{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T19:07:01Z","timestamp":1757617621410,"version":"3.44.0"},"publisher-location":"Singapore","reference-count":45,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819624164"},{"type":"electronic","value":"9789819624171"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-2417-1_2","type":"book-chapter","created":{"date-parts":[[2025,3,3]],"date-time":"2025-03-03T09:50:39Z","timestamp":1740995439000},"page":"19-36","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Identifying Ransomware Functions Through Microarchitectural Side-Channel Analysis"],"prefix":"10.1007","author":[{"given":"Connor","family":"Startzel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7235-548X","authenticated-orcid":false,"given":"Dane","family":"Brown","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9709-5090","authenticated-orcid":false,"suffix":"III","given":"T.","family":"Owens Walker","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0674-154X","authenticated-orcid":false,"given":"Jennie E.","family":"Hill","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,3,4]]},"reference":[{"key":"2_CR1","unstructured":"Brill, A., Thompson, E.: Ransomware, a tool and opportunity for terrorist financing and cyberwarfare. Defence Against Terror. Rev. 12 (2019)"},{"key":"2_CR2","unstructured":"Team ZCySec. Mgm resorts data breach FAQ: what happened, who was affected, what was the impact? (2023)"},{"key":"2_CR3","unstructured":"Siddiqui, Z.: MGM casino expects \\$100 million hit from hack that led to data breach. Insurance J. (2023). Accessed 10 May 2024"},{"key":"2_CR4","unstructured":"Braue, D.: Global ransomware damage costs predicted to exceed \\$265 billion by 2031 (2021)"},{"issue":"10","key":"2_CR5","doi-asserted-by":"publisher","first-page":"102","DOI":"10.1109\/MC.2023.3298072","volume":"56","author":"PS Chauhan","year":"2023","unstructured":"Chauhan, P.S., Kshetri, N.: Ransomware as a service kit: a novel cybercrime strategy to monetize victims\u2019 data. Computer 56(10), 102\u2013106 (2023)","journal-title":"Computer"},{"key":"2_CR6","unstructured":"Gatlan, S.: CISA: lockbit ransomware extorted \\$91 million in 1,700 U.S. attacks. BleepingComputer (2023). Accessed 10 May 2024"},{"key":"2_CR7","unstructured":"Kovacs, E.: Law enforcement hacks lockbit ransomware, delivers major blow to operation. SecurityWeek (2023). Accessed 10 May 2024"},{"key":"2_CR8","unstructured":"The biggest ransomware attacks of 2023. Kaspersky Official Blog (2023). Accessed 10 May 2024"},{"key":"2_CR9","unstructured":"CrowdStrike. U.S. and U.K. law enforcement seize lockbit ransomware infrastructure. CrowdStrike Blog (2024). Accessed 10 May 2024"},{"key":"2_CR10","unstructured":"O\u2019Donnell-Welch, L.: Europol, FBI announce lockbit ransomware crackdown. Decipher - Duo Security (2024). Accessed 10 May 2024"},{"key":"2_CR11","unstructured":"Office of\u00a0Public\u00a0Affairs. U.S. and U.K. disrupt lockbit ransomware variant. United States Department of Justice (2024). Accessed 10 May 2024"},{"key":"2_CR12","doi-asserted-by":"publisher","first-page":"100178","DOI":"10.1109\/ACCESS.2022.3207757","volume":"10","author":"S Alzahrani","year":"2022","unstructured":"Alzahrani, S., Xiao, Y., Sun, W.: An analysis of conti ransomware leaked source codes. IEEE Access 10, 100178\u2013100193 (2022)","journal-title":"IEEE Access"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Malone, C., Zahran, M., Karri, R.: Are hardware performance counters a cost effective way for integrity checking of programs. In: Proceedings of the Sixth ACM Workshop on Scalable Trusted Computing, STC 2011, New York, NY, USA, pp. 71\u201376. Association for Computing Machinery (2011)","DOI":"10.1145\/2046582.2046596"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Gonzalez, D., Hayajneh, T.: Detection and prevention of crypto-ransomware. In: 2017 IEEE 8th Annual Ubiquitous Computing, Electronics and Mobile Communication Conference (UEMCON), pp. 472\u2013478. IEEE (2017)","DOI":"10.1109\/UEMCON.2017.8249052"},{"key":"2_CR15","unstructured":"Taylor, M.A., Smith, K.N., Thornton, M.A.: Sensor-based ransomware detection. In: Future Technologies Conference, pp. 794\u2013801 (2017)"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Taylor, M.A., Larson, E.C., Thornton, M.A.: Rapid