{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T12:52:35Z","timestamp":1781959955138,"version":"3.54.5"},"reference-count":27,"publisher":"Oxford University Press (OUP)","issue":"6","license":[{"start":{"date-parts":[[2026,1,27]],"date-time":"2026-01-27T00:00:00Z","timestamp":1769472000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,20]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The security of operating system has always been challenged by the hidden operation of rootkits. Based on virtual machine introspection technology, security tools are deployed outside the target virtual machine (TVM) that provides strict isolation between them and enhances the anti-interference of security tools. However, the current methods based on virtualization can only detect the hidden objects but cannot make them visible to TVM that leads to handling failure for host-based security tools. To solve this problem, this paper proposes a hidden object detection and recovery method RecObj based on virtualization technology. RecObj uses multidimensional semantic views cross-comparison to discover the hidden processes and files. By dynamically monitoring the change of logical relationship between loadable kernel modules and the change of their states, the hiding detection of rootkit itself can be realized. For processes and modules hidden by direct kernel object manipulation technology, RecObj uses memory writable mapping to restore hidden objects to be visible objects. Finally, the processing signal is transmitted to the hidden object manager in TVM through xenstore, and the cleanup operation to the hidden object is completed. The feasibility and effectiveness of RecObj is proved through the hiding detection, recovery, and processing experiments.<\/jats:p>","DOI":"10.1093\/comjnl\/bxag007","type":"journal-article","created":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T12:51:14Z","timestamp":1767963074000},"page":"1015-1026","source":"Crossref","is-referenced-by-count":0,"title":["RecObj: detection and recovery of hidden objects based on virtualization"],"prefix":"10.1093","volume":"69","author":[{"given":"Yun","family":"Wu","sequence":"first","affiliation":[{"name":"Institute of Intelligent Machines, Hefei Institutes of Physical Sciences, Chinese Academy of Sciences , 350 Shushanhu Road, Hefei 230031, Anhui ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Bao","sequence":"additional","affiliation":[{"name":"Institute of Systems Engineering, Academy of Military Sciences , No. 13 Dacheng Road, Fengtai District 100082, Beijing ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yonggang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology in CUMT , No. 1, Daxue Road, 221116, Xuzhou, Jiangsu ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guang","family":"Jin","sequence":"additional","affiliation":[{"name":"College of Systems Engineering, National University of Defense Technology , No. 137 Yanwachi Street, Changsha 410073, Hunan ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaoyuan","family":"Cui","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Machines, Hefei Institutes of Physical Sciences, Chinese Academy of Sciences , 350 Shushanhu Road, Hefei 230031, Anhui ,","place":["China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2026,1,27]]},"reference":[{"key":"2026062008164313600_ref1","doi-asserted-by":"publisher","first-page":"63","DOI":"10.5755\/j01.eee.104.8.9229","article-title":"Rootkit detection experiment within a virtual environment","volume":"104","author":"Toldinas","year":"2010","journal-title":"Elektron Elektrotech"},{"key":"2026062008164313600_ref2","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1007\/s00607-014-0433-6","article-title":"A hybrid artificial immune network for detecting communities in complex networks","volume":"97","author":"Karimi-Majd","year":"2015","journal-title":"Computing"},{"key":"2026062008164313600_ref3","doi-asserted-by":"publisher","first-page":"1225","DOI":"10.1109\/tc.2015.2439274","article-title":"MEMORY-based hardware architectures to detect ClamAV virus signatures with restricted regular expression features","volume":"65","author":"Or","year":"2016","journal-title":"IEEE Trans Comput"},{"key":"2026062008164313600_ref4","doi-asserted-by":"publisher","first-page":"485","DOI":"10.1109\/tcad.2015.2474374","article-title":"Reusing hardware performance counters to detect and identify kernel control-flow modifying rootkits","volume":"35","author":"Wang","year":"2016","journal-title":"IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"},{"key":"2026062008164313600_ref5","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1109\/tdsc.2015.2443803","article-title":"Detecting and preventing kernel rootkit attacks with bus snooping","volume":"14","author":"Moon","year":"2017","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"2026062008164313600_ref6","doi-asserted-by":"publisher","first-page":"1568","DOI":"10.1166\/asl.2017.8624","article-title":"Dual-mode kernel rootkit scan and recovery with process ID brute-force","volume":"23","author":"Choi","year":"2017","journal-title":"Adv Sci Lett"},{"key":"2026062008164313600_ref7","doi-asserted-by":"publisher","first-page":"24","DOI":"10.3969\/j.issn.1001-0505.2013.01.005","article-title":"Novel process-protecting method using camouflage techniques based on direct kernel object manipulation","volume":"43","author":"Lan","year":"2013","journal-title":"J South Med Univ"},{"key":"2026062008164313600_ref8","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1145\/3052973.3052999","article-title":"On the detection of kernel-level rootkits using hardware performance counters","volume-title":"ACM Asia Conference on Computer and Communications Security, Abu Dhabi United Arab, 2\u20136 