{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T02:48:23Z","timestamp":1768445303268,"version":"3.49.0"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,2,13]],"date-time":"2017-02-13T00:00:00Z","timestamp":1486944000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,5]]},"DOI":"10.1007\/s11416-017-0291-9","type":"journal-article","created":{"date-parts":[[2017,2,13]],"date-time":"2017-02-13T22:47:46Z","timestamp":1487026066000},"page":"107-126","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Anti-emulation trends in modern packers: a survey on the evolution of anti-emulation techniques in UPA packers"],"prefix":"10.1007","volume":"14","author":[{"given":"C\u0103t\u0103lin Valeriu","family":"Li\u0163\u0103","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8598-930X","authenticated-orcid":false,"given":"Doina","family":"Cosovan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Drago\u015f","family":"Gavrilu\u0163","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,2,13]]},"reference":[{"key":"291_CR1","volume-title":"Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-vm technologies","author":"RR Branco","year":"2012","unstructured":"Branco, R.R., Barbosa, G.N., Neto, P.N.: Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-vm technologies. Blackhat, Las Vegas (2012)"},{"key":"291_CR2","volume-title":"Covert debugging circumventing software armoring techniques","author":"D Quist","year":"2007","unstructured":"Quist, D., Smith, V.: Covert debugging circumventing software armoring techniques. Black Hat Briefings, Las Vegas (2007)"},{"issue":"4","key":"291_CR3","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1007\/s11416-012-0165-0","volume":"8","author":"A Issa","year":"2012","unstructured":"Issa, A.: Anti-virtual machines and emulations. J. Comput. Virol. 8(4), 141\u2013149 (2012). doi: 10.1007\/s11416-012-0165-0","journal-title":"J. Comput. Virol."},{"key":"291_CR4","unstructured":"Chubachi, Y., Aiko, K.: Tentacle: Environment-sensitive malware palpation"},{"key":"291_CR5","unstructured":"Ferrie, P.: Anti-unpacker tricks\u2013part one. Virus Bull. 4 (2008). http:\/\/www.virusbtn.com\/pdf\/magazine\/2008\/200812.pdf"},{"key":"291_CR6","unstructured":"Yason, M.V.: The art of unpacking (2007). Retrieved 12 Feb 2008"},{"key":"291_CR7","unstructured":"Tan, X.: Anti-unpacker tricks in malicious code. In: Proceedings of 10th Annual AVAR International Conference (2007)"},{"key":"291_CR8","unstructured":"Ferrie, P.: The ultimate anti-debugging reference, p 14. Tech. rep. (2011)"},{"key":"291_CR9","unstructured":"Falliere, N.: Windows anti-debug reference (2007). Retrieved 1 Oct 2007"},{"key":"291_CR10","doi-asserted-by":"crossref","unstructured":"Gao, S., Lin, Q., Xia, M., Yu, M., Qi, Z., Guan, H.: Debugging classification and anti-debugging strategies. In: Fourth International Conference on Machine Vision (ICMV 11), pp. 83503C\u201383503C. International Society for Optics and Photonics (2011)","DOI":"10.1117\/12.924835"},{"key":"291_CR11","unstructured":"Chen, X., Andersen, J., Mao, Z.\u00a0M., Bailey, M., Nazario, J.: Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware. In: The 38th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, DSN 2008, June 24\u201327, 2008, Anchorage, Alaska, USA, pp. 177\u2013186 (2008)"},{"key":"291_CR12","unstructured":"Shields, T.: Anti-debugging\u2013a developers view. Veracode Inc., USA (2010)"},{"issue":"5","key":"291_CR13","first-page":"813","volume":"28","author":"Z Qi","year":"2012","unstructured":"Qi, Z., Li, B., Lin, Q., Yu, M., Xia, Mingyuan, Guan, Haibing: SPAD: software protection through anti-debugging using hardware-assisted virtualization. J. Inf. Sci. Eng. 28(5), 813\u2013827 (2012)","journal-title":"J. Inf. Sci. Eng."