{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T19:31:00Z","timestamp":1770751860009,"version":"3.50.0"},"reference-count":71,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,6,1]],"date-time":"2017-06-01T00:00:00Z","timestamp":1496275200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["NSF-CAREER-CNS-1453647"],"award-info":[{"award-number":["NSF-CAREER-CNS-1453647"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000015","name":"U.S. Department of Energy","doi-asserted-by":"publisher","award":["US DOE DE-OE0000779"],"award-info":[{"award-number":["US DOE DE-OE0000779"]}],"id":[{"id":"10.13039\/100000015","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["US NSF-REU-CNS-1461119"],"award-info":[{"award-number":["US NSF-REU-CNS-1461119"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Hardw Syst Secur"],"published-print":{"date-parts":[[2017,6]]},"DOI":"10.1007\/s41635-017-0013-2","type":"journal-article","created":{"date-parts":[[2017,9,21]],"date-time":"2017-09-21T16:06:21Z","timestamp":1506009981000},"page":"114-136","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":38,"title":["A Survey on Function and System Call Hooking Approaches"],"prefix":"10.1007","volume":"1","author":[{"given":"Juan","family":"Lopez","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7082-8423","authenticated-orcid":false,"given":"Leonardo","family":"Babun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hidayet","family":"Aksu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A. Selcuk","family":"Uluagac","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,9,21]]},"reference":[{"key":"13_CR1","unstructured":"API monitor. \n                    http:\/\/www.rohitab.com\/apimonitor\n                    \n                  . [Online; accessed 22-December-2016]"},{"key":"13_CR2","unstructured":"AppInit DLLs and secure boot. \n                    https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/dn280412(v=vs.85).aspx\n                    \n                  . [Online; acces- sed 20-December-2016]"},{"key":"13_CR3","unstructured":"BitBlaze: binary analysis for computer security. \n                    http:\/\/bitblaze.cs.berkeley.edu\/\n                    \n                  . [Online; accessed 25-June-2017]"},{"key":"13_CR4","unstructured":"Cydia substrate. \n                    http:\/\/www.cydiasubstrate.com\n                    \n                  . [Online; accessed 20-December-2016]"},{"key":"13_CR5","unstructured":"dlsym(3)\u2014linux man page. \n                    http:\/\/man7.org\/linux\/man-pages\/man3\/dlsym.3.html\n                    \n                  . [Online; accessed 16-December-2016]"},{"key":"13_CR6","unstructured":"dtruss(1m)\u2014Mac OS X man pages. \n                    https:\/\/developer.apple.com\/legacy\/library\/documentation\/Darwin\/Reference\/ManPages\/man1\/dtruss.1m.html\n                    \n                  . [Online; accessed 16-December-2016]"},{"key":"13_CR7","unstructured":"DYLD(1)\u2014Mac OS X man pages. \n                    https:\/\/developer.apple.com\/legacy\/library\/documentation\/Darwin\/Reference\/ManPages\/man1\/dyld.1.html\n                    \n                  . [Online; accessed 16-December-2016]"},{"key":"13_CR8","unstructured":"EasyHook. \n                    https:\/\/easyhook.github.io\n                    \n                  . [Online; accessed 22-December-2016]"},{"key":"13_CR9","unstructured":"Frida. \n                    https:\/\/www.frida.re\n                    \n                  . [Online; accessed 19-December-2016]"},{"key":"13_CR10","unstructured":"Instruments user guide. \n                    https:\/\/developer.apple.com\/library\/content\/documentation\/DeveloperTools\/Conceptual\/InstrumentsUserGuide\/\n                    \n                  . [Online; accessed 20-December-2016]"},{"key":"13_CR11","unstructured":"Introspy-Android. \n                    http:\/\/isecpartners.github.io\/Introspy-Android\/\n                    \n                  . [Online; accessed 19-December-2016]"},{"key":"13_CR12","unstructured":"ld.so(8)\u2014linux man page. \n                    http:\/\/man7.org\/linux\/man-pages\/man8\/ld.so.8.html\n                    \n                  . [Online; accessed 22-December-2016]"},{"key":"13_CR13","unstructured":"Microsoft detours. \n                    https:\/\/www.microsoft.com\/en-us\/research\/project\/detours\/\n                    \n                  . [Online; accessed 02-July-2017]"},{"key":"13_CR14","unstructured":"Nektra: advanced computing. \n                    http:\/\/www.nektra.com\/products\/spystudio-api-monitor\/\n                    \n                  . [Online; accessed 02-July-2017]"},{"key":"13_CR15","unstructured":"POSIX.1-2008 The pen Group Base Specifications Issue 7. \n                    http:\/\/pubs.opengroup.org\/onlinepubs\/9699919799\/\n                    \n                  . [Online; accessed 20-January-2017]"},{"key":"13_CR16","unstructured":"ptrace\u2014linux manual page. \n                    http:\/\/man7.org\/linux\/man-pages\/man2\/ptrace.2.html\n                    \n                  . [Online; accessed 14-December-2016]"},{"key":"13_CR17","unstructured":"SpyStudio Overview. \n                    http:\/\/www.nektra.com\/products\/spystudio-api-monitor\/\n                    \n                   \n                           \n                    http:\/\/www.nektra.com\/products\/spystudio-api-monitor\/\n                    \n                  . [Online; accessed 18-December-2016]"},{"key":"13_CR18","unstructured":"strace for android. \n                    https:\/\/github.com\/alireza7991?tab=repositories\n                    \n                  . [Online; accessed 20-December-2016]"},{"key":"13_CR19","unstructured":"Strace for NT. \n                    http:\/\/seriss.com\/people\/erco\/ftp\/winnt\/strace\/\n                    \n                  . [Online; accessed 10-January-2017]"},{"key":"13_CR20","unstructured":"strace(1)\u2014linux man page. \n                    https:\/\/linux.die.net\/man\/1\/strace\n                    \n                  . [Online; accessed 14-December-2016]"},{"key":"13_CR21","unstructured":"Theos\/setup. \n                    http:\/\/iphonedevwiki.net\/index.php\/Theos\/Setup\n                    \n                  . [Online; accessed 20-December-2016]"},{"key":"13_CR22","unstructured":"WinAPIOverride. \n                    http:\/\/jacquelin.potier.free.fr\/winapioverride32\/\n                    \n                  . [Online; accessed 18-December-2016]"},{"key":"13_CR23","unstructured":"Windows API index. \n                    https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ff818516(v=vs.85).aspx\n                    \n                  . [Online; accessed 20-January-2017]"},{"key":"13_CR24","unstructured":"Windows API index. \n                    https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ff818516(v=vs.85).aspx\n                    \n                  . [Online; accessed 02-July-2017]"},{"key":"13_CR25","unstructured":"Xcode 8. \n                    https:\/\/developer.apple.com\/xcode\/\n                    \n                  . [Online; accessed 20-December-2016]"},{"key":"13_CR26","unstructured":"Xposed module repository. \n                    http:\/\/repo.xposed.info\n                    \n                  . [Online; accessed 19-December-2016]"},{"issue":"4","key":"13_CR27","doi-asserted-by":"publisher","first-page":"166","DOI":"10.1016\/j.istr.2006.10.003","volume":"11","author":"AA Abimbola","year":"2006","unstructured":"Abimbola AA, Munoz JM, Buchanan WJ (2006) Nethost-sensor: monitoring a target host\u2019s application via system calls. Inf Secur Tech Rep 11(4):166\u2013175","journal-title":"Inf Secur Tech Rep"},{"key":"13_CR28","doi-asserted-by":"crossref","unstructured":"Andersson S, Clark A, Mohay G, Schatz B, Zimmermann J (2005) A framework for detecting network-based code injection attacks targeting Windows and UNIX. In: Proceedings of the 21st annual computer security applications conference, ACSAC \u201905. IEEE Computer Society, Washington, DC, USA, pp 49\u201358","DOI":"10.1109\/CSAC.2005.5"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Babun L, Aksu H, Uluagac AS (2017) Identifying counterfeit smart grid devices: a lightweight system level framework. In: 2017 international