{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T17:09:14Z","timestamp":1783184954282,"version":"3.54.6"},"reference-count":95,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSF","award":["CCF CCF2211750"],"award-info":[{"award-number":["CCF CCF2211750"]}]},{"name":"NSF","award":["CICI 2115075"],"award-info":[{"award-number":["CICI 2115075"]}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["FA8750-19C-0003"],"award-info":[{"award-number":["FA8750-19C-0003"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["N6600120C4020"],"award-info":[{"award-number":["N6600120C4020"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006602","name":"Air Force Research Laboratory","doi-asserted-by":"publisher","award":["FA8750-19-1-0501"],"award-info":[{"award-number":["FA8750-19-1-0501"]}],"id":[{"id":"10.13039\/100006602","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011419","name":"Santa Fe Institute","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100011419","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1109\/tdsc.2023.3346328","type":"journal-article","created":{"date-parts":[[2023,12,25]],"date-time":"2023-12-25T20:38:16Z","timestamp":1703536696000},"page":"4133-4146","source":"Crossref","is-referenced-by-count":5,"title":["Reducing Malware Analysis Overhead With Coverings"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8592-6758","authenticated-orcid":false,"given":"Michael","family":"Sandborn","sequence":"first","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zach","family":"Stoebner","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6749-2204","authenticated-orcid":false,"given":"Westley","family":"Weimer","sequence":"additional","affiliation":[{"name":"University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5904-1646","authenticated-orcid":false,"given":"Stephanie","family":"Forrest","sequence":"additional","affiliation":[{"name":"Arizona State University, Tempe, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1739-1127","authenticated-orcid":false,"given":"Ryan","family":"Dougherty","sequence":"additional","affiliation":[{"name":"United States Military Academy, West Point, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jules","family":"White","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4001-3442","authenticated-orcid":false,"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"It threat evolution Q1 2022","author":"Emm","year":"2022"},{"key":"ref2","article-title":"McAfee labs threat report: June 2021","year":"2021"},{"key":"ref3","article-title":"The threat report: Summer 2022","year":"2022"},{"key":"ref4","article-title":"X-force threat intelligence index 2022","year":"2022"},{"key":"ref5","article-title":"2022 threat review","year":"2022"},{"key":"ref6","article-title":"Sonicwall cyber threat report 2020","year":"2020"},{"key":"ref7","article-title":"Mastering 4 stages of malware analysis","author":"Zelster","year":"2015"},{"key":"ref8","volume-title":"Forensic Discover","author":"Farmer","year":"2005"},{"key":"ref9","author":"Distler","year":"2007","journal-title":"Malware Analysis: An Introduction"},{"key":"ref10","article-title":"Malware analysis: A systematic approach","author":"Wedum","year":"2008"},{"key":"ref11","article-title":"Vmware server","year":"2008"},{"key":"ref12","first-page":"164","article-title":"Xen and the art of virtualization","volume-title":"Proc. ACM Symp. Operating Syst. Princ.","author":"Dragovic"},{"key":"ref13","article-title":"VirtualBox","year":"2007"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1858996.1859085"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523675"},{"key":"ref17","article-title":"Volatility framework - Volatile memory extraction utility framework","author":"Auty","year":"2020"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315262"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.10.001"},{"key":"ref20","article-title":"The cuckoo sandbox","author":"Guarnieri","year":"2012"},{"key":"ref21","article-title":"Vmcloak","author":"Sick","year":"2020"},{"key":"ref22","article-title":"Evasive malware now a commodity","author":"Stefnisson","year":"2018"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630086"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23121"},{"key":"ref25","article-title":"Scientific but not academical overview of malware anti-debugging, anti-disassembly and anti-VM technologies","author":"Branco","year":"2012"},{"key":"ref26","article-title":"Windows anti-debug reference","author":"Falliere","year":"2010"},{"key":"ref27","article-title":"Detecting the presence of virtual machines using the local data table","author":"Quist","year":"2020"},{"key":"ref28","article-title":"Detect if your program is running inside a virtual machine","author":"Bachaalany","year":"2005"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-75496-1_1"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2015.11"},{"key":"ref31","first-page":"5","article-title":"Efficient detection of split personalities in malware","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Balzarotti"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-017-0290-x"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23265"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78813-5_26"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-75160-3_22"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93411-2_8"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.42"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SNPD.2012.87"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93411-2_8"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3150376.3150378"},{"key":"ref41","article-title":"Blue