{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2023,2,10]],"date-time":"2023-02-10T12:00:26Z","timestamp":1676030426384},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2015,2,4]],"date-time":"2015-02-04T00:00:00Z","timestamp":1423008000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2016,2]]},"DOI":"10.1007\/s11416-015-0237-z","type":"journal-article","created":{"date-parts":[[2015,2,3]],"date-time":"2015-02-03T14:50:17Z","timestamp":1422975017000},"page":"23-36","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["U-HIPE: hypervisor-based protection of user-mode processes in Windows"],"prefix":"10.1007","volume":"12","author":[{"given":"Andrei","family":"Lu\u021ba\u0219","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrian","family":"Cole\u0219a","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S\u00e1ndor","family":"Luk\u00e1cs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Lu\u021ba\u0219","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,2,4]]},"reference":[{"key":"237_CR1","unstructured":"Bitdefender: Qhost Virus Description. http:\/\/www.bitdefender.com\/free-virus-removal\/#Trojan.Qhost.WU . Accessed 28 Jan 2015"},{"key":"237_CR2","unstructured":"Bitdefender: Sality Virus Description. http:\/\/www.bitdefender.com\/free-virus-removal\/#Win32.Sality.OG . Accessed 28 Jan 2015"},{"key":"237_CR3","unstructured":"Bitdefender: Virtob Virus Description. http:\/\/www.bitdefender.com\/free-virus-removal\/#Win32.Virtob.Gen . Accessed 28 Jan 2015"},{"key":"237_CR4","unstructured":"Bitdefender: Zbot Virus Description. http:\/\/www.bitdefender.com\/free-virus-removal\/#Trojan.Spy.ZBot.EHE . Accessed 28 Jan 2015"},{"key":"237_CR5","doi-asserted-by":"crossref","unstructured":"Chen, P.M., Noble, B.D.: When virtual is better than real. In: Proceedings of the Eighth Workshop on Hot Topics in Operating Systems, HOTOS \u201901. IEEE Computer Society, Washington, DC (2001)","DOI":"10.1109\/HOTOS.2001.990073"},{"issue":"2","key":"237_CR6","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1145\/1353535.1346284","volume":"42","author":"X Chen","year":"2008","unstructured":"Chen, X., Garfinkel, T., Lewis, E.C., Subrahmanyam, P., Waldspurger, C.A., Boneh, D., Dwoskin, J., Ports, D.R.K.: Overshadow: a virtualization-based approach to retrofitting protection in commodity operating systems. SIGOPS Oper. Syst. Rev. 42(2), 2\u201313 (2008)","journal-title":"SIGOPS Oper. Syst. Rev."},{"key":"237_CR7","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS \u201908, pp. 51\u201362. ACM, New York (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"237_CR8","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., Lee, W.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: IEEE Symposium on Security and Privacy (SP), pp. 297\u2013312. IEEE, New York (2011)","DOI":"10.1109\/SP.2011.11"},{"key":"237_CR9","doi-asserted-by":"crossref","unstructured":"Dunlap, G.W., King, S.T., Cinar, S., Basrai, M.A., Chen, P.M.: ReVirt: enabling intrusion analysis through virtual-machine logging and replay. SIGOPS Oper. Syst. Rev. 36(SI), 211\u2013224 (2002)","DOI":"10.1145\/844128.844148"},{"key":"237_CR10","doi-asserted-by":"crossref","unstructured":"Fu, Y., Lin, Z.: Space traveling across VM: automatically bridging the semantic gap in virtual machine introspection via online Kernel data redirection. In: Proceedings of the 2012 IEEE Symposium on Security and Privacy, SP \u201912, pp. 586\u2013600. IEEE Computer Society, Washington, DC (2012)","DOI":"10.1109\/SP.2012.40"},{"key":"237_CR11","doi-asserted-by":"crossref","unstructured":"Fu, Y., Lin, Z.: Bridging the semantic gap in virtual machine introspection via online Kernel data redirection. ACM Trans. Inf. Syst. Secur. 16(2) (2013)","DOI":"10.1145\/2516951.2505124"},{"key":"237_CR12","unstructured":"Garfinkel, T., Rosenblum, M.: A virtual machine introspection based architecture for intrusion detection. In: Proceedings of Network and Distributed Systems Security Symposium, pp. 191\u2013206 (2003)"},{"key":"237_CR13","doi-asserted-by":"crossref","unstructured":"Gavitt, B.D., Leek, T., Hodosh, J., Lee, W.: Tappan zee (north) bridge: mining memory accesses for introspection. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer and Communication Security, CCS \u201913, pp. 839\u2013850. ACM, New York (2013)","DOI":"10.1145\/2508859.2516697"},{"key":"237_CR14","doi-asserted-by":"crossref","unstructured":"Hizver, J., Chiueh, T.c.: Real-time deep virtual machine introspection and its applications. In: Proceedings of the 10th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE \u201914, pp. 3\u201314. ACM, New York (2014)","DOI":"10.1145\/2576195.2576196"},{"key":"237_CR15","doi-asserted-by":"publisher","unstructured":"Hofmann, O.S., Kim, S., Dunn, A.M., Lee, M.Z., Witchel, E.: InkTag: secure applications on an untrusted operating system. SIGPLAN Not. 48(4), 265\u2013278 (2013). doi: 10.1145\/2499368.2451146","DOI":"10.1145\/2499368.2451146"},{"key":"237_CR16","unstructured":"Intel Corporation: $$\\text{ Intel }^{\\textregistered }$$ Intel \u00ae 64 and IA-32 Architectures Software Developer\u2019s Manual. 325462\u2013050US (2014). http:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/manuals\/64-ia-32-architectures-software-developer-manual-325462.pdf . Accessed 02 Feb 2015"},{"key":"237_CR17","doi-asserted-by":"crossref","unstructured":"Jiang, X., Wang, X., Xu, D.: Stealthy malware detection and monitoring through VMM-based \u201cout-of-the-box\u201d semantic view reconstruction. ACM Trans. Inf. Syst. Secur. 13(2) (2010)","DOI":"10.1145\/1698750.1698752"},{"key":"237_CR18","unstructured":"Jones, S.T., Arpaci Dusseau, A.C., Arpaci Dusseau, R.H.: Antfarm: tracking processes in a virtual machine environment. In: Proceedings of the Annual Conference on USENIX \u201906 Annual Technical Conference, ATEC \u201906, pp. 1\u201314. USENIX Association, Berkeley (2006)"},{"key":"237_CR19","doi-asserted-by":"crossref","unstructured":"Jones, S.T., Arpaci Dusseau, A.C., Arpaci Dusseau, R.H.: Geiger: Monitoring the buffer cache in a virtual machine environment. SIGARCH Comput. Archit. News 34(5), 14\u201324 (2006)","DOI":"10.1145\/1168919.1168861"},{"key":"237_CR20","doi-asserted-by":"crossref","unstructured":"Jones, S.T., Arpaci Dusseau, A.C., Arpaci Dusseau, R.H.: VMM-based hidden process detection and identification using Lycosid. In: Proceedings of the fourth ACM SIGPLAN\/SIGOPS international conference on Virtual execution environments, VEE \u201908, pp. 91\u2013100. ACM, New York (2008)","DOI":"10.1145\/1346256.1346269"},{"key":"237_CR21","doi-asserted-by":"crossref","unstructured":"Joshi, A., King, S.T., Dunlap, G.W., Chen, P.M.: Detecting past and present intrusions through vulnerability-specific predicates. In: Proceedings of the Twentieth ACM Symposium on Operating Systems Principles, SOSP \u201905, pp. 91\u2013104. ACM, New York (2005)","DOI":"10.1145\/1095810.1095820"},{"key":"237_CR22","doi-asserted-by":"crossref","unstructured":"Lange, J.R., Dinda, P.: SymCall: Symbiotic virtualization through VMM-to-guest upcalls. In: Proceedings of the 7th ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE \u201911, vol. 46, pp. 193\u2013204. ACM, New York (2011)","DOI":"10.1145\/1952682.1952707"},{"key":"237_CR23","doi-asserted-by":"crossref","unstructured":"Laureano, M., Maziero, C., Jamhour, E.: Intrusion detection in virtual machine environments. In: Proceedings of the 30th EUROMICRO Conference, EUROMICRO \u201904, pp. 520\u2013525. IEEE Computer Society, Washington, DC (2004)","DOI":"10.1109\/EURMIC.2004.1333416"},{"key":"237_CR24","unstructured":"Litty, L., Cavilla, A.L., Lie, D.: Hypervisor support for identifying covertly executing binaries. In: Proceedings of the 17th Conference on Security Symposium, SS\u201908, pp. 243\u2013258. USENIX Association, Berkeley (2008)"},{"key":"237_CR25","doi-asserted-by":"crossref","unstructured":"Martignoni, L., Fattori, A., Paleari, R., Cavallaro, L.: Live and trustworthy forensic analysis of commodity production systems. In: Proceedings of the 13th International Conference on Recent Advances in Intrusion Detection, RAID\u201910, pp. 297\u2013316. Springer, Berlin (2010)","DOI":"10.1007\/978-3-642-15512-3_16"},{"key":"237_CR26","unstructured":"Microsoft: Win32\/Bagle. http:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?name=Win32%2fBagle . Accessed 19 Nov 