{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,12,29]],"date-time":"2022-12-29T05:18:22Z","timestamp":1672291102693},"reference-count":16,"publisher":"Association for Computing Machinery (ACM)","issue":"5","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGARCH Comput. Archit. News"],"published-print":{"date-parts":[[2005,12]]},"abstract":"<jats:p>\n            <jats:italic>Our<\/jats:italic>\n            Application Security Monitor\n            <jats:italic>(ASM) is a run-time monitor that dynamically collects execution-related data. ASM is part of a security framework that will allow us to explore different security policies aimed at identifying malicious behavior such as Trojan horses and backdoors<\/jats:italic>\n            .\n            <jats:italic>In this paper, we show what type of data ASM can collect and illustrate how this data can be used to enforce a security policy. Using ASM we are able to explore different tradeoffs between security and performance<\/jats:italic>\n            .\n          <\/jats:p>","DOI":"10.1145\/1127577.1127583","type":"journal-article","created":{"date-parts":[[2006,5,8]],"date-time":"2006-05-08T22:51:53Z","timestamp":1147128713000},"page":"21-26","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["ASM"],"prefix":"10.1145","volume":"33","author":[{"given":"Micha","family":"Moffie","sequence":"first","affiliation":[{"name":"Northeastern University, Boston, MA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Kaeli","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,12]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/288090.288102"},{"key":"e_1_2_1_3_1","first-page":"103","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Gao D.","year":"2004","unstructured":"D. Gao , M. K. Reiter , and D. Song . On gray-box program tracking for anomaly detection . In Proceedings of the 13th USENIX Security Symposium , pages 103 -- 118 , San Diego, CA, USA, Aug. 9--13 2004 . D. Gao, M. K. Reiter, and D. Song. On gray-box program tracking for anomaly detection. In Proceedings of the 13th USENIX Security Symposium, pages 103--118, San Diego, CA, USA, Aug. 9--13 2004."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the 6th Usenix Security Symposium","author":"Goldberg I.","year":"1996","unstructured":"I. Goldberg , D. Wagner , R. Thomas , and E. A. Brewer . A secure environment for untrusted helper applications (confining the wily hacker) . In Proceedings of the 6th Usenix Security Symposium , San Jose, CA, USA , 1996 . I. Goldberg, D. Wagner, R. Thomas, and E. A. Brewer. A secure environment for untrusted helper applications (confining the wily hacker). In Proceedings of the 6th Usenix Security Symposium, San Jose, CA, USA, 1996."},{"key":"e_1_2_1_5_1","unstructured":"LURHQ Threat Intelligence Group. Lurhq. http:\/\/www.lurhq.com\/phatbot.html.  LURHQ Threat Intelligence Group. Lurhq. http:\/\/www.lurhq.com\/phatbot.html."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720293"},{"key":"e_1_2_1_7_1","first-page":"145","volume-title":"Proceedings of the USENIX Security Conference","author":"Ko C.","year":"2000","unstructured":"C. Ko , T. Fraser , L. Badger , and D. Kilpatrick . Detecting and countering system intrusions using software wrappers . In Proceedings of the USENIX Security Conference , pages 145 -- 156 , Jan 2000 . C. Ko, T. Fraser, L. Badger, and D. Kilpatrick. Detecting and countering system intrusions using software wrappers. In Proceedings of the USENIX Security Conference, pages 145--156, Jan 2000."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.605929"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065034"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/292540.292561"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1071713.1071729"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/784592.784801"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1024393.1024404"},{"key":"e_1_2_1_14_1","unstructured":"United States Computer Emergency Readiness Team. Us-cert. http:\/\/www.us-cert.gov\/.  United States Computer Emergency Readiness Team. Us-cert. http:\/\/www.us-cert.gov\/."},{"key":"e_1_2_1_15_1","unstructured":"Carnegie Mellon University. Cert. http:\/\/www.cert.org\/.  Carnegie Mellon University. Cert. http:\/\/www.cert.org\/."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2004.31"}],"container-title":["ACM SIGARCH Computer Architecture News"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1127577.1127583","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T21:23:17Z","timestamp":1672262597000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1127577.1127583"}},"subtitle":["application security monitor"],"short-title":[],"issued":{"date-parts":[[2005,12]]},"references-count":16,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2005,12]]}},"alternative-id":["10.1145\/1127577.1127583"],"URL":"https:\/\/doi.org\/10.1145\/1127577.1127583","relation":{},"ISSN":["0163-5964"],"issn-type":[{"value":"0163-5964","type":"print"}],"subject":[],"published":{"date-parts":[[2005,12]]},"assertion":[{"value":"2005-12-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}