ransomware detection through side channel exploitation. In: 2021 IEEE International Conference on Cyber Security and Resilience (CSR), pp. 47\u201354. IEEE (2021)","DOI":"10.1109\/CSR51186.2021.9527943"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Taylor, M.A., Larson, E.C., Thornton, M.A.: General process detection through physical side channel characterization. In: 2022 IEEE International Systems Conference (SysCon), pp. 1\u20138. IEEE (2022)","DOI":"10.1109\/SysCon53536.2022.9773803"},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Thummapudi, K., Lama, P., Boppana, R.V.: Detection of ransomware attacks using processor and disk usage data. IEEE Access (2023)","DOI":"10.1109\/ACCESS.2023.3279819"},{"key":"2_CR19","doi-asserted-by":"crossref","unstructured":"Alam, M., Bhattacharya, S., Dutta, S., Sinha, S., Mukhopadhyay, D., Chattopadhyay, A.: RATAFIA: ransomware analysis using time and frequency informed autoencoders. In: 2019 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 218\u2013227. IEEE (2019)","DOI":"10.1109\/HST.2019.8740837"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Woralert, C., Liu, C., Blasingame, Z., Yang, Z.: A comparison of one-class and two-class models for ransomware detection via low-level hardware information. In: 2023 Asian Hardware Oriented Security and Trust Symposium (AsianHOST), pp. 1\u20136. IEEE (2023)","DOI":"10.1109\/AsianHOST59942.2023.10409333"},{"key":"2_CR21","doi-asserted-by":"publisher","first-page":"e361","DOI":"10.7717\/peerj-cs.361","volume":"7","author":"S Aurangzeb","year":"2021","unstructured":"Aurangzeb, S., Rais, R.N.B., Aleem, M., Islam, M.A., Iqbal, M.A.: On the classification of microsoft-windows ransomware using hardware profile. PeerJ Comput. Sci. 7, e361 (2021)","journal-title":"PeerJ Comput. Sci."},{"issue":"3","key":"2_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3608484","volume":"4","author":"PM Anand","year":"2023","unstructured":"Anand, P.M., Charan, P.V.S., Shukla, S.K.: Hiper-early detection of a ransomware attack using hardware performance counters. Digit. Threats: Res. Pract. 4(3), 1\u201324 (2023)","journal-title":"Digit. Threats: Res. Pract."},{"key":"2_CR23","unstructured":"Sinha, S., Alam, M., Bhattacharya, S., Mukhopadhyay, D., Chattopadhyay, A., Dutta, S.: RAPPER: ransomware prevention via performance counters. In: Kangacrypt 2018, Adelaide, Australia (2018)"},{"key":"2_CR24","unstructured":"Pundir, N., Tehranipoor, M., Rahman, F.: RanStop: a hardware-assisted runtime crypto-ransomware detection technique. arXiv preprint arXiv:2011.12248 (2020)"},{"key":"2_CR25","doi-asserted-by":"crossref","unstructured":"Hill, J.E., Walker, T.O., Blanco, J.A., Ives, R.W., Rakvic, R., Jacob, B.: Ransomware classification using hardware performance counters on a non-virtualized system. IEEE Access (2024)","DOI":"10.1109\/ACCESS.2024.3395491"},{"key":"2_CR26","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 51\u201362 (2008)","DOI":"10.1145\/1455770.1455779"},{"issue":"2","key":"2_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3382190","volume":"53","author":"F Sierra-Arriaga","year":"2020","unstructured":"Sierra-Arriaga, F., Branco, R., Lee, B.: Security issues and challenges for virtualization technologies. ACM Comput. Surv. (CSUR) 53(2), 1\u201337 (2020)","journal-title":"ACM Comput. Surv. (CSUR)"},{"issue":"5","key":"2_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3329786","volume":"52","author":"O Or-Meir","year":"2019","unstructured":"Or-Meir, O., Nissim, N., Elovici, Y., Rokach, L.: Dynamic malware analysis in the modern era-a state of the art survey. ACM Comput. Surv. (CSUR) 52(5), 1\u201348 (2019)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"2_CR29","doi-asserted-by":"crossref","unstructured":"Arora, A., Hasan, R., Warner, G.: Obsolete ransomware: a comprehensive study of the continued threat to users. Int. J. Internet Technol. Secur. Trans. 7 (2020)","DOI":"10.20533\/jitst.2046.3723.2020.0082"},{"issue":"8","key":"2_CR30","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1016\/S1353-4858(21)00088-X","volume":"2021","author":"R Davidson","year":"2021","unstructured":"Davidson, R.: The fight against malware as a service. Netw. Secur. 2021(8), 7\u201311 (2021)","journal-title":"Netw. Secur."},{"key":"2_CR31","doi-asserted-by":"crossref","unstructured":"Mahmoud, R.