{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,28]],"date-time":"2025-10-28T18:30:31Z","timestamp":1761676231696,"version":"3.37.3"},"reference-count":36,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2015,9,1]],"date-time":"2015-09-01T00:00:00Z","timestamp":1441065600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["#1018217"],"award-info":[{"award-number":["#1018217"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["#1054605"],"award-info":[{"award-number":["#1054605"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000181","name":"AFOSR","doi-asserted-by":"publisher","award":["#FA9550-12-1-0077","#FA9550-14-1-0119"],"award-info":[{"award-number":["#FA9550-12-1-0077","#FA9550-14-1-0119"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100005139","name":"McAfee Inc","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100005139","id-type":"DOI","asserted-by":"publisher"}]},{"name":"VMware Inc."}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2015,9,1]]},"DOI":"10.1109\/tdsc.2014.2366464","type":"journal-article","created":{"date-parts":[[2014,10,31]],"date-time":"2014-10-31T18:49:32Z","timestamp":1414781372000},"page":"557-570","source":"Crossref","is-referenced-by-count":8,"title":["On the Trustworthiness of Memory Analysis\u2014An Empirical Study from the Perspective of Binary Execution"],"prefix":"10.1109","volume":"12","author":[{"given":"Aravind","family":"Prakash","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eknath","family":"Venkataramani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Heng","family":"Yin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.29"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653729"},{"key":"ref31","first-page":"103","article-title":"Automated detection of persistent kernel control-flow attacks","author":"nick","year":"0","journal-title":"Proc 14th ACM Conf Comput Commun Security"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.19"},{"key":"ref36","first-page":"311","article-title":"Enforcing system-wide control flow integrity for exploit detection and diagnosis","author":"prakash","year":"0","journal-title":"Proc 8th ACM SIGSAC Symp Inf Comput Commun Security"},{"key":"ref35","first-page":"1","article-title":"Guest-transparent prevention of kernel rootkits with VMM-based memory shadowing","author":"riley","year":"0","journal-title":"Proc 11th Int?l Symp Recent Advances in Intrusion Detection"},{"key":"ref34","first-page":"243","article-title":"Hypervisor support for identifying covertly executing binaries","author":"litty","year":"0","journal-title":"Proc 17th USENIX Security Symp"},{"article-title":"Siggraph: Brute force scanning of kernel data structure instances using graph-based signatures","year":"2011","author":"lin","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.28"},{"year":"0","author":"golovanov","key":"ref12"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2013.6575344"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2610384.2610407"},{"key":"ref15","first-page":"196","article-title":"Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software","author":"newsome","year":"0","journal-title":"Proc 12th Annu Netw Distrib Syst Security Symp"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/93542.93576"},{"key":"ref17","first-page":"151","article-title":"Automated whitebox fuzz testing","author":"godfroid","year":"0","journal-title":"Proc 10th Annu Netw Distrib Syst Security Symp"},{"year":"0","author":"russinovich","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.27"},{"key":"ref4","first-page":"116","article-title":"Panorama: Capturing system-wide information flow for malware detection and analysis","author":"yin","year":"0","journal-title":"Proc 14th ACM Conf Comput Commun Security"},{"article-title":"Howard: A dynamic excavator for reverse engineering data structures","year":"2011","author":"slowinska","key":"ref27"},{"key":"ref3","first-page":"128","article-title":"Stealthy malware detection through VMM-based &#x2018;out-of-the-box&#x2019; semantic view reconstruction","author":"jiang","year":"0","journal-title":"Proc 14th ACM Conf Comput Commun Security"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046751"},{"key":"ref29","first-page":"13","article-title":"Copilot - A coprocessor-based kernel runtime integrity monitor","author":"petroni","year":"0","journal-title":"Proc 13th Usenix Security Symp"},{"key":"ref5","first-page":"191","article-title":"A virtual machine introspection based architecture for intrusion detection","author":"garfinkel","year":"0","journal-title":"Proc Symp Network and Distributed System Security"},{"year":"2005","key":"ref8"},{"key":"ref7","first-page":"133","article-title":"When virtual is better than real","author":"chen","year":"0","journal-title":"Proc 8th IEEE Workshop on Hot Topics in Operating Systems"},{"year":"0","key":"ref2"},{"key":"ref9","first-page":"566","article-title":"Robust signatures for kernel data structures","author":"dolan","year":"0","journal-title":"Proc ACM Conf Comput Commun Security"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.10.001"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.40"},{"key":"ref22","first-page":"317","article-title":"Polyglot: Automatic extraction of protocol message format using dynamic binary analysis","author":"caballero","year":"0","journal-title":"Proc 14th ACM Conf Comput Commun Security"},{"key":"ref21","first-page":"586","article-title":"Understanding data lifetime via whole system simulation","author":"chow","year":"0","journal-title":"Proc 13th Usenix Security Symp"},{"key":"ref24","article-title":"Automatic protocol format reverse engineering through context-aware monitored execution","author":"lin","year":"0","journal-title":"Proc 10th Annu Netw Distrib Syst Security Symp"},{"key":"ref23","first-page":"1","article-title":"Automatic network protocol analysis","author":"wondracek","year":"0","journal-title":"Proc 10th Annu Netw Distrib Syst Security Symp"},{"key":"ref26","first-page":"251","article-title":"Tie: Principled reverse engineering of types in binary programs","author":"lee","year":"0","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref25","article-title":"Automatic reverse engineering of data structures from binary execution","author":"lin","year":"0","journal-title":"Proc 17th Annu Netw Distrib Syst Security Symp"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/7240136\/06942280.pdf?arnumber=6942280","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T15:59:53Z","timestamp":1642003193000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6942280\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,9,1]]},"references-count":36,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2014.2366464","relation":{},"ISSN":["1545-5971"],"issn-type":[{"type":"print","value":"1545-5971"}],"subject":[],"published":{"date-parts":[[2015,9,1]]}}}