{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T13:11:29Z","timestamp":1769605889674,"version":"3.49.0"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2017,8,17]],"date-time":"2017-08-17T00:00:00Z","timestamp":1502928000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Pers Commun"],"published-print":{"date-parts":[[2017,12]]},"DOI":"10.1007\/s11277-017-4823-x","type":"journal-article","created":{"date-parts":[[2017,8,16]],"date-time":"2017-08-16T22:43:41Z","timestamp":1502923421000},"page":"5983-6004","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Research on Semantic Gap Problem of Virtual Machine"],"prefix":"10.1007","volume":"97","author":[{"given":"Xiaoyan","family":"Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bo","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaorui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rongcai","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,8,17]]},"reference":[{"key":"4823_CR1","doi-asserted-by":"crossref","unstructured":"Chen, P. M., & Noble, B. D. (2001). When virtual is better than real [operating system relocation to virtual machines. In Hot Topics in Operating Systems, 2001. Proceedings of the Eighth Workshop on, (pp. 133\u2013138). IEEE.","DOI":"10.1109\/HOTOS.2001.990073"},{"key":"4823_CR2","unstructured":"Bao, Y., Zhang, J., Zhu, Y., Tang, D., Ruan, Y., Chen, M., et al. (2011). arXiv preprint arXiv:1106.2568 ."},{"key":"4823_CR3","unstructured":"Garfinkel, T., & Rosenblum, M., et al. (2003). A virtual machine introspection based architecture for intrusion detection. In NDSS, Vol. 3, pp. 191\u2013206."},{"key":"4823_CR4","doi-asserted-by":"crossref","unstructured":"Mankin, J., & Kaeli, D. (2012). Dione: A flexible disk monitoring and analysis framework. In Research in attacks, intrusions, and defenses (pp. 127\u2013146). Springer.","DOI":"10.1007\/978-3-642-33338-5_7"},{"key":"4823_CR5","unstructured":"Carbone, M. (2012). Semantic view re-creation for the secure monitoring of virtual machines. Georgia Institute of Technology."},{"key":"4823_CR6","doi-asserted-by":"crossref","unstructured":"Pfoh, J., Schneider, C., & Eckert, C. (2009). A formal model for virtual machine introspection. In Proceedings of the 1st ACM workshop on Virtual machine security (pp. 1\u201310). ACM.","DOI":"10.1145\/1655148.1655150"},{"key":"4823_CR7","unstructured":"Jiang, X., Wang, X., & Xu, D. (2007). In Proceedings of the 14th ACM conference on computer and communications security (pp. 128\u2013138). ACM."},{"key":"4823_CR8","doi-asserted-by":"crossref","unstructured":"Jiang, X., & Wang, X. (2007). Out-of-the-box monitoring of VM-based high-interaction honeypots. In Recent advances in intrusion detection (pp. 198\u2013218). Springer.","DOI":"10.1007\/978-3-540-74320-0_11"},{"key":"4823_CR9","doi-asserted-by":"crossref","unstructured":"Schneider, C., Pfoh, J., & Eckert, C. (2011). In Information systems security (pp. 370\u2013373). Springer.","DOI":"10.1007\/978-3-642-25560-1_25"},{"key":"4823_CR10","doi-asserted-by":"crossref","unstructured":"Tupakula, U. K., & Varadharajan, V. (2010). Detecting security attacks in trusted virtual domains. In 2010 IEEE\/IFIP 8th international conference on embedded and ubiquitous computing (EUC) (pp. 529\u2013535). IEEE.","DOI":"10.1109\/EUC.2010.87"},{"key":"4823_CR11","doi-asserted-by":"crossref","unstructured":"Ibrahim, A. S., Hamlyn-Harris, J., Grundy, J., & Almorsy, M. (2011). CloudSec: A security monitoring appliance for virtual machines in the IaaS cloud model. In 2011 5th international conference on network and system security (NSS) (pp. 113\u2013120). IEEE.","DOI":"10.1109\/ICNSS.2011.6059967"},{"key":"4823_CR12","unstructured":"Willems, C., Hund, R., & Holz, T. (2013). Cxpinspector: Hypervisor-based, hardware-assisted system monitoring. Ruhr-Universitat Bochum, Tech. Rep."},{"key":"4823_CR13","doi-asserted-by":"crossref","unstructured":"Fattori, A., Paleari, R., Martignoni, L., & Monga, M. (2010). Dynamic and transparent analysis of commodity production systems. In Proceedings of the IEEE\/ACM international conference on Automated software engineering (pp. 417\u2013426). ACM.","DOI":"10.1145\/1858996.1859085"},{"key":"4823_CR14","unstructured":"Rhee, J., & Xu, D. (2010). LiveDM: Temporal mapping of dynamic kernel memory for dynamic kernel malware analysis and debugging."