{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T04:47:22Z","timestamp":1755838042533,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":26,"publisher":"ACM","license":[{"start":{"date-parts":[[2006,6,14]],"date-time":"2006-06-14T00:00:00Z","timestamp":1150243200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2006,6,14]]},"DOI":"10.1145\/1134760.1134765","type":"proceedings-article","created":{"date-parts":[[2006,7,24]],"date-time":"2006-07-24T16:53:01Z","timestamp":1153759981000},"page":"13-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Using VMM-based sensors to monitor honeypots"],"prefix":"10.1145","author":[{"given":"Kurniadi","family":"Asrigo","sequence":"first","affiliation":[{"name":"University of Toronto"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lionel","family":"Litty","sequence":"additional","affiliation":[{"name":"University of Toronto"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Lie","sequence":"additional","affiliation":[{"name":"University of Toronto"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2006,6,14]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945462"},{"key":"e_1_3_2_1_2_1","volume-title":"Syngress","author":"Caswell B.","year":"2003","unstructured":"B. Caswell , J. Beale , J. C. Foster , and J. Faircloth . Snort 2.0 Intrusion Detection . Syngress , Feb. 2003 . B. Caswell, J. Beale, J. C. Foster, and J. Faircloth. Snort 2.0 Intrusion Detection. Syngress, Feb. 2003."},{"key":"e_1_3_2_1_3_1","first-page":"63","volume-title":"Proceedings of the 7th USENIX Security Symposium","author":"Cowan C.","year":"1998","unstructured":"C. Cowan , C. Pu , D. Maier , J. Walpole , P. Bakke , S. Beattie , A. Grier , P. Wagle , Q. Zhang , and H. Hinton . StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks . In Proceedings of the 7th USENIX Security Symposium , pages 63 -- 78 , Jan. 1998 . C. Cowan, C. Pu, D. Maier, J. Walpole, P. Bakke, S. Beattie, A. Grier, P. Wagle, Q. Zhang, and H. Hinton. StackGuard: Automatic adaptive detection and prevention of buffer-overflow attacks. In Proceedings of the 7th USENIX Security Symposium, pages 63--78, Jan. 1998."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30143-1_3"},{"key":"e_1_3_2_1_5_1","first-page":"63","volume-title":"Proceedings of the 2000 Linux Showcase and Conference","author":"Dike J.","year":"2000","unstructured":"J. Dike . A user-mode port of the Linux kernel . In Proceedings of the 2000 Linux Showcase and Conference , pages 63 -- 72 , Oct. 2000 . J. Dike. A user-mode port of the Linux kernel. In Proceedings of the 2000 Linux Showcase and Conference, pages 63--72, Oct. 2000."},{"key":"e_1_3_2_1_6_1","volume-title":"UML as a honeypot","author":"Dike J.","year":"2005","unstructured":"J. Dike . UML as a honeypot , 2005 . http:\/\/user-mode-linux.sourceforge.net\/honeypots.html. J. Dike. UML as a honeypot, 2005. http:\/\/user-mode-linux.sourceforge.net\/honeypots.html."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060289.1060309"},{"key":"e_1_3_2_1_8_1","first-page":"163","volume-title":"Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel . Traps and pitfalls: Practical problems in system call interposition based security tools . In Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003 ), pages 163 -- 157 , February 2003 . T. Garfinkel. Traps and pitfalls: Practical problems in system call interposition based security tools. In Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003), pages 163--157, February 2003."},{"key":"e_1_3_2_1_9_1","first-page":"191","volume-title":"Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003","author":"Garfinkel T.","year":"2003","unstructured":"T. Garfinkel and M. Rosenblum . A virtual machine introspection based architecture for intrusion detection . In Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003 ), pages 191 -- 206 , Feb. 2003 . T. Garfinkel and M. Rosenblum. A virtual machine introspection based architecture for intrusion detection. In Proceedings of the 10th Annual Symposium on Network and Distributed System Security (NDSS 2003), pages 191--206, Feb. 2003."