{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T14:23:33Z","timestamp":1768746213466,"version":"3.49.0"},"reference-count":66,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2018,3,1]],"date-time":"2018-03-01T00:00:00Z","timestamp":1519862400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2018,3,1]]},"DOI":"10.1109\/tdsc.2016.2545671","type":"journal-article","created":{"date-parts":[[2016,3,23]],"date-time":"2016-03-23T18:17:42Z","timestamp":1458757062000},"page":"321-335","source":"Crossref","is-referenced-by-count":9,"title":["Towards Transparent Debugging"],"prefix":"10.1109","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3365-2526","authenticated-orcid":false,"given":"Fengwei","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos","family":"Stavrou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haining","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"1","article-title":"Using\n CPU system management mode to circumvent operating system security functions","author":"duflot","year":"0","journal-title":"Proc 7th CanSecWest Conf"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420962"},{"key":"ref33","author":"rutkowska","year":"2008"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/1952682.1952696"},{"key":"ref31","year":"0"},{"key":"ref30","year":"0"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SADFE.2011.7"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2013.6575343"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866313"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.53"},{"key":"ref60","year":"0"},{"key":"ref62","author":"duflot","year":"0"},{"key":"ref61","article-title":"Getting into the SMRAM: SMM reloaded","author":"duflot","year":"0","journal-title":"Proc 12th CanSecWest Conf"},{"key":"ref63","author":"wojtczuk","year":"2014"},{"key":"ref28","first-page":"1","article-title":"nEther: In-guest\n detection of Out-of-the-guest malware analyzers","author":"pek","year":"0","journal-title":"Proc of the 4th European Workshop on System Security(EuroSec)"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516714"},{"key":"ref27","author":"rutkowska","year":"0"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046752"},{"key":"ref66","article-title":"Attacking intel trust execution technologies","author":"wojtczuk","year":"2009"},{"key":"ref29","first-page":"287","article-title":"BareCloud:\n Bare-metal Analysis-based evasive malware detection","author":"kirat","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref2","first-page":"289","article-title":"SPIDER:\n Stealthy binary program instrumentation and debugging via hardware virtualization","author":"deng","year":"0","journal-title":"Proc Comput Security Appl Conf"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.11"},{"key":"ref22","year":"0"},{"key":"ref21","year":"0"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2005.52"},{"key":"ref23","year":"0"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"ref25","year":"0"},{"key":"ref50","article-title":"Using hardware performance events for instruction-level monitoring on the x86 architecture","author":"vogl","year":"0","journal-title":"Proc 3rd Eur Workshop Syst Security"},{"key":"ref51","year":"0"},{"key":"ref59","year":"0"},{"key":"ref58","year":"0"},{"key":"ref57","year":"0"},{"key":"ref56","year":"0"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2013.6575349"},{"key":"ref54","year":"0"},{"key":"ref53","year":"2015"},{"key":"ref52","author":"wojtczuk","year":"2009"},{"key":"ref10","author":"quist","year":"0"},{"key":"ref11","year":"0"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1002\/sec.166"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-75496-1_1"},{"key":"ref13","first-page":"1","article-title":"Compatibility is not transparency: VMM\n detection myths and realities","author":"garfinkel","year":"0","journal-title":"Proc 11th Workshop Hot Topics in Operating Systems Usenix"},{"key":"ref14","first-page":"403","article-title":"BareBox:\n Efficient malware analysis on Bare-metal","author":"kirat","year":"0","journal-title":"Proc 27th Annu Comput Security Appl Conf"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420980"},{"key":"ref16","article-title":"CLOUDBURST: A VMware guest to host escape story","author":"kortchinsky","year":"0","journal-title":"Black Hat USA"},{"key":"ref17","article-title":"Xen 0wning Trilogy","author":"wojtczuk","year":"0","journal-title":"Black Hat USA"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.38"},{"key":"ref19","author":"rutkowska","year":"2006"},{"key":"ref4","author":"yan","year":"0","journal-title":"Proc 8th ACM SIGPLAN\/SIGOPS Conf Virtual Execution Environ"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859085"},{"key":"ref6","article-title":"Virt-ICE: Next-generation debugger for malware analysis","author":"quynh","year":"0","journal-title":"Black Hat USA"},{"key":"ref5","year":"0"},{"key":"ref8","article-title":"Scientific but not academical overview of malware anti-debugging, anti-disassembly and Anti-VM\n technologies","author":"branco","year":"0","journal-title":"Black Hat"},{"key":"ref7","first-page":"177","article-title":"Towards an understanding of Anti-Virtualization and Anti-Debugging\n behavior in modern malware","author":"chen","year":"0","journal-title":"Proc 38th Annu IEEE Int Conf Dependable Syst Netw"},{"key":"ref49","year":"0"},{"key":"ref9","author":"falliere","year":"2010"},{"key":"ref46","first-page":"191","article-title":"A virtual machine introspection based architecture for intrusion detection","author":"garfinkel","year":"0","journal-title":"Proc 10th Annu Netw Distrib Syst Security Symp"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.45"},{"key":"ref48","article-title":"VT8237R South Bridge, Revision 2.06","year":"2005"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"ref42","year":"0"},{"key":"ref41","article-title":"System management mode Hack: Using SMM for\n &#x2018;other purposes&#x2019;","author":"coideloko","year":"0","journal-title":"Phrack Mag"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11203-9_13"},{"key":"ref43","year":"2012"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/8314283\/07439809.pdf?arnumber=7439809","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:25:50Z","timestamp":1642004750000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7439809\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,3,1]]},"references-count":66,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2016.2545671","relation":{},"ISSN":["1545-5971"],"issn-type":[{"value":"1545-5971","type":"print"}],"subject":[],"published":{"date-parts":[[2018,3,1]]}}}