},{"key":"4823_CR15","doi-asserted-by":"crossref","unstructured":"Zhang, F., Leach, K., Sun, K., & Stavrou, A. (2013). Spectre: A dependable introspection framework via system management mode. In 2013 43rd Annual IEEE\/IFIP international conference on dependable systems and networks (DSN) (pp. 1\u201312). IEEE.","DOI":"10.1109\/DSN.2013.6575343"},{"key":"4823_CR16","unstructured":"Inoue, H., Adelstein, F., Donovan, M., & Brueckner, S. (2011). Automatically bridging the semantic gap using ac interpreter. In Proceedings of the 2011 annual symposium on information assurance, pp. 51\u201358."},{"key":"4823_CR17","doi-asserted-by":"crossref","unstructured":"Ibrahim, A. S., Hamlyn-Harris, J., Grundy, J., & Almorsy, M. (2012). Supporting virtualization-aware security solutions using a systematic approach to overcome the semantic gap. In 2012 IEEE 5th international conference on cloud computing (CLOUD) (pp. 836\u2013843). IEEE.","DOI":"10.1109\/CLOUD.2012.129"},{"key":"4823_CR18","unstructured":"Schneider, C., Pfoh, J., & Eckert, C. (2012). Bridging the semantic gap through static code analysis. In Proceedings of EuroSec, Vol. 12."},{"key":"4823_CR19","doi-asserted-by":"crossref","unstructured":"Payne, B. D., De Carbone, M., & Lee, W. (2007). Secure and flexible monitoring of virtual machines. In Twenty-third annual computer security applications conference, 2007. ACSAC 2007 (pp. 385\u2013397). IEEE.","DOI":"10.1109\/ACSAC.2007.10"},{"key":"4823_CR20","doi-asserted-by":"crossref","unstructured":"Payne, B. D. (2012). Simplifying virtual machine introspection using libvmi. Sandia report.","DOI":"10.2172\/1055635"},{"key":"4823_CR21","unstructured":"Srivastava, A. (2011). Robust and secure monitoring and attribution of malicious behaviors. Georgia Institute of Technology."},{"key":"4823_CR22","unstructured":"Nasab, M. R. (2012). Security functions for virtual machines via introspection."},{"key":"4823_CR23","unstructured":"Lengyel, T. K., Neumann, J., Maresca, S., Payne, B. D., & Kiayias, A. (2012). Virtual machine introspection in a hybrid honeypot architecture. In CSET."},{"key":"4823_CR24","unstructured":"Srivastava, A., Singh, K., & Giffin, J. (2008). Secure observation of kernel behavior. Georgia Institute of Technology."},{"key":"4823_CR25","doi-asserted-by":"crossref","unstructured":"Srinivasan, D., Wang, Z., Jiang, X., & Xu, D. (2011). Process out-grafting: An efficient out-of-vm approach for fine-grained process execution monitoring. In Proceedings of the 18th ACM conference on computer and communications security (pp. 363\u2013374). ACM.","DOI":"10.1145\/2046707.2046751"},{"key":"4823_CR26","unstructured":"Srinivasan, D. (2013). Elevating virtual machine introspection for fine-grained process monitoring: Techniques and applications. North Carolina State University."},{"key":"4823_CR27","doi-asserted-by":"crossref","unstructured":"Lombardi, F., & Di Pietro, R. (2009). KvmSec: A security extension for Linux kernel virtual machines. In Proceedings of the 2009 ACM symposium on applied computing (pp. 2029\u20132034). ACM.","DOI":"10.1145\/1529282.1529733"},{"key":"4823_CR28","doi-asserted-by":"crossref","unstructured":"Payne, B. D., Carbone, M., Sharif, M., & Lee, W. (2008). Lares: An architecture for secure active monitoring using virtualization. In IEEE symposium on security and privacy, 2008. SP 2008 (pp. 233\u2013247). IEEE.","DOI":"10.1109\/SP.2008.24"},{"key":"4823_CR29","doi-asserted-by":"crossref","unstructured":"Carbone, M., Conover, M., Montague, B., & Lee, W. (2012). Secure and robust monitoring of virtual machines through guest-assisted introspection. In Research in attacks, intrusions, and defenses (pp. 22\u201341). Springer.","DOI":"10.1007\/978-3-642-33338-5_2"},{"key":"4823_CR30","unstructured":"Montague, B., Sawhney, S., Conover, M., & Chiueh, T. C. (2013). Security driver for hypervisors and operating systems of virtualized datacenters. US Patent 8,387,046."},{"key":"4823_CR31","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., & Lee, W. (2011). Virtuoso: Narrowing the semantic gap in virtual machine introspection. In 2011 IEEE symposium on security and privacy (SP) (pp. 297\u2013312). IEEE.","DOI":"10.1109\/SP.2011.11"},{"key":"4823_CR32","doi-asserted-by":"crossref","unstructured":"Fu, Y., & Lin, Z. (2012). Space traveling across vm: Automatically bridging the semantic gap in virtual machine introspection via online kernel data redirection. In 2012 IEEE symposium on security and privacy (SP) (pp. 586\u2013600). IEEE.","DOI":"10.1109\/SP.2012.40"},{"issue":"7","key":"4823_CR33","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1145\/2517326.2451534","volume":"48","author":"Y Fu","year":"2013","unstructured":"Fu, Y., & Lin, Z. (2013). Exterior: Using a dual-vm based external shell for guest-os introspection, configuration, and recovery. ACM SIGPLAN Notices, 48(7), 97.","journal-title":"ACM SIGPLAN Notices"},{"key":"4823_CR34","unstructured":"Litty, L., Lagar-Cavilla, H. A., & Lie, D. (2008). Hypervisor support for identifying covertly executing binaries. In USENIX Security Symposium, pp. 243\u2013258."