{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T15:14:22Z","timestamp":1783523662015,"version":"3.55.0"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J. Comput. Sci. Technol."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1007\/s11390-026-5439-y","type":"journal-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T14:22:05Z","timestamp":1783520525000},"page":"825-842","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["WOWAF: Enhanced Dynamic Binary Analysis Framework Targeting Windows-on-Windows 64-Bit Environments"],"prefix":"10.1007","volume":"41","author":[{"given":"Jia-Ye","family":"Pan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Le-Tian","family":"Sha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"De-Qiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fu","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,8]]},"reference":[{"key":"5439_CR1","doi-asserted-by":"publisher","first-page":"1557","DOI":"10.1109\/SP40001.2021.00047","volume-title":"Proc. the 2021 IEEE Symposium on Security and Privacy","author":"F Barr-Smith","year":"2021","unstructured":"Barr-Smith F, Ugarte-Pedrero X, Graziano M, Spolaor R, Martinovic I. Survivalism: Systematic analysis of Windows malware living-off-the-land. In Proc. the 2021 IEEE Symposium on Security and Privacy, May 2021, pp.1557\u20131574. DOI: https:\/\/doi.org\/10.1109\/SP40001.2021.00047."},{"key":"5439_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2019.01.002","volume":"32","author":"S S Chakkaravarthy","year":"2019","unstructured":"Chakkaravarthy S S, Sangeetha D, Vaidehi V. A survey on malware analysis and mitigation techniques. Computer Science Review, 2019, 32: 1\u201323. DOI: https:\/\/doi.org\/10.1016\/j.cosrev.2019.01.002.","journal-title":"Computer Science Review"},{"key":"5439_CR3","doi-asserted-by":"publisher","unstructured":"Mallissery S, Wu Y S. Demystify the fuzzing methods: A comprehensive survey. ACM Computing Surveys, 2024, 56(3): Article No. 71. DOI: https:\/\/doi.org\/10.1145\/3623375.","DOI":"10.1145\/3623375"},{"key":"5439_CR4","doi-asserted-by":"publisher","unstructured":"Or-Meir O, Nissim N, Elovici Y, Rokach L. Dynamic malware analysis in the modern era\u2014A state of the art survey. ACM Computing Surveys (CSUR), 2020, 52(5): Article No. 88. DOI: https:\/\/doi.org\/10.1145\/3329786.","DOI":"10.1145\/3329786"},{"key":"5439_CR5","doi-asserted-by":"publisher","first-page":"2725","DOI":"10.1145\/3576915.3623214","volume-title":"Proc. the 2023 ACM SIGSAC Conference on Computer and Communications Security","author":"Z Lin","year":"2023","unstructured":"Lin Z, Li J, Li B, Ma H, Gao D, Ma J. TypeSqueezer: When static recovery of function signatures for binary executables meets dynamic analysis. In Proc. the 2023 ACM SIGSAC Conference on Computer and Communications Security, Nov. 2023, pp.2725\u20132739. DOI: https:\/\/doi.org\/10.1145\/3576915.3623214."},{"key":"5439_CR6","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/3321705.3329819","volume-title":"Proc. the 2019 ACM Asia Conference on Computer and Communications Security","author":"D C D\u2019Elia","year":"2019","unstructured":"D\u2019Elia D C, Coppa E, Nicchi S, Palmaro F, Cavallaro L. SoK: Using dynamic binary instrumentation for security (and how you may get caught red handed). In Proc. the 2019 ACM Asia Conference on Computer and Communications Security, Jul. 2019, pp.15\u201327. DOI: https:\/\/doi.org\/10.1145\/3321705.3329819."