.4412978"},{"key":"8_CR44","doi-asserted-by":"crossref","unstructured":"Vasudevan, A., Yerraballi, R.: Cobra: Fine-grained Malware Analysis using Stealth Localized Executions. In: Proceedings of the IEEE Symposium on Security and Privacy (2006)","DOI":"10.1109\/SP.2006.9"},{"key":"8_CR45","doi-asserted-by":"crossref","unstructured":"Vigna, G., Robertson, W., Balzarotti, D.: Testing Network-based Intrusion Detection Signatures Using Mutant Exploits. In: Proceedings of the ACM Conference on Computer and Communications Security CCS (2004)","DOI":"10.1145\/1030083.1030088"},{"key":"8_CR46","unstructured":"Wang, Y.-M., Beck, D., Jiang, X., Roussev, R., Verbowski, C., Chen, S., King, S.: Automated Web Patrol with Strider HoneyMonkeys: Finding Web Sites That Exploit Browser Vulnerabilities. In: Proceedings of the Symposium on Network and Distributed System Security, NDSS (2006)"},{"key":"8_CR47","doi-asserted-by":"crossref","unstructured":"Yin, H., Poosankam, P., Hanna, S., Song, D.: HookScout: Proactive Binary-Centric Hook Detection. In: Proceedings of the Conference on Detection of Intrusions and Malware & Vulnerability Assessment, DIMVA (2010)","DOI":"10.1007\/978-3-642-14215-4_1"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-22424-9_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,6,20]],"date-time":"2020-06-20T12:13:34Z","timestamp":1592655214000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-22424-9_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642224232","9783642224249"],"references-count":47,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-22424-9_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}