conference on communications (ICC)","DOI":"10.1109\/ICC.2017.7996877"},{"key":"13_CR30","doi-asserted-by":"crossref","unstructured":"Backes M, Gerling S, Hammer C, Maffei M, von Styp-Rekowsky P (2013) Appguard: enforcing user requirements on Android apps. In: Proceedings of the 19th international conference on tools and algorithms for the construction and analysis of systems, TACAS\u201913. Springer, Berlin, pp 543\u2013548","DOI":"10.1007\/978-3-642-36742-7_39"},{"key":"13_CR31","unstructured":"Bovet D, Cesati M (2005) Understanding the Linux kernel Oreilly & Associates Inc"},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Davis B, Chen H (2013) Retroskeleton: retrofitting Android apps. In: Proceeding of the 11th annual international conference on mobile systems, applications, and services, MobiSys \u201913. ACM, New York, pp 181\u2013192","DOI":"10.1145\/2462456.2464462"},{"key":"13_CR33","doi-asserted-by":"crossref","unstructured":"Eder T, Rodler M, Vymazal D, Zeilinger M (2013) ANANAS - A framework for analyzing android applications. In: 2013 eighth international conference on availability, reliability and security (ARES), pp 711\u2013719","DOI":"10.1109\/ARES.2013.93"},{"key":"13_CR34","unstructured":"Enck W, Octeau D, McDaniel P, Chaudhuri S (2011) A study of android application security. In: Proceedings of the 20th USENIX conference on security, SEC\u201911. USENIX Association, Berkeley, pp 21\u201321"},{"key":"13_CR35","unstructured":"Holy Father (2004) Hooking Windows API-Technics of hooking API functions on Windows. CodeBreakers-Journal, 1(2)"},{"key":"13_CR36","unstructured":"Garfinkel T (2003) Traps and pitfalls practical problems in system call interposition based security tools. In: Proceedings of network and distributed systems security symposium, pp 163\u2013176"},{"key":"13_CR37","volume-title":"DTrace: dynamic tracing in oracle Solaris, Mac OS X and freeBSD","author":"B Gregg","year":"2011","unstructured":"Gregg B, Mauro J (2011) DTrace: dynamic tracing in oracle Solaris, Mac OS X and freeBSD, 1st edn. Prentice Hall Press, Upper Saddle River","edition":"1st edn"},{"key":"13_CR38","unstructured":"Guo PJ, Engler D (2011) Using system call interposition to automatically create portable software packages. In: Proceedings of the 2011 USENIX conference on USENIX annual technical conference, USENIXATC\u201911. USENIX Association, Berkeley, pp 21\u201321"},{"key":"13_CR39","unstructured":"Hunt G, Brubacher D (1999) Detours: binary interception of Win32 functions. In: Proceedings of the 3rd conference on USENIX windows NT symposium - Volume 3, WINSYM\u201999. USENIX Association, Berkeley, pp 14\u201314"},{"key":"13_CR40","doi-asserted-by":"crossref","unstructured":"Jeong Y, Lee H, Cho S, Han S, Park M (2014) A kernel-based monitoring approach for analyzing malicious behavior on Android. In: Proceedings of the 29th annual ACM symposium on applied computing, SAC \u201914. ACM, New York, pp 1737\u20131738","DOI":"10.1145\/2554850.2559915"},{"key":"13_CR41","unstructured":"Keniston J, Mavinakayanahalli A, Panchamukhi P, Prasad V (2007) Ptrace, utrace, uprobes lightweight, dynamic tracing of user apps. In: Proceedings of the 2007 Linux symposium, pp 215\u2013224"},{"key":"13_CR42","unstructured":"Kim S-W (2012) Intercepting system API calls. \n                    https:\/\/software.intel.com\/en-us\/articles\/intercepting-system-api-calls\n                    \n                  . [Online; accessed 18-December-2016]"},{"key":"13_CR43","unstructured":"Kim T, Zeldovich N (2013) Practical and effective sandboxing for non-root users. In: Presented as part of the 2013 USENIX annual technical conference (USENIX ATC 13). USENIX, San Jose, pp 139\u2013144"},{"key":"13_CR44","doi-asserted-by":"crossref","unstructured":"Liu ST, Huang Hc, Chen YM (2011) A system call analysis method with mapreduce for malware detection. In: 2011 IEEE 17th international conference on parallel and distributed systems, pp 631\u2013637","DOI":"10.1109\/ICPADS.2011.17"},{"key":"13_CR45","unstructured":"Zhao F, Tan L, Zhang X (2012) Advanced operating and distributed system android and iOS platform study final