},{"issue":"6","key":"5439_CR7","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1145\/1064978.1065034","volume":"40","author":"C K Luk","year":"2005","unstructured":"Luk C K, Cohn R, Muth R, Patil H, Klauser A, Lowney G, Wallace S, Reddi V J, Hazelwood K. Pin: Building customized program analysis tools with dynamic instrumentation. ACM SIGPLAN Notices, 2005, 40(6): 190\u2013200. DOI: https:\/\/doi.org\/10.1145\/1064978.1065034.","journal-title":"ACM SIGPLAN Notices"},{"key":"5439_CR8","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1145\/2151024.2151043","volume-title":"Proc. the 8th ACM SIGPLAN\/SIGOPS Conference on Virtual Execution Environments","author":"D Bruening","year":"2012","unstructured":"Bruening D, Zhao Q, Amarasinghe S. Transparent dynamic instrumentation. In Proc. the 8th ACM SIGPLAN\/SIGOPS Conference on Virtual Execution Environments, Mar. 2012, pp.133\u2013144. DOI: https:\/\/doi.org\/10.1145\/2151024.2151043."},{"issue":"6","key":"5439_CR9","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1145\/1273442.1250746","volume":"42","author":"N Nethercote","year":"2007","unstructured":"Nethercote N, Seward J. Valgrind: A framework for heavyweight dynamic binary instrumentation. ACM SIGPLAN Notices, 2007, 42(6): 89\u2013100. DOI: https:\/\/doi.org\/10.1145\/1273442.1250746.","journal-title":"ACM SIGPLAN Notices"},{"key":"5439_CR10","first-page":"31","volume-title":"Proc. the 22nd International Symposium on Research in Attacks, Intrusions and Defenses","author":"A Davanian","year":"2019","unstructured":"Davanian A, Qi Z, Qu Y, Yin H. DECAF++: Elastic whole-system dynamic taint analysis. In Proc. the 22nd International Symposium on Research in Attacks, Intrusions and Defenses, Sept. 2019, pp.31\u201345."},{"issue":"1","key":"5439_CR11","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/s11416-014-0224-9","volume":"11","author":"O Ferrand","year":"2015","unstructured":"Ferrand O. How to detect the cuckoo sandbox and to strengthen it? Journal of Computer Virology and Hacking Techniques, 2015, 11(1): 51\u201358. DOI: https:\/\/doi.org\/10.1007\/s11416-014-0224-9.","journal-title":"Journal of Computer Virology and Hacking Techniques"},{"key":"5439_CR12","doi-asserted-by":"publisher","unstructured":"Bauman E, Ayoade G, Lin Z. A survey on hypervisor-based monitoring: Approaches, applications, and evolutions. ACM Computing Surveys (CSUR), 2015, 48(1): Article No. 10. DOI: https:\/\/doi.org\/10.1145\/2775111.","DOI":"10.1145\/2775111"},{"key":"5439_CR13","first-page":"2567","volume-title":"Proc. the 31st USENIX Security Symposium","author":"K Ji","year":"2022","unstructured":"Ji K, Zeng J, Jiang Y, Liang Z, Chua Z L, Saxena P, Roychoudhury A. FlowMatrix: GPU-assisted information-flow analysis through matrix-based representation. In Proc. the 31st USENIX Security Symposium, Aug. 2022, pp.2567\u20132584."},{"key":"5439_CR14","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620656","volume-title":"Proc. the 32nd USENIX Conference on Security Symposium","author":"B Cheng","year":"2023","unstructured":"Cheng B, Leal E A, Zhang H, Ming J. On the feasibility of malware unpacking via hardware-assisted loop profiling. In Proc. the 32nd USENIX Conference on Security Symposium, Aug. 2023, Article No. 419. DOI: https:\/\/doi.org\/10.5555\/3620237.3620656."