},{"key":"4823_CR35","doi-asserted-by":"crossref","unstructured":"Wang, J., Yu, M., Li, B., Qi, Z., & Guan, H. (2012). Hypervisor-based protection of sensitive files in a compromised system. In Proceedings of the 27th annual ACM symposium on applied computing (pp. 1765\u20131770). ACM.","DOI":"10.1145\/2245276.2232063"},{"key":"4823_CR36","unstructured":"Jones, S. T., Arpaci-Dusseau, A. C., & Arpaci-Dusseau, R. H. (2006). Antfarm: Tracking processes in a virtual machine environment. In USENIX Annual Technical Conference, General Track, pp. 1\u201314."},{"key":"4823_CR37","doi-asserted-by":"crossref","unstructured":"Jones, S. T., Arpaci-Dusseau, A. C., & Arpaci-Dusseau, R. H. (2008). VMM-based hidden process detection and identification using Lycosid. In Proceedings of the fourth ACM SIGPLAN\/SIGOPS international conference on virtual execution environments (pp. 91\u2013100). ACM.","DOI":"10.1145\/1346256.1346269"},{"key":"4823_CR38","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., & Lee, W. (2008). Ether: Malware analysis via hardware virtualization extensions. In Proceedings of the 15th ACM conference on computer and communications security (pp. 51\u201362). ACM.","DOI":"10.1145\/1455770.1455779"},{"key":"4823_CR39","doi-asserted-by":"crossref","unstructured":"Pfoh, J., Schneider, C., & Eckert, C. (2011). Nitro: Hardware-based system call tracing for virtual machines. In Advances in information and computer security (pp. 96\u2013112). Springer.","DOI":"10.1007\/978-3-642-25141-2_7"},{"key":"4823_CR40","unstructured":"Pfoh, J., et al. (2013). Leveraging derivative virtual machine introspection methods for security applications. Ph.D. thesis, Technische Universit\u00e4t M\u00fcnchen."},{"key":"4823_CR41","doi-asserted-by":"crossref","unstructured":"Christodorescu, M., Sailer, R., Schales, D. L., Sgandurra, D., & Zamboni, D. (2009). Cloud security is not (just) virtualization security: A short paper. In Proceedings of the 2009 ACM workshop on cloud computing security (pp. 97\u2013102). ACM.","DOI":"10.1145\/1655008.1655022"},{"key":"4823_CR42","doi-asserted-by":"crossref","unstructured":"Bahram, S., Jiang, X., Wang, Z., Grace, M., Li, J., Srinivasan, D., et al. (2010). Dksm: Subverting virtual machine introspection for fun and profit. In 2010 29th IEEE symposium on reliable distributed systems (pp. 82\u201391). IEEE.","DOI":"10.1109\/SRDS.2010.39"},{"key":"4823_CR43","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1016\/j.ins.2013.03.022","volume":"239","author":"I Corona","year":"2013","unstructured":"Corona, I., Giacinto, G., & Roli, F. (2013). Adversarial attacks against intrusion detection systems: Taxonomy, solutions and open issues. Information Sciences, 239, 201.","journal-title":"Information Sciences"},{"key":"4823_CR44","doi-asserted-by":"crossref","unstructured":"Gu, Z., Deng, Z., Xu, D., & Jiang, X. (2011). Process implanting: A new active introspection framework for virtualization. In 2011 30th IEEE symposium on reliable distributed systems (SRDS) (pp. 147\u2013156). IEEE.","DOI":"10.1109\/SRDS.2011.26"}],"container-title":["Wireless Personal Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11277-017-4823-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-017-4823-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-017-4823-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,2]],"date-time":"2019-10-02T09:42:51Z","timestamp":1570009371000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11277-017-4823-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,17]]},"references-count":44,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,12]]}},"alternative-id":["4823"],"URL":"https:\/\/doi.org\/10.1007\/s11277-017-4823-x","relation":{},"ISSN":["0929-6212","1572-834X"],"issn-type":[{"value":"0929-6212","type":"print"},{"value":"1572-834X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,8,17]]}}}