{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T08:25:16Z","timestamp":1771230316160,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":39,"publisher":"Springer Singapore","isbn-type":[{"value":"9789811566479","type":"print"},{"value":"9789811566486","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-981-15-6648-6_21","type":"book-chapter","created":{"date-parts":[[2020,7,18]],"date-time":"2020-07-18T09:02:51Z","timestamp":1595062971000},"page":"263-276","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["A Method for Malware Detection in Virtualization Environment"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5138-8979","authenticated-orcid":false,"given":"Darshan","family":"Tank","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Akshai","family":"Aggarwal","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6575-7723","authenticated-orcid":false,"given":"Nirbhay","family":"Chaubey","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,7,19]]},"reference":[{"key":"21_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1007\/978-3-319-49445-6_16","volume-title":"Security, Privacy, and Applied Cryptography Engineering","author":"MA Ajay Kumara","year":"2016","unstructured":"Ajay Kumara, M.A., Jaidhar, C.D.: VMI based automated real-time malware detector for virtualized cloud environment. In: Carlet, Claude, Hasan, M.Anwar, Saraswat, Vishal (eds.) SPACE 2016. LNCS, vol. 10076, pp. 281\u2013300. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-49445-6_16"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Zhang, S., Meng, X., Wang, L., Xu, L., Han, X.: Secure virtualization environment based on advanced memory introspection. In: Security and Communication Networks (2018)","DOI":"10.1155\/2018\/9410278"},{"issue":"1","key":"21_CR3","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1186\/s13677-014-0016-2","volume":"3","author":"A More","year":"2014","unstructured":"More, A., Tapaswi, S.: Virtual machine introspection: towards bridging the semantic gap. J. Cloud Comput. 3(1), 16 (2014)","journal-title":"J. Cloud Comput."},{"issue":"1","key":"21_CR4","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1186\/s13677-017-0098-8","volume":"6","author":"N Rakotondravony","year":"2017","unstructured":"Rakotondravony, N., et al.: Classifying malware attacks in IaaS cloud environments. J. Cloud Comput. 6(1), 26 (2017)","journal-title":"J. Cloud Comput."},{"key":"21_CR5","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., Lee, W.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: 2011 IEEE Symposium on Security and Privacy, pp. 297\u2013312. IEEE, May 2011","DOI":"10.1109\/SP.2011.11"},{"key":"21_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2516951.2505124","volume":"16","author":"Yangchun Fu","year":"2013","unstructured":"Fu, Y., Lin, Z.: Bridging the semantic gap in virtual machine introspection via online kernel data redirection. ACM Trans. Inf. Syst. Secur. 16, 1\u201329 (2013). https:\/\/doi.org\/10.1145\/2516951.2505124","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"21_CR7","unstructured":"Virtual Machine Introspection in Malware Analysis. https:\/\/resources.infosecinstitute.com\/virtual-machine-introspection-in-malware-analysis\/. Accessed 17 Dec 2019"},{"key":"21_CR8","unstructured":"Wikipedia contributors: Rootkit. In Wikipedia, The Free Encyclopedia, 12 March 2020. https:\/\/en.wikipedia.org\/w\/index.php?title=Rootkit&oldid=945263481. Accessed 15 Mar 2020"},{"key":"21_CR9","doi-asserted-by":"crossref","unstructured":"Huseinovic, A., Ribic, S.: Virtual machine memory forensics. In: 2013 21st Telecommunications Forum Telfor (TELFOR), pp. 940\u2013942 (2013)","DOI":"10.1109\/TELFOR.2013.6716386"},{"key":"21_CR10","doi-asserted-by":"crossref","unstructured":"Hua, Q., Zhang, Y.: Detecting malware and rootkit via memory forensics. In: 2015 International Conference on Computer Science and Mechanical Automation (CSMA), pp. 92\u201396 (2015)","DOI":"10.1109\/CSMA.2015.25"},{"key":"21_CR11","doi-asserted-by":"crossref","unstructured":"Tien, C., Liao, J., Chang, S., Kuo, S.: Memory forensics using virtual machine introspection for Malware analysis. In: 2017 IEEE Conference on Dependable and Secure Computing, 518\u2013519 (2017)","DOI":"10.1109\/DESEC.2017.8073871"},{"key":"21_CR12","doi-asserted-by":"publisher","first-page":"S25","DOI":"10.1016\/j.diin.2015.05.005","volume":"14","author":"Andrew Case","year":"2015","unstructured":"Case, A., Richard, I.I.I., Golden, G.: Advancing Mac OS X rootkit detection. Digital Invest. 