},{"key":"5439_CR15","doi-asserted-by":"publisher","first-page":"164593","DOI":"10.1109\/ACCESS.2020.3021463","volume":"8","author":"J Pan","year":"2020","unstructured":"Pan J, Yi Z, Zhao X J, Sun B. Lightweight and efficient hypervisor-based dynamic binary instrumentation and analysis method. IEEE Access, 2020, 8: 164593\u2013164610. DOI: https:\/\/doi.org\/10.1109\/ACCESS.2020.3021463.","journal-title":"IEEE Access"},{"key":"5439_CR16","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620512","volume-title":"Proc. the 32nd USENIX Conference on Security Symposium","author":"L Stone","year":"2023","unstructured":"Stone L, Ranjan R, Nagy S, Hicks M. No linux, no problem: Fast and correct Windows binary fuzzing via target-embedded snapshotting. In Proc. the 32nd USENIX Conference on Security Symposium, Aug. 2023, Article No. 275. DOI: https:\/\/doi.org\/10.5555\/3620237.3620512."},{"key":"5439_CR17","doi-asserted-by":"publisher","first-page":"622","DOI":"10.1145\/3320269.3384764","volume-title":"Proc. the 15th ACM Asia Conference on Computer and Communications Security","author":"J Galea","year":"2020","unstructured":"Galea J, Kroening D. The taint rabbit: Optimizing generic taint analysis with dynamic fast path generation. In Proc. the 15th ACM Asia Conference on Computer and Communications Security, Oct. 2020, pp.622\u2013636. DOI: https:\/\/doi.org\/10.1145\/3320269.3384764."},{"key":"5439_CR18","doi-asserted-by":"publisher","first-page":"1841","DOI":"10.1145\/3650212.3685313","volume-title":"Proc. the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"E Sultanik","year":"2024","unstructured":"Sultanik E, Surovi\u010d M, Brodin H, Kaoudis K, Tuesca F, Harmon C, Overall L, Sweeney J, Larsen B. PolyTracker: Whole-input dynamic information flow tracing. In Proc. the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, Sept. 2024, pp.1841\u20131845. DOI: https:\/\/doi.org\/10.1145\/3650212.3685313."},{"key":"5439_CR19","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1145\/2151024.2151042","volume-title":"Proc. the 8th ACM SIGPLAN\/SIGOPS Conference on Virtual Execution Environments","author":"V P Kemerlis","year":"2012","unstructured":"Kemerlis V P, Portokalidis G, Jee K, Keromytis A D. libdft: Practical dynamic data flow tracking for commodity systems. In Proc. the 8th ACM SIGPLAN\/SIGOPS Conference on Virtual Execution Environments, Mar. 2012, pp.121\u2013132. DOI: https:\/\/doi.org\/10.1145\/2151024.2151042."},{"key":"5439_CR20","doi-asserted-by":"publisher","first-page":"490","DOI":"10.1109\/SP.2019.00043","volume-title":"Proc. the 2019 IEEE Symposium on Security and Privacy","author":"S Banerjee","year":"2019","unstructured":"Banerjee S, Devecsery D, Chen P M, Narayanasamy S. Iodine: Fast dynamic taint tracking using rollback-free optimistic hybrid analysis. In Proc. the 2019 IEEE Symposium on Security and Privacy, May 2019, pp.490\u2013504. DOI: https:\/\/doi.org\/10.1109\/SP.2019.00043."},{"key":"5439_CR21","doi-asserted-by":"publisher","first-page":"1919","DOI":"10.1109\/SP40001.2021.00082","volume-title":"Proc. the 2021 IEEE Symposium on Security and Privacy","author":"T Palit","year":"2021","unstructured":"Palit T, Moon J F, Monrose F, Polychronakis M. DynPTA: Combining static and dynamic analysis for practical selective data protection. In Proc. the 2021 IEEE Symposium on Security and Privacy, May 2021, pp.1919\u20131937. DOI: https:\/\/doi.org\/10.1109\/SP40001.2021.00082."},{"key":"5439_CR22","doi-asserted-by":"publisher","first-page":"932","DOI":"10.1109\/ICSE48619.2023.00086","volume-title":"Proc. the 45th IEEE\/ACM International Conference on Software Engineering","author":"C Wang","year":"2023","unstructured":"Wang C, Ko R, Zhang Y, Yang Y, Lin Z. Taintmini: Detecting flow of sensitive data in mini-programs with static taint analysis. In Proc. the 45th IEEE\/ACM International Conference on Software Engineering, May 2023, pp.932\u2013944. DOI: https:\/\/doi.org\/10.1109\/ICSE48619.2023.00086."