{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T18:56:22Z","timestamp":1768416982832,"version":"3.49.0"},"reference-count":15,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T00:00:00Z","timestamp":1567296000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T00:00:00Z","timestamp":1567296000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,9,1]],"date-time":"2019-09-01T00:00:00Z","timestamp":1567296000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Secur. Privacy"],"published-print":{"date-parts":[[2019,9]]},"DOI":"10.1109\/msec.2019.2910218","type":"journal-article","created":{"date-parts":[[2019,5,8]],"date-time":"2019-05-08T00:52:47Z","timestamp":1557276767000},"page":"58-67","source":"Crossref","is-referenced-by-count":12,"title":["Hypervisor-Based White Listing of Executables"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0905-3913","authenticated-orcid":false,"given":"Roee S.","family":"Leon","sequence":"first","affiliation":[{"name":"University of Jyvaskyla, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Kiperberg","sequence":"additional","affiliation":[{"name":"Holon Institute of Technology, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anat Anatey","family":"Leon Zabag","sequence":"additional","affiliation":[{"name":"Holon Institute of Technology, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amit","family":"Resh","sequence":"additional","affiliation":[{"name":"Design and Art, Shenkar College of Engineering, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Asaf","family":"Algawi","sequence":"additional","affiliation":[{"name":"University of Jyvaskyla, Finland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nezer J.","family":"Zaidenberg","sequence":"additional","affiliation":[{"name":"The College of Management Studies, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","author":"larabel","year":"0","journal-title":"Phoronix test suite"},{"key":"ref12","year":"2017","journal-title":"Unified extensible firmware interface (UEFI) specification version 2 7 errata A"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23156"},{"key":"ref14","author":"pappas","year":"2012","journal-title":"Kbouncer Efficient and Transparent Rop Mitigation"},{"key":"ref11","year":"2007","journal-title":"Intel 64 and IA-32 architectures software developer's manual"},{"key":"ref10","author":"kotadia","year":"2004","journal-title":"Norton AntiVirus ignores malicious WMI instructions"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.5121\/ijcseit.2012.2502"},{"key":"ref1","author":"idika","year":"2007","journal-title":"A Survey of Malware Detection Techniques"},{"key":"ref8","author":"whitehouse","year":"2013","journal-title":"Bypassing Windows AppLocker using a time of check time of use vulnerability"},{"key":"ref7","author":"beechey","year":"0","journal-title":"Application Whitelisting Panacea or Propaganda"},{"key":"ref9","article-title":"Subverting Windows 7 x64 kernel with DMA attacks","author":"damien","year":"0","journal-title":"Proc HITBSecConf"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36084-0_4"},{"key":"ref3","first-page":"32","article-title":"Hamsa: Fast signature generation for zero-day polymorphic worms with provable attack resilience","author":"li","year":"0","journal-title":"Proc IEEE Symp Security and Privacy (S&P"},{"key":"ref6","author":"fanton","year":"2017","journal-title":"Secure system for allowing the execution of authorized computer program code"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(09)70085-6"}],"container-title":["IEEE Security &amp; Privacy"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8013\/8821441\/08708283.pdf?arnumber=8708283","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,27]],"date-time":"2023-04-27T22:23:47Z","timestamp":1682634227000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8708283\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,9]]},"references-count":15,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/msec.2019.2910218","relation":{},"ISSN":["1540-7993","1558-4046"],"issn-type":[{"value":"1540-7993","type":"print"},{"value":"1558-4046","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,9]]}}}