14, S25\u2013S33 (2015). https:\/\/doi.org\/10.1016\/j.diin.2015.05.005","journal-title":"Digital Invest."},{"key":"21_CR13","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1007\/978-3-319-46279-0_19","volume-title":"Advances in Digital Forensics XII","author":"Haiyu Yang","year":"2016","unstructured":"Yang, H., Zhuge, J., Liu, H., Liu, W.: A tool for volatile memory acquisition from android devices. DigitalForensics 2016. IAICT, vol. 484, pp. 365\u2013378. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46279-0_19"},{"key":"21_CR14","unstructured":"Kumara, A., Jaidhar, C.D.: Execution time measurement of virtual machine volatile artifacts analyzers. In: 2015 IEEE 21st International Conference on Parallel and Distributed Systems (ICPADS), pp. 314\u2013319. IEEE (2015)"},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Tien, C., Liao, J., Chang, S., Kuo, S.: Memory forensics using virtual machine introspection for Malware analysis. In: 2017 IEEE Conference on Dependable and Secure Computing, pp. 518\u2013519 (2017)","DOI":"10.1109\/DESEC.2017.8073871"},{"key":"21_CR16","doi-asserted-by":"crossref","unstructured":"Kumara, M.A., Jaidhar, C.D.: Automated multi-level malware detection system based on reconstructed semantic view of executables using machine learning techniques at VMM (2018)","DOI":"10.1016\/j.future.2017.06.002"},{"key":"21_CR17","doi-asserted-by":"crossref","unstructured":"Mosli, R., Li, R., Yuan, B., Pan, Y.: Automated malware detection using artifacts in forensic memory images. In: 2016 IEEE Symposium on Technologies for Homeland Security (HST), 1\u20136 (2016)","DOI":"10.1109\/THS.2016.7568881"},{"key":"21_CR18","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1016\/j.diin.2017.10.004","volume":"23","author":"MA Kumara","year":"2017","unstructured":"Kumara, M.A., Jaidhar, C.D.: Leveraging virtual machine introspection with memory forensics to detect and characterize unknown malware using machine learning techniques at hypervisor. Digit. Invest. 23, 99\u2013123 (2017)","journal-title":"Digit. Invest."},{"key":"21_CR19","doi-asserted-by":"publisher","unstructured":"Chaubey, N.K., Tank, D.M.: Security, privacy and challenges in Mobile Cloud Computing (MCC): - a critical study and comparison. Int. J. Innov. Res. Comput. Commun. Eng. (IJIRCCE), 4(2), 1259\u20131266 (2016). https:\/\/doi.org\/10.15680\/ijircce.2016.0402028","DOI":"10.15680\/ijircce.2016.0402028"},{"issue":"6","key":"21_CR20","first-page":"31","volume":"6","author":"D Tank","year":"2017","unstructured":"Tank, D., Aggarwal, A., Chaubey, N.: Security analysis of OpenStack keystone. Int. J. Latest Technol. Eng. Manag. Appl. Sci. (IJLTEMAS) 6(6), 31\u201338 (2017)","journal-title":"Int. J. Latest Technol. Eng. Manag. Appl. Sci. (IJLTEMAS)"},{"key":"21_CR21","doi-asserted-by":"publisher","unstructured":"Tank, D.M.: Security and privacy issues, solutions, and tools for MCC. In: Munir, K. (ed.) Security Management in Mobile Cloud Computing, pp. 121\u2013147. IGI Global, Hershey (2017). https:\/\/doi.org\/10.4018\/978-1-5225-0602-7.ch006","DOI":"10.4018\/978-1-5225-0602-7.ch006"},{"key":"21_CR22","doi-asserted-by":"publisher","unstructured":"Tank, D., Aggarwal, A. Chaubey, N.: Virtualization vulnerabilities, security issues, and solutions: a critical study and comparison. Int. J. Inf. Technol. (2019). https:\/\/doi.org\/10.1007\/s41870-019-00294-x","DOI":"10.1007\/s41870-019-00294-x"},{"issue":"5","key":"21_CR23","doi-asserted-by":"publisher","first-page":"1109","DOI":"10.1080\/02522667.2019.1638001","volume":"40","author":"D Tank","year":"2019","unstructured":"Tank, D., Aggarwal, A., Chaubey, N.: Cache attack detection in virtualized environments. J. Inf. Optim. Sci. 40(5), 1109\u20131119 (2019). https:\/\/doi.org\/10.1080\/02522667.2019.1638001","journal-title":"J. Inf. Optim. Sci."