report"},{"key":"13_CR46","volume-title":"Malware analyst\u2019s codebook and DVD: tools and techniques for fighting malicious code","author":"MH Ligh","year":"2011","unstructured":"Ligh MH, Adair S, Hartstein B, Richards M (2011) Malware analyst\u2019s codebook and DVD: tools and techniques for fighting malicious code. Wiley, New York"},{"key":"13_CR47","doi-asserted-by":"crossref","unstructured":"Madani P, Vlajic N (2016) Towards sequencing malicious system calls. In: 2016 IEEE conference on communications and network security (CNS), pp 376\u2013377","DOI":"10.1109\/CNS.2016.7860519"},{"key":"13_CR48","doi-asserted-by":"crossref","unstructured":"Marhusin MF, Larkin H, Lokan C, Cornforth D (2008) An evaluation of API calls hooking performance. In: Proceedings of the 2008 international conference on computational intelligence and security - volume 01, CIS \u201908. IEEE Computer Society, Washington, pp 315\u2013319","DOI":"10.1109\/CIS.2008.199"},{"key":"13_CR49","doi-asserted-by":"crossref","unstructured":"Mehdi B, Ahmed F, Khayyam SA, Farooq M (2010) Towards a theory of generalizing system call representation for in-execution malware detection. In: 2010 IEEE international conference on communications, pp 1\u20135","DOI":"10.1109\/ICC.2010.5501969"},{"key":"13_CR50","unstructured":"(2015). Microsoft. Visual studio, Microsoft portable executable and common object file format specification. Technical report, Microsoft"},{"key":"13_CR51","unstructured":"Myers DS, Bazinet AL (2004) Intercepting arbitrary functions on Windows, UNIX, and Macintosh OS X platforms. Technical report, Center for Bioinformatics and Computational Biology, Institute for Advanced Computer Studies University of Maryland"},{"key":"13_CR52","doi-asserted-by":"crossref","unstructured":"Qin F, Wang C, Li Z, Kim Hs, Zhou Y, Wu Y (2006) Lift: a low-overhead practical information flow tracking system for detecting security attacks. In: 2006 39th annual IEEE\/ACM international symposium on microarchitecture (MICRO\u201906), pp 135\u2013 148","DOI":"10.1109\/MICRO.2006.29"},{"key":"13_CR53","volume-title":"Windows via C\/C++","author":"JM Richter","year":"2007","unstructured":"Richter JM, Nasarre C (2007) Windows via C\/C++, 5th edn. Microsoft Press, USA","edition":"5th edn"},{"key":"13_CR54","unstructured":"Rubanov VV, Shatokhin EA (2011) Runtime verification of linux kernel modules based on call interception. In: 2011 fourth IEEE international conference on software testing, verification and validation, pp 180\u2013189"},{"key":"13_CR55","doi-asserted-by":"crossref","unstructured":"Russello G, Jimenez AB, Naderi H, van der Mark W (2013) FireDroid: hardening security in almost-stock android. In: Proceedings of the 29th annual computer security applications conference, ACSAC \u201913. ACM, New York, pp 319\u2013328","DOI":"10.1145\/2523649.2523678"},{"key":"13_CR56","volume-title":"Windows internals, Part 1: covering windows server 2008 R2 and Windows 7","author":"ME Russinovich","year":"2012","unstructured":"Russinovich ME, Solomon DA, Ionescu A (2012) Windows internals, Part 1: covering windows server 2008 R2 and Windows 7, 6th edition. Microsoft Press, USA","edition":"6th edition"},{"key":"13_CR57","doi-asserted-by":"crossref","unstructured":"Mohd Shaid SZ, Maarof MA (2015) In memory detection of Windows API call hooking technique. In: 2015 international conference on computer, communications, and control technology (i4CT), pp 294\u2013298","DOI":"10.1109\/I4CT.2015.7219584"},{"key":"13_CR58","volume-title":"Operating system concepts","author":"A Silberschatz","year":"2008","unstructured":"Silberschatz A, Galvin PB, Gagne G (2008) Operating system concepts, 8th edn. Wiley Publishing, New York","edition":"8th edn"},{"key":"13_CR59","doi-asserted-by":"crossref","unstructured":"Song D, Brumley D, Yin H, Caballero J, Jager I, Kang MG, Liang Z, Newsome J, Poosankam P, Saxena P (2008) BitBlaze: a new approach to computer security via binary analysis. In: Proceedings of the 4th international conference on information systems security. Keynote Invited paper., Hyderabad, India","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"13_CR60","doi-asserted-by":"crossref","unstructured":"Sun