},{"issue":"55","key":"e_1_3_2_1_11_1","volume":"9","author":"Hoglund G.","unstructured":"G. Hoglund . A REAL NT rootkit. Phrack Magazine , 9 ( 55 ), 1999. http:\/\/www.phrack.org\/phrack\/55\/P55-05. G. Hoglund. A REAL NT rootkit. Phrack Magazine, 9(55), 1999. http:\/\/www.phrack.org\/phrack\/55\/P55-05.","journal-title":"Phrack Magazine"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1991.130768"},{"key":"e_1_3_2_1_13_1","first-page":"15","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Jiang X.","year":"2004","unstructured":"X. Jiang and D. Xu . Collapsar: A VM-based architecture for network attack detention center . In Proceedings of the 13th USENIX Security Symposium , pages 15 -- 28 , Aug. 2004 . X. Jiang and D. Xu. Collapsar: A VM-based architecture for network attack detention center. In Proceedings of the 13th USENIX Security Symposium, pages 15--28, Aug. 2004."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095820"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2005.18"},{"key":"e_1_3_2_1_16_1","volume-title":"Dionaea: On the automatic collection of malicious code samples through honey pot farms","author":"Levy E.","year":"2005","unstructured":"E. Levy . Dionaea: On the automatic collection of malicious code samples through honey pot farms , 2005 . Invited talk at the CASCON 2005 Workshop on Cybersecurity . E. Levy. Dionaea: On the automatic collection of malicious code samples through honey pot farms, 2005. Invited talk at the CASCON 2005 Workshop on Cybersecurity."},{"key":"e_1_3_2_1_17_1","volume-title":"Private conversation","author":"Levy E.","year":"2005","unstructured":"E. Levy . Private conversation , 2005 . Symantec Corp . E. Levy. Private conversation, 2005. Symantec Corp."},{"key":"e_1_3_2_1_18_1","unstructured":"LIDS Toolkit 2005. http:\/\/www.lids.org.  LIDS Toolkit 2005. http:\/\/www.lids.org."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/647054.715771"},{"key":"e_1_3_2_1_20_1","unstructured":"Metasploit 2005. http:\/\/www.metasploit.com.  Metasploit 2005. http:\/\/www.metasploit.com."},{"key":"e_1_3_2_1_21_1","first-page":"179","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Petroni N. L.","year":"2004","unstructured":"N. L. Petroni Jr ., T. Fraser , J. Molina , and W. A. Arbaugh . Copilot--a coprocessor-based kernel runtime integrity monitor . In Proceedings of the 13th USENIX Security Symposium , pages 179 -- 194 , Aug. 2004 . N. L. Petroni Jr., T. Fraser, J. Molina, and W. A. Arbaugh. Copilot--a coprocessor-based kernel runtime integrity monitor. In Proceedings of the 13th USENIX Security Symposium, pages 179--194, Aug. 2004."},{"key":"e_1_3_2_1_22_1","first-page":"1","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Provos N.","year":"2004","unstructured":"N. Provos . A virtual honeypot framework . In Proceedings of the 13th USENIX Security Symposium , pages 1 -- 14 , Aug. 2004 . N. Provos. A virtual honeypot framework. In Proceedings of the 13th USENIX Security Symposium, pages 1--14, Aug. 2004."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095812"},{"key":"e_1_3_2_1_24_1","volume-title":"Honeynet Project","author":"Spitzner L.","year":"2000","unstructured":"L. Spitzner . Know your enemy: A forensic analysis. Technical report , Honeynet Project , May 2000 . http:\/\/www.honeynet.org\/papers\/forensics. L. Spitzner. Know your enemy: A forensic analysis. Technical report, Honeynet Project, May 2000. http:\/\/www.honeynet.org\/papers\/forensics."},{"key":"e_1_3_2_1_25_1","unstructured":"The Honeynet Project 2005. http:\/\/www.honeynet.org.  The Honeynet Project 2005. http:\/\/www.honeynet.org."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1095810.1095825"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133373.1133423"}],"event":{"name":"VEE06: Second International Conference on Virtual Execution Environments","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGOPS ACM Special Interest Group on Operating Systems","ACM Association for Computing Machinery"],"location":"Ottawa Ontario Canada","acronym":"VEE06"},"container-title":["Proceedings of the 2nd international conference on Virtual execution environments"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1134760.1134765","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1134760.1134765","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T15:14:28Z","timestamp":1750259668000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1134760.1134765"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,6,14]]},"references-count":26,"alternative-id":["10.1145\/1134760.1134765","10.1145\/1134760"],"URL":"https:\/\/doi.org\/10.1145\/1134760.1134765","relation":{},"subject":[],"published":{"date-parts":[[2006,6,14]]},"assertion":[{"value":"2006-06-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}