{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T18:54:17Z","timestamp":1768416857875,"version":"3.49.0"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,2,8]],"date-time":"2017-02-08T00:00:00Z","timestamp":1486512000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"name":"Japan Society for the Promotion of Science (JP)","award":["26330080"],"award-info":[{"award-number":["26330080"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,2]]},"DOI":"10.1007\/s11416-017-0290-x","type":"journal-article","created":{"date-parts":[[2017,2,8]],"date-time":"2017-02-08T06:20:50Z","timestamp":1486534850000},"page":"69-85","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":28,"title":["Trends of anti-analysis operations of malwares observed in API call logs"],"prefix":"10.1007","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9406-5037","authenticated-orcid":false,"given":"Yoshihiro","family":"Oyama","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,2,8]]},"reference":[{"key":"290_CR1","unstructured":"VENOM vulnerability. CVE-2015-3456 (2015)"},{"key":"290_CR2","unstructured":"Symantec: Internet Security Threat Report, vol. 21 (2016)"},{"issue":"5","key":"290_CR3","first-page":"579","volume":"23","author":"M Hatada","year":"2015","unstructured":"Hatada, M., Akiyama, M., Matsuki, T., Kasama, T.: Empowering anti-malware research in Japan by sharing the MWS datasets. J. Inf. Process. 23(5), 579\u2013588 (2015)","journal-title":"J. Inf. Process."},{"key":"290_CR4","unstructured":"Takata, Y., Terada, M., Murakami, J., Kasama, T., Yoshioka, K., Hatada, M.: Datasets for anti-malware research $$\\sim $$ \u223c MWS datasets 2016 $$\\sim $$ \u223c . In: IPSJ SIG Technical Report, vol. 2016-CSEC-74 (2016)"},{"key":"290_CR5","unstructured":"Garfinkel, T., Adams, K., Warfield, A., Franklin, J.: Compatibility is not transparency: VMM detection myths and realities. In: Proceedings of the 11th Workshop on Hot Topics in Operating Systems (2007)"},{"key":"290_CR6","doi-asserted-by":"crossref","unstructured":"Raffetseder, T., Kruegel, C., Kirda, E.: Detecting system emulators. In: Proceedings of the 10th Information Security Conference, pp. 1\u201318 (2007)","DOI":"10.1007\/978-3-540-75496-1_1"},{"key":"290_CR7","doi-asserted-by":"crossref","unstructured":"Chen, P., Huygens, C., Desmet, L., Joosen, W.: Advanced or not? A comparative study of the use of anti-debugging and anti-VM techniques in generic and targeted malware. In: Proceedings of the 31st IFIP International Conference on ICT Systems Security and Privacy Protection, pp. 323\u2013336 (2016)","DOI":"10.1007\/978-3-319-33630-5_22"},{"key":"290_CR8","doi-asserted-by":"crossref","unstructured":"Kirat, D., Vigna, G.: MalGene: Automatic extraction of malware analysis evasion signature. In: Proceedings of the 22nd ACM Conference on Computer and Communications Security, pp. 769\u2013780 (2015)","DOI":"10.1145\/2810103.2813642"},{"key":"290_CR9","unstructured":"Kirat, D., Vigna, G., Kruegel, C.: BareCloud: Bare-metal analysis-based evasive malware detection. In: Proceedings of the 23rd USENIX Security Symposium, pp. 287\u2013301 (2014)"},{"key":"290_CR10","unstructured":"Branco, R.R., Barbosa, G.N., Neto, P.D.: Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-VM technologies. Black Hat USA 2012 (2012)"},{"key":"290_CR11","unstructured":"Chubachi, Y., Aiko, K.: SLIME: Automated anti-sandboxing disarmament system. Black Hat Asia 2015 (2015)"},{"key":"290_CR12","unstructured":"Barbosa, G.N., Branco, R.R.: Prevalent characteristics in modern malware. Black Hat USA 2014 (2014)"},{"issue":"1","key":"290_CR13","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1007\/s11416-014-0224-9","volume":"11","author":"O Ferrand","year":"2015","unstructured":"Ferrand, O.: How to detect the Cuckoo Sandbox and to strengthen it? J. Comput. Virol. Hacking Tech. 11(1), 51\u201358 (2015)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"290_CR14","unstructured":"Chen, X., Andersen, J., Mao, Z.M., Bailey, M., Nazario, J.: Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware. In: Proceedings of the 38th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 177\u2013186 (2008)"},{"key":"290_CR15","unstructured":"Wang, G., Estrada, Z.J., Pham, C., Kalbarczyk, Z., Iyer, R.K.: Hypervisor introspection: A technique for evading passive virtual machine monitoring. In: Proceedings of the 9th USENIX Workshop on Offensive Technologies (2015)"},{"key":"290_CR16","unstructured":"Shi, H., Alwabel, A., Mirkovic, J.: Cardinal pill testing of system virtual machines. In: Proceedings of the 23rd USENIX Security Symposium, pp. 271\u2013285 (2014)"},{"key":"290_CR17","doi-asserted-by":"crossref","unstructured":"P\u00e9k, G., Bencs\u00e1th, B., Butty\u00e1n, L.: nEther: In-guest detection of out-of-the-guest malware analyzers. In: Proceedings of the 4th European Workshop on System Security (2011)","DOI":"10.1145\/1972551.1972554"},{"key":"290_CR18","unstructured":"Balzarotti, D., Cova, M., Karlberger, C., Kruegel, C., Kirda, E., Vigna, G.: Efficient detection of split personalities in malware. In: Proceedings of the 17th Annual Network and Distributed System Security Symposium (2010)"},{"key":"290_CR19","unstructured":"Blackthorne, J., Bulazel, A., Fasano, A., Biernat, P., Yener, B.: AVLeak: Fingerprinting antivirus emulators through black-box testing. In: Proceedings of the 10th USENIX Workshop on Offensive Technologies (2016)"},{"key":"290_CR20","doi-asserted-by":"crossref","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: Malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, pp. 51\u201362 (2008)","DOI":"10.1145\/1455770.1455779"},{"key":"290_CR21","doi-asserted-by":"crossref","unstructured":"Kang, M.G., Yin, H., Hanna, S., McCamant, S., Song, D.: Emulating emulation-resistant malware. In: Proceedings of the 2nd ACM Workshop on Virtual Machine Security, pp. 11\u201322 (2009)","DOI":"10.1145\/1655148.1655151"},{"key":"290_CR22","doi-asserted-by":"crossref","unstructured":"Lengyel, T.K., Maresca, S., Payne, B.D., Webster, G.D., Vogl, S., Kiayias, A.: Scalability, fidelity and stealth in the DRAKVUF dynamic malware analysis system. In: Proceedings of the 30th Annual Computer Security Applications Conference, pp. 386\u2013395 (2014)","DOI":"10.1145\/2664243.2664252"},{"key":"290_CR23","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Kolbitsch, C., Comparetti, P.M.: Detecting environment-sensitive malware. In: Proceedings of the 14th International Symposium on Recent Advances in Intrusion Detection, pp. 338\u2013357 (2011)","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"290_CR24","doi-asserted-by":"crossref","unstructured":"Nguyen, A.M., Schear, N., Jung, H., Godiyal, A., King, S.T., Nguyen, H.D.: MAVMM: Lightweight and purpose built VMM for malware analysis. In: Proceedings of the 2009 Annual Computer Security Applications Conference, pp. 441\u2013450 (2009)","DOI":"10.1109\/ACSAC.2009.48"},{"key":"290_CR25","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1007\/978-94-007-6818-5_21","volume":"247","author":"Y Otsuki","year":"2013","unstructured":"Otsuki, Y., Takimoto, E., Kashiyama, T., Saito, S., Cooper, E.W., Mouri, K.: Tracing malicious injected threads using Alkanet malware analyzer. IAENG Trans. Eng. Technol. 247, 283\u2013299 (2013)","journal-title":"IAENG Trans. Eng. Technol."},{"issue":"2","key":"290_CR26","first-page":"132","volume":"23","author":"Y Oyama","year":"2015","unstructured":"Oyama, Y., Kawasaki, Y., Takahashi, K.: Checkpointing an operating system using a parapass-through hypervisor. J. Inf. Process. 23(2), 132\u2013141 (2015)","journal-title":"J. Inf. Process."},{"key":"290_CR27","doi-asserted-by":"crossref","unstructured":"Pekta\u015f, A., Acarman, T.: A dynamic malware analyzer against virtual machine aware malicious software. Secur. Commun. Netw. 7(12), 2245\u20132257 (2014)","DOI":"10.1002\/sec.931"},{"key":"290_CR28","doi-asserted-by":"crossref","unstructured":"Spensky, C., Hu, H., Leach, K.: LO-PHI: low-observable physical host instrumentation for malware analysis. In: Proceedings of the 23rd Annual Network and Distributed System Security Symposium (2016)","DOI":"10.14722\/ndss.2016.23121"},{"key":"290_CR29","doi-asserted-by":"crossref","unstructured":"Wang, G., Liu, C., Lin, J.: Transparency and semantics coexist: When malware analysis meets the hardware assisted virtualization. In: Proceedings of the International Standard Conference on Trustworthy Distributed Computing and Services, pp. 29\u201337 (2013)","DOI":"10.1007\/978-3-662-43908-1_4"},{"key":"290_CR30","doi-asserted-by":"crossref","unstructured":"Zhang, F., Leach, K., Stavrou, A., Wang, H., Sun, K.: Using hardware features for increased debugging transparency. In: Proceedings of the 36th IEEE Symposium on Security and Privacy, pp. 55\u201369 (2015)","DOI":"10.1109\/SP.2015.11"},{"key":"290_CR31","unstructured":"Singh, A., Bu, Z.: Hot Knives Through Butter: Evading File-Based Sandboxes. Tech. rep, FireEye (2014)"},{"key":"290_CR32","doi-asserted-by":"crossref","unstructured":"Brengel, M., Backes, M., Rossow, C.: Detecting hardware-assisted virtualization. In: Proceedings of the 13th International Conference on Detection of Intrusions and Malware and Vulnerability Assessment, pp. 207\u2013227 (2016)","DOI":"10.1007\/978-3-319-40667-1_11"},{"key":"290_CR33","unstructured":"Cuckoo Sandbox: https:\/\/cuckoosandbox.org\/"},{"key":"290_CR34","unstructured":"OPSWAT: Windows Anti-malware Market Share Reports. https:\/\/www.metadefender.com\/stats\/anti-malware-market-share-report#!\/ (2016)"},{"key":"290_CR35","unstructured":"Wyke, J.: Duping the machine\u2014malware strategies, post sandbox detection. In: Proceedings of the 24th Virus Bulletin International Conference, pp. 91\u201397 (2014)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0290-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0290-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0290-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,18]],"date-time":"2019-09-18T08:07:27Z","timestamp":1568794047000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0290-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,8]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,2]]}},"alternative-id":["290"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0290-x","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,8]]}}}