April","author":"Singh","year":"2017"},{"key":"2026062008164313600_ref9","doi-asserted-by":"publisher","first-page":"3332","DOI":"10.1109\/tc.2016.2540634","article-title":"Hardware-based malware detection using low-level architectural features","volume":"65","author":"Ozsoy","year":"2016","journal-title":"IEEE Trans Comput"},{"key":"2026062008164313600_ref10","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1109\/mm.2016.86","article-title":"Monitoring and attestation of virtual machine security health in cloud computing","volume":"36","author":"Zhang","year":"2016","journal-title":"IEEE Micro"},{"key":"2026062008164313600_ref11","doi-asserted-by":"publisher","first-page":"5983","DOI":"10.1007\/s11277-017-4823-x","article-title":"Research on semantic gap problem of virtual machine","volume":"97","author":"Xu","year":"2017","journal-title":"Wirel Pers Commun"},{"key":"2026062008164313600_ref12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2516951.2505124","article-title":"Bridging the semantic gap in virtual machine introspection via online kernel data redirection","volume":"16","author":"Fu","year":"2013","journal-title":"ACM Trans Inf Syst Secur"},{"key":"2026062008164313600_ref13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13677-014-0016-2","article-title":"Virtual machine introspection: towards bridging the semantic gap","volume":"3","author":"More","year":"2014","journal-title":"J Cloud Comput"},{"key":"2026062008164313600_ref14","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1109\/IC2E.2014.82","article-title":"CloudVMI: virtual machine introspection as a cloud service","volume-title":"2014 IEEE International Conference on Cloud Engineering","author":"Baek","year":"2014"},{"key":"2026062008164313600_ref15","doi-asserted-by":"publisher","first-page":"S85","DOI":"10.1016\/j.diin.2014.05.016","article-title":"VMI-PL: a monitoring language for virtual platforms using virtual machine introspection","volume":"11","author":"Westphal","year":"2014","journal-title":"Digit Investig"},{"key":"2026062008164313600_ref16","doi-asserted-by":"publisher","article-title":"Kernel-level rootkit detection, prevention and behavior profiling: a taxonomy and survey","author":"Nadim","DOI":"10.48550\/arXiv.2304.00473"},{"key":"2026062008164313600_ref17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1698750.1698752","article-title":"Stealthy malware detection and monitoring through VMM-based \u201cout-of-the-box\u201d semantic view reconstruction","volume":"13","author":"Jiang","year":"2010","journal-title":"ACM Trans Inf Syst Secur (TISSEC)"},{"key":"2026062008164313600_ref18","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/ARES.2009.116","article-title":"Defeating dynamic data kernel rootkit attacks via VMM-based guest-transparent monitoring","volume-title":"International conference on availability, reliability and security","author":"Rhee","year":"2009"},{"key":"2026062008164313600_ref19","doi-asserted-by":"publisher","first-page":"1058","DOI":"10.1109\/IranianCEE.2014.6999692","article-title":"KLrtD: kernel level rootkit detection","volume-title":"2014 22nd Iranian Conference on Electrical Engineering (ICEE)","author":"Behrozinia","year":"2014"},{"key":"2026062008164313600_ref20","doi-asserted-by":"publisher","first-page":"545","DOI":"10.1145\/1653662.1653728","article-title":"Countering kernel rootkits with lightweight hook protection","volume-title":"Proceedings of the 16th ACM conference on computer and communications security","author":"Wang","year":"2009"},{"key":"2026062008164313600_ref21","doi-asserted-by":"publisher","first-page":"1404","DOI":"10.1109\/tifs.2011.2159712","article-title":"Comprehensive and efficient protection of kernel control data","volume":"6","author":"Li","year":"2011","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2026062008164313600_ref22","doi-asserted-by":"publisher","first-page":"1722","DOI":"10.3837\/tiis.2017.03.026","article-title":"Lightweight intrusion detection of rootkit with VMI-based driver separation mechanism","volume":"11","author":"Cui","year":"2017","journal-title":"KSII Trans Internet Inf Syst"},{"key":"2026062008164313600_ref23","doi-asserted-by":"publisher","first-page":"15845","DOI":"10.1109\/ACCESS.2019.2893627","article-title":"RMVP: a real-time method to monitor random processes of virtual machine","volume":"7","author":"Li","year":"2019","journal-title":"IEEE Access"},{"key":"2026062008164313600_ref24","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/297127","article-title":"TSMC: a novel approach for live virtual machine migration","author":"Song","journal-title":"J Appl Math"},{"key":"2026062008164313600_ref25","doi-asserted-by":"publisher","first-page":"1697","DOI":"10.16208\/j.issn1000-7024.2016.06.051","article-title":"Getting process content of guest OS based on VMI","volume":"37","author":"Li","year":"2016","journal-title":"Comput Eng Des"},{"key":"2026062008164313600_ref26"},{"key":"2026062008164313600_ref27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2775111","article-title":"A survey on hypervisor-based monitoring","volume":"48","author":"Bauman","year":"2015","journal-title":"ACM Computing Surveys (CSUR)"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/6\/1015\/66591756\/bxag007.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/69\/6\/1015\/66591756\/bxag007.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T12:16:51Z","timestamp":1781957811000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/69\/6\/1015\/8442428"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,27]]},"references-count":27,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,1,27]]},"published-print":{"date-parts":[[2026,6,20]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxag007","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2026,6]]},"published":{"date-parts":[[2026,1,27]]}}}