},{"key":"291_CR14","doi-asserted-by":"crossref","unstructured":"Yi, T., Zong, A., Yu, M., Gao, S., Lin, Q., Yu, P., Ren, Z., Qi, Z.: Anti-debugging framework based on hardware virtualization technology. In: ICRCCS\u201909 International Conference on Research Challenges in Computer Science, IEEE, pp. 218\u2013220 (2009)","DOI":"10.1109\/ICRCCS.2009.63"},{"key":"291_CR15","doi-asserted-by":"crossref","unstructured":"Linn, C., Debray, S.K.: Obfuscation of executable code to improve resistance to static disassembly. In: Proceedings of the 10th ACM Conference on Computer and Communications Security, CCS 2003, ACM, Washington, DC, October 27\u201330, 2003, pp. 290\u2013299","DOI":"10.1145\/948109.948149"},{"issue":"1","key":"291_CR16","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/s11416-006-0011-3","volume":"2","author":"J Aycock","year":"2006","unstructured":"Aycock, J., deGraaf, R., Jacobson Jr., M.: Anti-disassembly using cryptographic hash functions. J. Comput. Virol. 2(1), 79\u201385 (2006)","journal-title":"J. Comput. Virol."},{"key":"291_CR17","unstructured":"Kr\u00fcgel, C., Robertson, W.K., Valeur, F., Vigna, G.: Static disassembly of obfuscated binaries. In: Proceedings of the 13th USENIX Security Symposium, August 9\u201313 2004, San Diego, CA, USA, pp. 255\u2013270 (2004)"},{"key":"291_CR18","unstructured":"Ferrie, P.: Attacks on virtual machine emulators. Symantec Adv. Threat Res. (2008)"},{"key":"291_CR19","unstructured":"Ferrie, P: Attacks on more virtual machine emulators. Symantec Technol. Exch. 55 (2007)"},{"key":"291_CR20","unstructured":"Ormandy, T.: An empirical study into the security exposure to hosts of hostile virtualized environments. 2007. Ce court article de recherche analyse la s\u00e9curit\u00e9 de quelques solutions de virtualisation, dont certaines trait\u00e9es dans mon m\u00e9moire. Lauteur analyse la robustesse et la r\u00e9silience des applications test\u00e9es (2007)"},{"key":"291_CR21","unstructured":"Reuben, J.S.: A survey on virtual machine security, vol. 2, p 36. Helsinki University of Technology. http:\/\/www.tml.tkk.fi\/Publications\/C\/25\/papers\/Reuben_final.pdf (2007)"},{"key":"291_CR22","unstructured":"Danny, Q., Smith, V.: Detecting the presence of virtual machines using the local data table. Offens. Comput. (2006)"},{"issue":"3","key":"291_CR23","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1007\/s11416-008-0096-y","volume":"6","author":"B Lau","year":"2010","unstructured":"Lau, B., Svajcer, V.: Measuring virtual machine detection in malware using DSD tracer. J. Comput. Virol. 6(3), 181\u2013195 (2010)","journal-title":"J. Comput. Virol."},{"key":"291_CR24","doi-asserted-by":"crossref","unstructured":"Raffetseder, T., Kr\u00fcgel, C., Kirda, E.: Detecting system emulators. In: Information Security, 10th International Conference, ISC 2007, Valpara\u00edso, Chile, October 9\u201312, pp. 1\u201318 (2007)","DOI":"10.1007\/978-3-540-75496-1_1"},{"key":"291_CR25","doi-asserted-by":"crossref","unstructured":"Kang, M.G., Yin, H., Hanna, S., McCamant, S., Song, D.: Emulating emulation-resistant malware. In: Proceedings of the 1st ACM workshop on Virtual machine security, pp. 11\u201322. ACM (2009)","DOI":"10.1145\/1655148.1655151"},{"key":"291_CR26","unstructured":"ODea, H.: The Modern Roguemalware with a Face. In: Proceedings of the Virus Bulletin Conference (2009)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0291-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0291-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0291-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,24]],"date-time":"2022-07-24T02:46:45Z","timestamp":1658630805000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0291-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,13]]},"references-count":26,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,5]]}},"alternative-id":["291"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0291-9","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,13]]}}}