},{"key":"5439_CR23","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1145\/2508859.2516704","volume-title":"Proc. the 2013 ACM SIGSAC Conference on Computer & Communications Security","author":"K Jee","year":"2013","unstructured":"Jee K, Kemerlis V P, Keromytis A D, Portokalidis G. ShadowReplica: Efficient parallelization of dynamic data flow tracking. In Proc. the 2013 ACM SIGSAC Conference on Computer & Communications Security, Nov. 2013, pp.235\u2013246. DOI: https:\/\/doi.org\/10.1145\/2508859.2516704."},{"key":"5439_CR24","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1145\/1455770.1455779","volume-title":"Proc. the 15th ACM Conference on Computer and Communications Security","author":"A Dinaburg","year":"2008","unstructured":"Dinaburg A, Royal P, Sharif M, Lee W. Ether: Malware analysis via hardware virtualization extensions. In Proc. the 15th ACM Conference on Computer and Communications Security, Oct. 2008, pp.51\u201362. DOI: https:\/\/doi.org\/10.1145\/1455770.1455779."},{"key":"5439_CR25","doi-asserted-by":"publisher","first-page":"1902","DOI":"10.1109\/SP40001.2021.00024","volume-title":"Proc. the 2021 IEEE Symposium on Security and Privacy","author":"J Hong","year":"2021","unstructured":"Hong J, Ding X. A novel dynamic analysis infrastructure to instrument untrusted execution flow across user-kernel spaces. In Proc. the 2021 IEEE Symposium on Security and Privacy, May 2021, pp.1902\u20131918. DOI: https:\/\/doi.org\/10.1109\/SP40001.2021.00024."},{"key":"5439_CR26","doi-asserted-by":"publisher","unstructured":"Chipounov V, Kuznetsov V, Candea G. The S2E platform: Design, implementation, and applications. ACM Trans. Computer Systems (TOCS), 2012, 30(1): Article No. 2. DOI: https:\/\/doi.org\/10.1145\/2110356.2110358.","DOI":"10.1145\/2110356.2110358"},{"key":"5439_CR27","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1145\/2731186.2731201","volume-title":"Proc. the 11th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments","author":"J Zeng","year":"2015","unstructured":"Zeng J, Fu Y, Lin Z. PEMU: A pin highly compatible out-of-VM dynamic binary instrumentation framework. In Proc. the 11th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, Mar. 2015, pp.147\u2013160. DOI: https:\/\/doi.org\/10.1145\/2731186.2731201."},{"key":"5439_CR28","doi-asserted-by":"publisher","first-page":"2009","DOI":"10.1145\/3576915.3623198","volume-title":"Proc. the 2023 ACM SIGSAC Conference on Computer and Communications Security","author":"P Pitigalaarachchi","year":"2023","unstructured":"Pitigalaarachchi P, Ding X, Qiu H, Tu H, Hong J, Jiang L. KRover: A symbolic execution engine for dynamic kernel analysis. In Proc. the 2023 ACM SIGSAC Conference on Computer and Communications Security, Nov. 2023, pp.2009\u20132023. DOI: https:\/\/doi.org\/10.1145\/3576915.3623198."},{"key":"5439_CR29","doi-asserted-by":"publisher","DOI":"10.1145\/2843859.2843867","volume-title":"Proc. the 5th Program Protection and Reverse Engineering Workshop","author":"B Dolan-Gavitt","year":"2015","unstructured":"Dolan-Gavitt B, Hodosh J, Hulin P, Leek T, Whelan R. Repeatable reverse engineering with PANDA. In Proc. the 5th Program Protection and Reverse Engineering Workshop, Dec. 2015, Article No. 4. DOI: https:\/\/doi.org\/10.1145\/2843859.2843867."