2014"},{"key":"237_CR27","doi-asserted-by":"crossref","unstructured":"Payne, B.D., Carbone, M., Sharif, M., Lee, W.: Lares: An architecture for secure active monitoring using virtualization. In: Proceedings of the 2008 IEEE Symposium on Security and Privacy, SP \u201908, pp. 233\u2013247. IEEE Computer Society, Washington, DC (2008)","DOI":"10.1109\/SP.2008.24"},{"key":"237_CR28","doi-asserted-by":"crossref","unstructured":"Riley, R., Jiang, X., Xu, D.: Guest-transparent prevention of kernel rootkits with VMM-based memory shadowing. In: Proceedings of the 11th International Symposium on Recent Advances in Intrusion Detection, RAID \u201908, vol. 5230, pp. 1\u201320. Springer, Berlin (2008)","DOI":"10.1007\/978-3-540-87403-4_1"},{"key":"237_CR29","doi-asserted-by":"crossref","unstructured":"Roemer, R., Buchanan, E., Shacham, H., Savage, S.: Return-oriented programming: systems, languages, and applications. ACM Trans. Inf. Syst. Secur. 15(1) (2012)","DOI":"10.1145\/2133375.2133377"},{"key":"237_CR30","volume-title":"Windows Internals","author":"ME Russinovich","year":"2012","unstructured":"Russinovich, M.E., Solomon, D.A., Ionescu, A.: Windows Internals, 6th edn. Microsoft Press, USA (2012)","edition":"6"},{"key":"237_CR31","doi-asserted-by":"crossref","unstructured":"Seshadri, A., Luk, M., Qu, N., Perrig, A.: SecVisor: a tiny hypervisor to provide lifetime kernel code integrity for commodity OSes. In: Proceedings of Twenty-First ACM SIGOPS Symposium on Operating Systems Principles, SOSP \u201907, vol. 41, pp. 335\u2013350. ACM, New York (2007)","DOI":"10.1145\/1294261.1294294"},{"key":"237_CR32","unstructured":"Software, P.: AppTimer. Application Startup Timer. http:\/\/www.passmark.com\/products\/apptimer.htm . Accessed 28 Mar 2014"},{"key":"237_CR33","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Addison-Wesley, Boston (2005)"},{"key":"237_CR34","unstructured":"Vogl, S., Eckert, C.: Using hardware performance events for instruction-level monitoring on the x86 architecture. In: Proceedings of the 2012 European Workshop on System Security (EuroSec\u201912) (2012)"},{"key":"237_CR35","unstructured":"Vulnerabilities, C., Exposures: CVE-2010-3333. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2010-3333 . Accessed 07 Apr 2014"},{"key":"237_CR36","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X., Cui, W., Ning, P.: Countering kernel rootkits with lightweight hook protection. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, CCS \u201909, pp. 545\u2013554. ACM, New York (2009)","DOI":"10.1145\/1653662.1653728"},{"key":"237_CR37","unstructured":"Wojtczuk, R., Rutkowska, J.: Following the White Rabbit: Software Attacks Against Intel VT-d Technology (2011). http:\/\/invisiblethingslab.com\/resources\/2011\/Software%20Attacks%20on%20Intel%20VT-d.pdf . Accessed 02 Feb 2015"},{"issue":"7","key":"237_CR38","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1145\/2365864.2151053","volume":"47","author":"LK Yan","year":"2012","unstructured":"Yan, L.K., Jayachandra, M., Zhang, M., Yin, H.: V2E: combining hardware virtualization and software emulation for transparent and extensible malware analysis. SIGPLAN Not. 47(7), 227\u2013238 (2012)","journal-title":"SIGPLAN Not."},{"key":"237_CR39","doi-asserted-by":"crossref","unstructured":"Yang, J., Shin, K.G.: Using hypervisor to provide data secrecy for user applications on a per-page basis. In: Proceedings of the Fourth ACM SIGPLAN\/SIGOPS International Conference on Virtual Execution Environments, VEE \u201908, pp. 71\u201380. ACM, New York (2008)","DOI":"10.1145\/1346256.1346267"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-015-0237-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-015-0237-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-015-0237-z","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,20]],"date-time":"2019-08-20T15:21:50Z","timestamp":1566314510000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-015-0237-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,2,4]]},"references-count":39,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2016,2]]}},"alternative-id":["237"],"URL":"https:\/\/doi.org\/10.1007\/s11416-015-0237-z","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,2,4]]}}}