-V., Anagnostopoulos, M., Pastrana, S., Pedersen, J.M.: Enhancing analysis through sysmon and ELK integration. IEEE Access, Redefining Malware Sandboxing (2024)","DOI":"10.1109\/ACCESS.2024.3400167"},{"key":"2_CR32","unstructured":"Grelot, F., Larinier, S., Salmon, M.: Automation of binary analysis: from open source collection to threat intelligence. In: Proceedings of the 28th C &ESAR, vol. 41 (2021)"},{"key":"2_CR33","unstructured":"Dasgupta, P., Osman, Z.: A comparison of state-of-the-art techniques for generating adversarial malware binaries. arXiv preprint arXiv:2111.11487 (2021)"},{"key":"2_CR34","unstructured":"Kharraz, M., Arshad, S., Kirda, E.: UNVEIL: a large-scale, automated approach to detecting ransomware. In: 25th USENIX Security Symposium (USENIX Security 2016), Austin, TX, pp. 757\u2013772 (2016)"},{"issue":"9","key":"2_CR35","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3479393","volume":"54","author":"T McIntosh","year":"2021","unstructured":"McIntosh, T., Kayes, A., Chen, Y.-P., Ng, A., Watters, P.: Ransomware mitigation in the modern era: a comprehensive review, research challenges, and future directions. ACM Comput. Surv. (CSUR) 54(9), 1\u201336 (2021)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"2_CR36","doi-asserted-by":"crossref","unstructured":"Wan, Y.-L., Chang, J.-C., Chen, R.-J., Wang, S.-J.: Feature-selection-based ransomware detection with machine learning of data analysis. In: 2018 3rd international conference on computer and communication systems (ICCCS), pp. 85\u201388. IEEE (2018)","DOI":"10.1109\/CCOMS.2018.8463300"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Sun, R., et al.: Mate! Are you really aware? An explainability-guided testing framework for robustness of malware detectors. In: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 1573\u20131585 (2023)","DOI":"10.1145\/3611643.3616309"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Rohleder, R.: Hands-on Ghidra-a tutorial about the software reverse engineering framework. In: Proceedings of the 3rd ACM Workshop on Software Protection, pp. 77\u201378 (2019)","DOI":"10.1145\/3338503.3357725"},{"issue":"1","key":"2_CR39","doi-asserted-by":"publisher","first-page":"35","DOI":"10.33260\/zictjournal.v1i1.19","volume":"1","author":"A Zimba","year":"2017","unstructured":"Zimba, A., Simukonda, L., Chishimba, M.: Demystifying ransomware attacks: reverse engineering and dynamic malware analysis of wannacry for network and information security. Zambia ICT J. 1(1), 35\u201340 (2017)","journal-title":"Zambia ICT J."},{"key":"2_CR40","unstructured":"Zugec, M.: Bitdefender threat debrief (2024). Accessed 11 May 2024"},{"key":"2_CR41","doi-asserted-by":"crossref","unstructured":"Das, S., Werner, J., Antonakakis, M., Polychronakis, M., Monrose, F.: SoK: the challenges, pitfalls, and perils of using hardware performance counters for security. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 20\u201338. IEEE (2019)","DOI":"10.1109\/SP.2019.00021"},{"key":"2_CR42","unstructured":"Ovalle, E., Figurelli, F., Souza, C., Mu\u00f1oz, A.: Revisiting the lockbit 3.0 builder files (2024). Accessed 30 May 2024"},{"key":"2_CR43","unstructured":"2nd generation intel xeon processor scalable family based on cascade lake product. Accessed 30 May 2024"},{"key":"2_CR44","unstructured":"Intel\u00ae VTune\u2122profiler user guide. Accessed 30 May 2024"},{"key":"2_CR45","unstructured":"Intel VTune amplifier XE and intel VTune amplifier for systems help: DSB switches. Accessed 30 May 2024"}],"container-title":["Lecture Notes in Computer Science","Science of Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-2417-1_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,6]],"date-time":"2025-09-06T06:59:46Z","timestamp":1757141986000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-2417-1_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819624164","9789819624171"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-2417-1_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"4 March 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SciSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Science of Cyber Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"scisec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.scisec.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}