{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:29:39Z","timestamp":1780961379221,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2005,10,20]],"date-time":"2005-10-20T00:00:00Z","timestamp":1129766400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2005,10,20]]},"DOI":"10.1145\/1095810.1095825","type":"proceedings-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T12:34:39Z","timestamp":1131366879000},"page":"148-162","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":126,"title":["Scalability, fidelity, and containment in the potemkin virtual honeyfarm"],"prefix":"10.1145","author":[{"given":"Michael","family":"Vrable","sequence":"first","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Justin","family":"Ma","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jay","family":"Chen","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Moore","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Erik","family":"Vandekieft","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alex C.","family":"Snoeren","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Geoffrey M.","family":"Voelker","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Stefan","family":"Savage","sequence":"additional","affiliation":[{"name":"University of California, San Diego, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2005,10,20]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05)","author":"Bailey M.","year":"2005","unstructured":"M. Bailey , E. Cooke , F. Jahanian , J. Nazario , and D. Watson . The Internet Motion Sensor: A Distributed Blackhole Monitoring System . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05) , San Diego, CA , Feb. 2005 .]] M. Bailey, E. Cooke, F. Jahanian, J. Nazario, and D. Watson. The Internet Motion Sensor: A Distributed Blackhole Monitoring System. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05), San Diego, CA, Feb. 2005.]]"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251086.1251107"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095820"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the Winter Usenix Conference","author":"Cheswick B.","year":"1992","unstructured":"B. Cheswick . An Evening with Berferd In Which a Cracker is Lured, Endured, and Studied . In Proceedings of the Winter Usenix Conference , San Francisco, CA , 1992 .]] B. Cheswick. An Evening with Berferd In Which a Cracker is Lured, Endured, and Studied. In Proceedings of the Winter Usenix Conference, San Francisco, CA, 1992.]]"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251203.1251223"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095824"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_3"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029625"},{"key":"e_1_3_2_1_10_1","volume-title":"RFC 2784 - Generic Routing Encapsulation (GRE). RFC","author":"Farinacci D.","year":"2000","unstructured":"D. Farinacci , T. Li , S. Hanks , D. Meyer , and P. Traina . RFC 2784 - Generic Routing Encapsulation (GRE). RFC 2784, Mar. 2000 .]] D. Farinacci, T. Li, S. Hanks, D. Meyer, and P. Traina. RFC 2784 - Generic Routing Encapsulation (GRE). RFC 2784, Mar. 2000.]]"},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS '03)","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel and M. Rosenblum . A Virtual Machine Introspection Based Architecture for Intrusion Detection . In Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS '03) , San Diego, CA , Feb. 2003 .]] T. Garfinkel and M. Rosenblum. A Virtual Machine Introspection Based Architecture for Intrusion Detection. In Proceedings of the 10th Annual Network and Distributed System Security Symposium (NDSS '03), San Diego, CA, Feb. 2003.]]"},{"key":"e_1_3_2_1_12_1","volume-title":"Know Your Enemy: Learning about Security Threats. Pearson Education","author":"Project Honeynet","year":"2004","unstructured":"Honeynet Project . Know Your Enemy: Learning about Security Threats. Pearson Education , Inc., Boston, MA , second edition, 2004 .]] Honeynet Project. Know Your Enemy: Learning about Security Threats. Pearson Education, Inc., Boston, MA, second edition, 2004.]]"},{"key":"e_1_3_2_1_13_1","unstructured":"Honeynet Project. Know Your Enemy: Tracking Botnets. http:\/\/www.honeynet.org\/papers\/bots\/ Mar. 2005.]]  Honeynet Project. Know Your Enemy: Tracking Botnets. http:\/\/www.honeynet.org\/papers\/bots\/ Mar. 2005.]]"},{"key":"e_1_3_2_1_14_1","unstructured":"Intel. Virtualization Technology. http:\/\/www.intel.com\/technology\/computing\/vptech\/.]]  Intel. Virtualization Technology. http:\/\/www.intel.com\/technology\/computing\/vptech\/.]]"},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Jiang X.","year":"2004","unstructured":"X. Jiang and D. Xu . Collapsar: A VM-Based Architecture for Network Attack Detention Center . In Proceedings of the USENIX Security Symposium , San Diego, CA , Aug. 2004 .]] X. Jiang and D. Xu. Collapsar: A VM-Based Architecture for Network Attack Detention Center. In Proceedings of the USENIX Security Symposium, San Diego, CA, Aug. 2004.]]"},{"key":"e_1_3_2_1_16_1","volume-title":"Distributed Worm Signature Detection. In Proceedings of the USENIX Security Symposium","author":"Kim H.-A.","year":"2004","unstructured":"H.-A. Kim and B. Karp . Autograph: Toward Automated , Distributed Worm Signature Detection. In Proceedings of the USENIX Security Symposium , San Diego, CA , Aug. 2004 .]] H.-A. Kim and B. Karp. Autograph: Toward Automated, Distributed Worm Signature Detection. In Proceedings of the USENIX Security Symposium, San Diego, CA, Aug. 2004.]]"