},{"key":"21_CR24","doi-asserted-by":"publisher","unstructured":"Tank, D. M., Aggarwal, A., Chaubey, N.K.: Cyber security aspects of virtualization in cloud computing environments: analyzing virtualization-specific cyber security risks. In: Chaubey, N., Prajapati, B. (eds.), Quantum Cryptography and the Future of Cyber Security, pp. 283\u2013299. IGI Global, Hershey (2020). https:\/\/doi.org\/10.4018\/978-1-7998-2253-0.ch013","DOI":"10.4018\/978-1-7998-2253-0.ch013"},{"key":"21_CR25","unstructured":"Introduction to LibVMI. http:\/\/libvmi.com\/docs\/gcode-intro.html. Accessed 11 Jan 2020"},{"key":"21_CR26","doi-asserted-by":"publisher","unstructured":"Xiong, H. Liu, Z., Xu, W.: Libvmi: a library for bridging the semantic gap between guest OS and VMM. In: Proceedings - 2012 IEEE 12th International Conference on Computer and Information Technology, CIT 2012, pp. 549\u2013556 (2012). https:\/\/doi.org\/10.1109\/cit.2012.119","DOI":"10.1109\/cit.2012.119"},{"key":"21_CR27","unstructured":"An advanced memory forensics framework. http:\/\/volatilityfoundation.org\/. Accessed 17 Nov 2019"},{"key":"21_CR28","unstructured":"Finding Advanced Malware Using Volatility. https:\/\/eforensicsmag.com\/finding-advanced-malware-using-volatility\/. Accessed 11 Jan 2020"},{"key":"21_CR29","unstructured":"Memory Forensics Investigation using Volatility. https:\/\/www.hackingarticles.in\/memory-forensics-investigation-using-volatility-part-1\/. Accessed 11 Jan 2020"},{"key":"21_CR30","doi-asserted-by":"publisher","unstructured":"Ainapure, B., Shah, D., Ananda Rao, A.: Performance analysis of virtual machine introspection tools in cloud environment. In: Proceedings of the International Conference on Informatics and Analytics (ICIA-16). Association for Computing Machinery, New York, NY, USA, Article 27, pp. 1\u20136 (2016). https:\/\/doi.org\/10.1145\/2980258.2980309","DOI":"10.1145\/2980258.2980309"},{"key":"21_CR31","unstructured":"GitHub, volatilityfoundation\/volatility - Command Reference Mal, https:\/\/github.com\/volatilityfoundation\/volatility\/wiki\/Command-Reference-Mal. Accessed 08 Jan 2020"},{"key":"21_CR32","unstructured":"GitHub, volatilityfoundation\/volatility - Command Reference, https:\/\/github.com\/volatilityfoundation\/volatility\/wiki\/Command-Reference. Accessed 08 Jan 2020"},{"key":"21_CR33","unstructured":"VirtualAllocEx function (memoryapi.h) - Win32 apps | Microsoft Docs. https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/memoryapi\/nf-memoryapi-virtualallocex. Accessed 08 Jan 2020"},{"key":"21_CR34","unstructured":"Wikipedia contributors. Scikit-learn. In Wikipedia, The Free Encyclopedia (2020). https:\/\/en.wikipedia.org\/w\/index.php?title=Scikit-learn&oldid=948478961. Accessed 11 Jan 2020"},{"key":"21_CR35","unstructured":"GitHub - theevilbit\/injection. https:\/\/github.com\/theevilbit\/injection. Accessed 08 Jan 2020"},{"key":"21_CR36","unstructured":"GitHub - fdiskyou\/injectAllTheThings: Seven different DLL injection techniques in one single project. https:\/\/github.com\/fdiskyou\/injectAllTheThings. Accessed 08 Jan 2020"},{"key":"21_CR37","unstructured":"GitHub - secrary\/InjectProc: InjectProc - Process Injection Techniques. https:\/\/github.com\/secrary\/InjectProc. Accessed 08 Jan 2020"},{"key":"21_CR38","unstructured":"GitHub - marcosd4h\/memhunter: Live hunting of code injection techniques. https:\/\/github.com\/marcosd4h\/memhunter. Accessed 08 Jan 2020"},{"key":"21_CR39","unstructured":"GitHub - stephenfewer\/ReflectiveDLLInjection: Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process. https:\/\/github.com\/stephenfewer\/ReflectiveDLLInjection. Accessed 08 Jan 2020"}],"container-title":["Communications in Computer and Information Science","Computing Science, Communication and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-15-6648-6_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T07:43:07Z","timestamp":1625125387000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-15-6648-6_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9789811566479","9789811566486"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-981-15-6648-6_21","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"19 July 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"COMS2","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computing Science, Communication and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gujarat","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 March 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 March 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"coms22020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/coms2.gnu.ac.in\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"OCS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"79","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"33% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Due to the COVID-19 pandemic COMS2 2020 was held virtually","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}