},{"issue":"1","key":"5439_CR30","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1145\/1945023.1945039","volume":"45","author":"D Zhu","year":"2011","unstructured":"Zhu D, Jung J, Song D, Kohno T, Wetherall D. TaintEraser: Protecting sensitive data leaks using application-level taint tracking. ACM SIGOPS Operating Systems Review, 2011, 45(1): 142\u2013154. DOI: https:\/\/doi.org\/10.1145\/1945023.1945039.","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"5439_CR31","volume-title":"Proc. the 19th Annual Network and Distributed System Security Symposium","author":"K Jee","year":"2012","unstructured":"Jee K, Portokalidis G, Kemerlis V P, Ghosh S, August D I, Keromytis A D. A general approach for efficiently accelerating software-based dynamic data flow tracking on commodity hardware. In Proc. the 19th Annual Network and Distributed System Security Symposium, Feb. 2012."},{"key":"5439_CR32","doi-asserted-by":"publisher","first-page":"103528","DOI":"10.1016\/j.cose.2023.103528","volume":"135","author":"Z Jia","year":"2023","unstructured":"Jia Z, Yang C, Zhao X, Li X, Ma J. Design and implementation of an efficient container tag dynamic taint analysis. Computers & Security, 2023, 135: 103528. DOI: https:\/\/doi.org\/10.1016\/j.cose.2023.103528.","journal-title":"Computers & Security"},{"key":"5439_CR33","doi-asserted-by":"publisher","first-page":"380","DOI":"10.1145\/3545948.3545969","volume-title":"Proc. the 25th International Symposium on Research in Attacks, Intrusions and Defenses","author":"T Usui","year":"2022","unstructured":"Usui T, Otsuki Y, Kawakoya Y, Iwamura M, Matsuura K. Script tainting was doomed from the start (by type conversion): Converting script engines into dynamic taint analysis frameworks. In Proc. the 25th International Symposium on Research in Attacks, Intrusions and Defenses, Oct. 2022, pp.380\u2013394. DOI: https:\/\/doi.org\/10.1145\/3545948.3545969."},{"key":"5439_CR34","first-page":"1665","volume-title":"Proc. the 30th USENIX Security Symposium","author":"S Chen","year":"2021","unstructured":"Chen S, Lin Z, Zhang Y. SelectiveTaint: Efficient data flow tracking with static binary rewriting. In Proc. the 30th USENIX Security Symposium, Aug. 2021, pp.1665\u20131682."},{"key":"5439_CR35","doi-asserted-by":"publisher","first-page":"3998","DOI":"10.1109\/SP54263.2024.00045","volume-title":"Proc. the 2024 IEEE Symposium on Security and Privacy","author":"Q Sang","year":"2024","unstructured":"Sang Q, Wang Y, Liu Y, Jia X, Bao T, Su P. AirTaint: Making dynamic taint analysis faster and easier. In Proc. the 2024 IEEE Symposium on Security and Privacy, May 2024, pp.3998\u20134014. DOI: https:\/\/doi.org\/10.1109\/SP54263.2024.00045."}],"container-title":["Journal of Computer Science and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-026-5439-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11390-026-5439-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11390-026-5439-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T14:22:06Z","timestamp":1783520526000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11390-026-5439-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":35,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["5439"],"URL":"https:\/\/doi.org\/10.1007\/s11390-026-5439-y","relation":{},"ISSN":["1000-9000","1860-4749"],"issn-type":[{"value":"1000-9000","type":"print"},{"value":"1860-4749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]},"assertion":[{"value":"8 April 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Conflict of Interest\n                      The authors declare that they have no conflict of interest.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics"}}]}}