{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T08:50:11Z","timestamp":1725612611343},"reference-count":20,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,5]]},"DOI":"10.1109\/hst.2016.7495577","type":"proceedings-article","created":{"date-parts":[[2016,6,25]],"date-time":"2016-06-25T07:39:11Z","timestamp":1466840351000},"page":"167-172","source":"Crossref","is-referenced-by-count":9,"title":["Hardware-based workload forensics: Process reconstruction via TLB monitoring"],"prefix":"10.1109","author":[{"given":"Liwei","family":"Zhou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yiorgos","family":"Makris","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00026-2"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/604264.604269"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2484402.2484406"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.69"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866353"},{"key":"ref15","first-page":"1","article-title":"Antfarm: Tracking processes in a virtual machine environment","author":"jones","year":"2006","journal-title":"USENIX Annual Conference"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2003.1261391"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/2485922.2485970"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/1961189.1961199"},{"key":"ref19","first-page":"3","article-title":"Mibench: A free, commercially representative embedded benchmark suite","author":"guthaus","year":"2001","journal-title":"IEEE International Workshop on Workload Characterization"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1244002.1244070"},{"year":"2013","key":"ref3"},{"key":"ref6","first-page":"243","article-title":"Hypervisor support for identifying covertly executing binaries","author":"litty","year":"0","journal-title":"17th USENIX Security Symposium"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2012.2210217"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25141-2_7"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"year":"2013","key":"ref2"},{"key":"ref1","article-title":"Encase: A case study in computer-forensic technology","author":"garber","year":"2011","journal-title":"IEEE Computer Magazine"},{"key":"ref9","first-page":"351","article-title":"Effective and efficient mal ware detection at the end host","author":"kolbitsch","year":"2009","journal-title":"18th USENIX Security Symp"},{"journal-title":"Computer Organization and Design&#x2014 The Hardware\/Software Interface","year":"2009","author":"patterson","key":"ref20"}],"event":{"name":"2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","start":{"date-parts":[[2016,5,3]]},"location":"McLean, VA, USA","end":{"date-parts":[[2016,5,5]]}},"container-title":["2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/7489989\/7495545\/07495577.pdf?arnumber=7495577","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2016,9,29]],"date-time":"2016-09-29T09:03:24Z","timestamp":1475139804000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7495577\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5]]},"references-count":20,"URL":"https:\/\/doi.org\/10.1109\/hst.2016.7495577","relation":{},"subject":[],"published":{"date-parts":[[2016,5]]}}}