pill","author":"Rutkowska","year":"2006"},{"key":"ref44","article-title":"RLPack","year":"2020"},{"key":"ref45","first-page":"287","article-title":"Barecloud: Bare-metal analysis-based evasive malware detection","volume-title":"Proc. USENIX Secur. Symp.","author":"Kirat"},{"key":"ref46","article-title":"Mind the gap: On bridging the semantic gap between machine learning and information security","author":"Smith","year":"2020"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2017.02.013"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-011-0151-y"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2017.7952603"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.1601325"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3180445.3180449"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/6294058"},{"key":"ref54","article-title":"OllyDbg","author":"Yuschuk","year":"2002"},{"key":"ref55","article-title":"Ghidra: A software reverse engineering (SRE) suite","author":"Agency","year":"2019"},{"key":"ref56","article-title":"Cuckoo sandbox","author":"Guarnieri","year":"2011"},{"key":"ref57","article-title":"Paranoid fish","author":"Ortega","year":"2011"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/4235.996017"},{"key":"ref59","article-title":"Classifying malware images with convolutional neural network models","author":"Bensaoud","year":"2020"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ETCEA57049.2022.10009748"},{"key":"ref61","article-title":"Deep transfer learning for static malware classification","author":"Chen","year":"2018"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.5220\/0007701407190726"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2018.8328749"},{"key":"ref64","article-title":"Deep residual learning for image recognition","author":"He","year":"2015"},{"key":"ref65","article-title":"Aggregated residual transformations for deep neural networks","author":"Xie","year":"2016"},{"key":"ref66","doi-asserted-by":"crossref","DOI":"10.1109\/CVPR52688.2022.01167","article-title":"A convnet for the 2020s","author":"Liu","year":"2022"},{"key":"ref67","article-title":"Tune: A research platform for distributed model selection and training","author":"Liaw","year":"2018"},{"key":"ref68","first-page":"8","article-title":"Scalable, behavior-based malware clustering","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Bayer"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243771"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23226"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.45"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp.2016.36"},{"key":"ref73","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"Grosse","year":"2016"},{"key":"ref74","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.42"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630086"},{"key":"ref77","article-title":"Red pill","author":"Rutkowska","year":"2006"},{"key":"ref78","article-title":"Detecting the presence of virtual machines using the local data table","author":"Quist","year":"2006"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664250"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046740"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2016.30"},{"key":"ref83","article-title":"Slime: Automated anti-sandboxing disarmament system","author":"Chubachi","year":"2015"},{"key":"ref84","article-title":"Longitudinal study of the prevalence of malware evasive techniques","author":"Maffia","year":"2021"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89862-7_1"},{"key":"ref86","article-title":"Analyzing unknown binaries","year":"2009"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151053"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523675"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664252"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076790"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420980"},{"key":"ref92","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2019.102526","article-title":"The rise of machine learning for detection and classification of malware: Research developments, trends and challenges","volume":"153","author":"Gibert","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"issue":"1","key":"ref93","article-title":"Stealthy malware detection based on deep neural network","volume":"1437","author":"Lu","year":"2020","journal-title":"J. Phys.: Conf. Ser."},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.285"},{"issue":"11","key":"ref95","doi-asserted-by":"crossref","first-page":"5","DOI":"10.3390\/electronics9111777","article-title":"MALGRA: Machine learning and N-gram malware feature extraction and detection system","volume":"9","author":"Ali","year":"2020","journal-title":"Electronics"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1145\/3386263.3407585"},{"key":"ref97","article-title":"Learning to evade static pe machine learning malware models via reinforcement learning","author":"Anderson","year":"2018"},{"key":"ref98","article-title":"Merlin\u2013malware evasion with reinforcement learning","author":"Quertier","year":"2022"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/8858\/10592103\/10373111-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10592103\/10373111.pdf?arnumber=10373111","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,17]],"date-time":"2024-07-17T04:48:58Z","timestamp":1721191738000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10373111\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":95,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2023.3346328","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7]]}}}