M, Zheng M, Lui JCS, Jiang X (2014) Design and implementation of an android host-based intrusion prevention system. In: Proceedings of the 30th annual computer security applications conference, ACSAC \u201914. ACM, New York, pp 226\u2013235","DOI":"10.1145\/2664243.2664245"},{"key":"13_CR61","unstructured":"Sze WK, Sekar R (2015) Provenance-based integrity protection for windows. In: Proceedings of the 31st annual computer security applications conference, ACSAC 2015. ACM, New York, pp 211\u2013220"},{"key":"13_CR62","doi-asserted-by":"crossref","unstructured":"Vogl S, Pfoh J, Kittel T, Eckert C (2014) Persistent data-only malware: function hooks without code. In: NDSS","DOI":"10.14722\/ndss.2014.23019"},{"key":"13_CR63","unstructured":"Wampler DR (2007) Methods for detecting Kernel Rootkits. PhD thesis, Louisville, KY, USA. AAI3293571"},{"issue":"2","key":"13_CR64","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems C, Holz T, Freiling F (2007) Toward automated dynamic malware analysis using CWSandbox. IEEE Secur Priv 5(2):32\u2013 39","journal-title":"IEEE Secur Priv"},{"key":"13_CR65","unstructured":"Wi\u00dffeld M, von Styp-Rekowsky P, Backes M Callee-side method hook injection on the new Android runtime ART"},{"issue":"6","key":"13_CR66","doi-asserted-by":"publisher","first-page":"1252","DOI":"10.1109\/TIFS.2016.2523912","volume":"11","author":"K Xu","year":"2016","unstructured":"Xu K, Li Y, Deng RH (2016) Iccdetector: Icc-based malware detection on android. IEEE Trans Inf Forensics Secur 11(6):1252\u20131264","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"13_CR67","unstructured":"Xu R, Sa\u00efdi H, Anderson R (2012) Aurasium: practical policy enforcement for android applications. In: Proceedings of the 21st USENIX conference on security symposium, Security\u201912. USENIX Association, Berkeley, pp 27\u201327"},{"key":"13_CR68","doi-asserted-by":"crossref","unstructured":"Ye Y, Wang D, Li T, Dongyi Y (2007) IMDS intelligent malware detection system. In: Proceedings of the 13th ACM SIGKDD international conference on knowledge discovery and data mining, KDD \u201907. ACM, New York, pp 1043\u20131047","DOI":"10.1145\/1281192.1281308"},{"key":"13_CR69","unstructured":"Yin H, Liang Z, Song D (2008) HookFinder: identifying and understanding malware hooking behaviors. In: Proceedings of the 15th annual network and distributed system security symposium (NDSS\u201908)"},{"key":"13_CR70","doi-asserted-by":"crossref","unstructured":"Yucheng G, Peng W, Juwei L, Qingping G (2011) A way to detect computer trojan based on DLL preemptive injection. In: 2011 tenth international symposium on distributed computing and applications to business, engineering and science (DCABES), pp 255\u2013258","DOI":"10.1109\/DCABES.2011.18"},{"key":"13_CR71","volume-title":"Hacking and securing iOS applications: stealing data, hijacking software, and how to prevent it","author":"J Zdziarski","year":"2012","unstructured":"Zdziarski J (2012) Hacking and securing iOS applications: stealing data, hijacking software, and how to prevent it. O\u2019Reilly Media, Inc., Sebastopol"}],"container-title":["Journal of Hardware and Systems Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s41635-017-0013-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-017-0013-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-017-0013-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,5,17]],"date-time":"2020-05-17T05:28:27Z","timestamp":1589693307000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s41635-017-0013-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,6]]},"references-count":71,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,6]]}},"alternative-id":["13"],"URL":"https:\/\/doi.org\/10.1007\/s41635-017-0013-2","relation":{},"ISSN":["2509-3428","2509-3436"],"issn-type":[{"value":"2509-3428","type":"print"},{"value":"2509-3436","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,6]]},"assertion":[{"value":"26 January 2017","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 August 2017","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 September 2017","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}