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/354871.354874"},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 2nd ACM Workshop on Hot Topics in Networks (HotNets-II)","author":"Kreibich C.","year":"2003","unstructured":"C. Kreibich and J. Crowcroft . Honeycomb -- Creating Intrusion Detection Signatures Using Honeypots . In Proceedings of the 2nd ACM Workshop on Hot Topics in Networks (HotNets-II) , Cambridge, MA , Nov. 2003 .]] C. Kreibich and J. Crowcroft. Honeycomb -- Creating Intrusion Detection Signatures Using Honeypots. In Proceedings of the 2nd ACM Workshop on Hot Topics in Networks (HotNets-II), Cambridge, MA, Nov. 2003.]]"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2000.832535"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1219056"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/637201.637244"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251327.1251329"},{"key":"e_1_3_2_1_24_1","unstructured":"C. Nachenberg. From AntiVirus to AntiWorm: A New Strategy for A New Threat Landscape. Invited talk at 2004 ACM Worm http:\/\/www.icir.org\/vern\/worm04\/carey.ppt.]]  C. Nachenberg. From AntiVirus to AntiWorm: A New Strategy for A New Threat Landscape. Invited talk at 2004 ACM Worm http:\/\/www.icir.org\/vern\/worm04\/carey.ppt.]]"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05)","author":"Newsome J.","year":"2005","unstructured":"J. Newsome and D. Song . Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05) , San Diego, CA , Feb. 2005 .]] J. Newsome and D. Song. Dynamic Taint Analysis for Automatic Detection, Analysis, and Signature Generation of Exploits on Commodity Software. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05), San Diego, CA, Feb. 2005.]]"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028788.1028794"},{"key":"e_1_3_2_1_27_1","volume-title":"Virtual Honeypot Framework. In Proceedings of the USENIX Security Symposium","author":"Provos N.","year":"2004","unstructured":"N. Provos . A Virtual Honeypot Framework. In Proceedings of the USENIX Security Symposium , San Diego, CA , Aug. 2004 .]] N. Provos. A Virtual Honeypot Framework. In Proceedings of the USENIX Security Symposium, San Diego, CA, Aug. 2004.]]"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/948187.948201"},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 6th ACM\/USENIX Symposium on Operating System Design and Implementation (OSDI)","author":"Singh S.","year":"2004","unstructured":"S. Singh , C. Estan , G. Varghese , and S. Savage . Automated Worm Fingerprinting . In Proceedings of the 6th ACM\/USENIX Symposium on Operating System Design and Implementation (OSDI) , San Francisco, CA , Dec. 2004 .]] S. Singh, C. Estan, G. Varghese, and S. Savage. Automated Worm Fingerprinting. In Proceedings of the 6th ACM\/USENIX Symposium on Operating System Design and Implementation (OSDI), San Francisco, CA, Dec. 2004.]]"},{"key":"e_1_3_2_1_31_1","volume-title":"The Cuckoo's Egg","author":"Stoll C.","year":"1990","unstructured":"C. Stoll . The Cuckoo's Egg . Pocket Books , New York, NY , 1990 .]] C. Stoll. The Cuckoo's Egg. Pocket Books, New York, NY, 1990.]]"},{"key":"e_1_3_2_1_32_1","unstructured":"Symantec. Decoy Server Product Sheet. http:\/\/www.symantec.com\/.]]  Symantec. Decoy Server Product Sheet. http:\/\/www.symantec.com\/.]]"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05)","author":"Venkataraman S.","year":"2005","unstructured":"S. Venkataraman , D. Song , P. Gibbons , and A. Blum . New Streaming Algorithms for Superspreader Detection . In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05) , San Diego, CA , Feb. 2005 .]] S. Venkataraman, D. Song, P. Gibbons, and A. Blum. New Streaming Algorithms for Superspreader Detection. In Proceedings of the 12th Annual Network and Distributed System Security Symposium (NDSS '05), San Diego, CA, Feb. 2005.]]"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060289.1060307"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 10th USENIX Workshop on Hot Topics in Operating Systems (HotOS-X)","author":"Warfield A.","year":"2005","unstructured":"A. Warfield , R. Ross , K. Fraser , C. Limpach , and S. Hand . Parallax: Managing Storage for a Million Machines . In Proceedings of the 10th USENIX Workshop on Hot Topics in Operating Systems (HotOS-X) , Santa Fe, NM , June 2005 .]] A. Warfield, R. Ross, K. Fraser, C. Limpach, and S. Hand. Parallax: Managing Storage for a Million Machines. In Proceedings of the 10th USENIX Workshop on Hot Topics in Operating Systems (HotOS-X), Santa Fe, NM, June 2005.]]"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Weaver N.","year":"2004","unstructured":"N. Weaver , S. Staniford , and V. Paxson . Very Fast Containment of Scanning Worms . In Proceedings of the USENIX Security Symposium , San Diego, CA , Aug. 2004 .]] N. Weaver, S. Staniford, and V. Paxson. Very Fast Containment of Scanning Worms. In Proceedings of the USENIX Security Symposium, San Diego, CA, Aug. 2004.]]"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060289.1060308"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029618.1029621"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_8"}],"event":{"name":"SOSP05: ACM SIGOPS 20th Symposium on Operating Systems Principles 2005","location":"Brighton United Kingdom","acronym":"SOSP05","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the twentieth ACM symposium on Operating systems principles"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1095810.1095825","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1095810.1095825","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:08:27Z","timestamp":1750248507000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1095810.1095825"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,10,20]]},"references-count":37,"alternative-id":["10.1145\/1095810.1095825","10.1145\/1095810"],"URL":"https:\/\/doi.org\/10.1145\/1095810.1095825","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/1095809.1095825","asserted-by":"object"}]},"subject":[],"published":{"date-parts":[[2005,10,20]]},"assertion":[{"value":"2005-10-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}